HT
SOAR Automation engineer
Accepting applicationsHexaware Technologies · Chennai, Tamil Nadu, India
Full-Time Mid_senior PythonSOC
Posted
2d ago
Category
Design
Experience
Mid_senior
Country
India
Experience: 8-12 years
Work location: Chennai
Roles and responsibilities:
Design, develop, and maintain SOAR playbooks for automated incident response and security operations workflows.
Integrate security tools such as EDR, email security, threat intelligence, ticketing, and IAM platforms with SOAR solutions.
Manage and optimize SIEM use cases, correlation rules, alerts, dashboards, and reporting.
Analyze security events, investigate incidents, and improve detection capabilities.
Develop automation workflows to reduce manual effort and improve SOC efficiency.
Collaborate with SOC, Threat Hunting, and Incident Response teams to enhance security operations.
Required Skills:
Hands-on experience with SOAR platforms (Microsoft Sentinel Automation, Cortex XSOAR, Splunk SOAR, Swimlane, etc.).
Strong experience with SIEM solutions (Microsoft Sentinel, Splunk, QRadar, ArcSight, LogRhythm, etc.).
Knowledge of security operations, incident response, threat intelligence, and log analysis.
Scripting experience in Python, PowerShell, or REST APIs for automation and integrations.
Understanding of MITRE ATT&CK, security frameworks, and cybersecurity best practices.
Show more Show less
Work location: Chennai
Roles and responsibilities:
Design, develop, and maintain SOAR playbooks for automated incident response and security operations workflows.
Integrate security tools such as EDR, email security, threat intelligence, ticketing, and IAM platforms with SOAR solutions.
Manage and optimize SIEM use cases, correlation rules, alerts, dashboards, and reporting.
Analyze security events, investigate incidents, and improve detection capabilities.
Develop automation workflows to reduce manual effort and improve SOC efficiency.
Collaborate with SOC, Threat Hunting, and Incident Response teams to enhance security operations.
Required Skills:
Hands-on experience with SOAR platforms (Microsoft Sentinel Automation, Cortex XSOAR, Splunk SOAR, Swimlane, etc.).
Strong experience with SIEM solutions (Microsoft Sentinel, Splunk, QRadar, ArcSight, LogRhythm, etc.).
Knowledge of security operations, incident response, threat intelligence, and log analysis.
Scripting experience in Python, PowerShell, or REST APIs for automation and integrations.
Understanding of MITRE ATT&CK, security frameworks, and cybersecurity best practices.
Show more Show less