Cortex Security Orchestration & Automated Response (XSOAR)

Salt Digital Recruitment

Dubai

Hybrid

AED 350,000 - 640,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
Annual flight tickets
Career progression
Flexible/hybrid working arrangements
Open-door management

Job summary

Salt Digital Recruitment is seeking a Cortex XSOAR Specialist to orchestrate and automate incident response activities across client environments, both on-site and off-site. You will serve as SME for automation, integration, and playbook development, collaborating with Cyber Defense and Architecture teams to deliver secure, automated outcomes.

The role requires deep XSOAR experience, scripting skills in Python/PowerShell, and a strong understanding of cyber threats, ITIL processes, and security

Qualifications

  • Bachelor's degree in Computer Science, Information Systems, Electrical Engineering, or related field.

Responsibilities

  • Provide technical leadership and optimize processes and systems.
  • Support pre-sales, sales and business development for services.
  • Collaborate with internal/external stakeholders for effective delivery of cybersecurity services.
  • Assist in service transition and onboarding of customers/infrastructure into operations.
  • Support rapid detection, mitigation, containment, and response to cybersecurity incidents using SOAR integrations.
  • Create and document playbooks, workflows, and automation activities.

Skills

XSOAR
Python
PowerShell
Threat Intelligence
Incident Response
Playbooks
APIs

Education

Bachelor's degree in CS/IS/EE

Tools

Palo Alto Cortex XSOAR
SIEM
ITIL

Job description

Job Overview

We are looking for a talented and experienced Cortex Security Orchestration & Automated Response (XSOAR) Specialist who will be responsible for the orchestration and automation of incident response activities. This role supports customer engagements, working both off-site and on-site, leveraging SOAR solutions and expertise in IT and cybersecurity technologies to demonstration, implement, and maximize the value of Security Orchestration, Automation and Response (SOAR) solutions. The successful candidate will serve as the primary technical and operational Subject Matter Expert (SME) for automation, integration, and playbook development. The role works closely with Cyber Defense, Platforms & Architecture, Managed Controls, and other relevant teams to deliver successful cybersecurity outcomes.

Key Responsibilities:
  • Provide technical and thought leadership, including the optimization of processes and systems.
  • Support pre-sales, sales, and business development activities for new and existing services.
  • Collaborate with internal teams and external stakeholders to achieve effective and sustainable implementation and delivery of cybersecurity services.
  • Support the service transition process and work with relevant teams to transition customers and infrastructure into operations effectively.
  • Work proactively and collaboratively with internal and external stakeholders to achieve mutually beneficial outcomes.
  • Support the rapid and effective detection, mitigation, containment, and response to cybersecurity incidents by leveraging integrations and capabilities across infrastructure platforms, security tools, managed assets, and customer controls.
  • Create, optimize, and document processes, procedures, workflows, and automation activities.
  • Track and report on SLAs, KPIs, and OLAs.
  • Initiate, support, and manage incidents, problems, issues, risks, and compliance activities.
  • Participate in 24x7 on‑call support for critical or urgent activities as required.
Qualifications & Skills:
  • Bachelor's degree in Computer Science, Information Systems, Electrical Engineering, or a closely related field.
  • Strong expertise in at least three of the following areas: Security Controls Operations Cyber Incident Response Cybersecurity Detection Managed Services Integration Cyber Threat Intelligence Threat Hunting
  • Minimum 3 years of experience working with Palo Alto Networks Cortex XSOAR (formerly Demisto SOAR).
  • Strong understanding of cyber threats, threat actors, Tactics, Techniques, and Procedures (TTPs), and appropriate mitigation strategies across on‑premises, cloud, and distributed environments.
  • CISSP, CISM, CISA, or equivalent professional experience/certification.
  • ITIL certification or relevant experience.
  • Hands‑on experience integrating various technologies with SOAR platforms.
  • Experience designing, implementing, maintaining, and optimizing playbooks for the detection, protection, containment, and mitigation of cybersecurity threats and incidents.
  • Strong scripting and integration skills using languages and technologies such as Python, Go, Kusto/KQL, and PowerShell.
  • Strong knowledge of information security technologies, including SIEM, NGFW, CTI, and WAF, as well as IT systems such as Microsoft 365 and service management tools.
  • Understanding of APIs and interfaces used to integrate, automate, and orchestrate IT and security systems.
  • Solid experience in Managed Security Service delivery, cybersecurity concepts, and relevant security standards.
  • Demonstrated experience in managing and mitigating security events, threats, attacks, and vulnerabilities.
  • Customer‑and‑team-focused approach.
  • Excellent organizational skills, with the ability to lead and motivate skilled security professionals.
  • Strong listening, communication, presentation, and training skills.
  • Ability to collaborate with and influence pre‑sales and sales teams to achieve agreed business outcomes.
  • Flexible approach to work based on business and operational requirements.
  • Strong interpersonal and collaboration skills, with the ability to work effectively across teams and resolve differences constructively.
Benefits:
  • Health insurance with a leading global medical insurance provider.
  • Career progression and growth through challenging projects and diverse work opportunities.
  • Employee engagement and wellness activities throughout the year.
  • Excellent learning and professional development opportunities.
  • Annual flight tickets to the employee's home country.
  • Inclusive and diverse working environment.
  • Flexible/hybrid working arrangements.
  • Open-door management and communication culture.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Resident Consultant (XSOAR Specialist)
Resident Consultant (XSOAR Specialist)

emagine • Abu Dhabi

On-site
AED 220,000 - 420,000
Resident Consultant XSOAR Specialist
Resident Consultant XSOAR Specialist

emagine • Abu Dhabi

On-site
AED 150,000 - 210,000
Cortex XSOAR Security Orchestration Specialist
Cortex XSOAR Security Orchestration Specialist

Salt Digital Recruitment • Dubai

Hybrid
AED 350,000 - 640,000
Health insurance
Annual flight tickets
Career progression
+2
FortiSOAR Specialist
FortiSOAR Specialist

Salt • Dubai

On-site
AED 90,000 - 140,000
Health insurance
Annual flight tickets to home country
Open door policy
Security Automation Workflow Developer
Security Automation Workflow Developer

Remotedxb • Dubai

On-site
AED 257,000 - 331,000
Competitive salary
100% medical premiums covered
3 weeks PTO plus holidays
+2
XSOAR Automation & Cyber Defense Specialist
XSOAR Automation & Cyber Defense Specialist

emagine • Abu Dhabi

On-site
AED 220,000 - 420,000
Solutions Consultant
Solutions Consultant

Palo Alto Networks, Inc. • Ajman

On-site
AED 350,000 - 550,000
XSOAR Automation & Cyber Defense SME
XSOAR Automation & Cyber Defense SME

emagine • Abu Dhabi

On-site
AED 150,000 - 210,000
SOAR Engineer
SOAR Engineer

CyberGate Defense • Abu Dhabi

On-site
AED 120,000 - 160,000
Services Delivery Manager
Services Delivery Manager

Noventiq Seven Seas Technology • Dubai

On-site
AED 280,000 - 520,000