Develop and support cybersecurity automation across Cortex XSOAR and Splunk. Build integrations, automated workflows, playbooks, and security data-source onboarding processes while improving SOC efficiency, reliability, and scalability. Collaborate with Incident Response, Threat Intelligence, Insider Risk, and SOC teams. Maintain internal and third-party tools, manage competing requests, and develop software using Python, web frameworks, Linux, Git, SQL, and front-end technologies.
Qualifications
This role is responsible for developing, enhancing, and supporting security automation solutions across Cortex XSOAR and Splunk. The successful candidate will collaborate with Incident Response, Threat Intelligence, Insider Risk, and SOC stakeholders to build integrations and automated workflows, onboard and maintain security data sources, and improve the reliability and efficiency of security operations. The position requires strong software development experience and the ability to deliver scalable solutions in a fast-paced, cross-functional environment.
Key Responsibilities
- Collaborate closely with the Incident Response, Threat Intelligence, and Insider Risk teams to design, develop, and enhance capabilities on the Cortex XSOAR platform.
- Develop and implement automation solutions that reduce manual effort and improve the efficiency of Security Operations Center (SOC) processes.
- Operate effectively in a fast-paced environment, managing and prioritizing diverse requests from multiple teams.
- Develop, maintain, and enhance internally built and third-party tools, ensuring their reliability, scalability, and alignment with operational requirements.
Required Qualifications
- A minimum of seven years of software development experience using Python and web frameworks such as Django and Flask.
- Working knowledge of front-end technologies, including HTML, CSS, JavaScript, and jQuery.
- Hands-on experience working in Linux environments, including Red Hat Enterprise Linux (RHEL) and Debian-based distributions.
- Experience managing source code and collaborating through Git-based repositories.
- A sound understanding of SQL fundamentals and database management systems (DBMS).
- A demonstrated eagerness to learn new technologies and adapt quickly to changing requirements.
- Basic knowledge of Security Operations Center (SOC) operations, including security monitoring, alert triage, incident investigation, and escalation processes.
Added Advantage
- Experience designing and developing features, integrations, or automated playbooks within Security Orchestration, Automation, and Response (SOAR) platforms.
- Hands-on experience onboarding, configuring, and validating data sources in Splunk.
- Proficiency in developing and optimizing complex Splunk Search Processing Language (SPL) queries for security monitoring, investigation, and reporting.
- Experience working with cybersecurity tools that support incident response and threat intelligence operations.
- Experience integrating security platforms with IT service management tools and ITIL-aligned workflows, particularly ServiceNow.
Similar Jobs
Aerospace • Security • Energy • Industrial
Develop and support security automation solutions across Cortex XSOAR and Splunk. Build integrations, automated workflows, playbooks, and security data-source pipelines in collaboration with Incident Response, Threat Intelligence, Insider Risk, and SOC teams. Maintain scalable internal and third-party tools, improve SOC efficiency, and support security monitoring and incident investigation. The role requires strong Python software development, Linux, web technologies, Git, SQL, and cybersecurity operations knowledge.
Top Skills:
Cortex XsoarCSSDbmsDebianDjangoFlaskGitHTMLItilJavaScriptJqueryLinuxPythonRed Hat Enterprise LinuxServicenowSoarSplSplunkSQL
Aerospace • Security • Energy • Industrial
Design, implement, and support Active Directory and hybrid identity solutions (Entra ID/AAD Connect). Perform AD builds, migrations, health checks, backups, hardening, patching, and conditional access/MFA enforcement. Configure Microsoft Defender (MDI/MDE), run assessments, remediate risks, automate with PowerShell/KQL, collaborate with vulnerability/compliance teams, and support production change management.
Top Skills:
Active DirectoryAd ReplicationAzure Ad ConnectAzure BackupsBmrCertificate ServicesConditional AccessDnsDomain ControllerEntra IdFsmo RolesGroup Policy (Gpo)Hybrid IdentityIdentity ProtectionKqlMfaMicrosoft Defender For Endpoint (Mde)Microsoft Defender For Identity (Mdi)PimPowershellRmadServicenowSsprVulnerability Management
Aerospace
Implement and manage Microsoft Active Directory domains and domain controllers (builds, promotion/demotion, replication, DNS, GPOs, FSMO, certificates). Design backups, configure MDI/MDE, perform health checks, patching, hardening, and migrations to Entra ID. Build and enforce Conditional Access and MFA, run AD/Azure assessments and remediation, automate with PowerShell and KQL, coordinate with vulnerability/compliance teams, support production with change management.
Top Skills:
Aad ConnectActive DirectoryAd Certificate ServicesAzure Active Directory (Aad)Azure BackupConditional AccessDnsEntra IdFsmo RolesGroup Policy (Gpo)Hybrid IdentityIdentity ProtectionKqlMfaMicrosoft Defender For Endpoint (Mde)Microsoft Defender For Identity (Mdi)PimPowershellServicenowSspr
What you need to know about the Delhi Tech Scene
Delhi, India's capital city, is a place where tradition and progress co-exist. While Old Delhi is known for its rich history and bustling markets, New Delhi is defined by its modern architecture. It's clear the region places a strong emphasis on preserving its cultural heritage while embracing technological advancements, particularly in artificial intelligence, which plays a central role in shaping the city's tech landscape, fueled by investments in research and development.

