We are an AI-led, platform-driven Digital Engineering and Enterprise Modernization partner, combining deep technical expertise and industry experience to help our clients anticipate what’s next. Our offerings and proven solutions create a unique competitive advantage for our clients by giving them the power to see beyond and rise above. We work with many industry-leading organizations across the world, including 20 Fortune 50 companies and 4 of the 5 top banks in both the US and India, and numerous innovators across the healthcare ecosystem.
We are seeking a skilled Cortex XSOAR Automation Engineer to design, develop, integrate, and maintain security automation solutions. This role is critical in enhancing our security operations by streamlining incident-response workflows and reducing repetitive manual activities. You will work closely with SOC analysts, incident responders, threat analysts, and platform teams to improve our security posture through reliable automation.
- Role: Cortex XSOAR Automation Engineer
- Experience: 8 to 12 Years
- Job Type: Full-Time Employment
What You'll Do:
- Design, develop, test, deploy, and maintain Cortex XSOAR playbooks and automation workflows.
- Develop custom integrations and automation scripts using Python, REST APIs, and JSON.
- Integrate XSOAR with SIEM, EDR/XDR, threat intelligence, identity, email security, ticketing, and network security platforms.
- Collaborate with SOC and Incident Response teams to identify automation opportunities and translate operational requirements into technical solutions.
- Configure and manage incident types, layouts, fields, classifiers, mappers, indicators, jobs, dashboards, and reports.
- Monitor, troubleshoot, and optimize playbooks, integrations, engines, and platform performance.
- Manage content packs and support controlled promotion of XSOAR content across development, testing, and production environments.
- Apply role-based access control, credential protection, auditability, and secure integration practices.
- Maintain technical documentation, runbooks, playbook logic, test evidence, and operational procedures.
- Provide production support during critical security incidents and contribute to continuous platform improvement initiatives.
Expertise You'll Bring:
- Hands-on experience with Palo Alto Networks Cortex XSOAR (formerly Demisto).
- Strong understanding of SOAR concepts, Security Operations Center (SOC) workflows, incident response, and security automation.
- Proficiency in Python scripting and troubleshooting automation code.
- Experience with REST APIs, JSON, authentication mechanisms, and third-party security tool integrations.
- Experience creating and maintaining XSOAR playbooks, integrations, automations, classifiers, and mappers.
- Strong understanding of security alerts, Indicators of Compromise (IOCs), enrichment, triage, containment, and case management workflows.
- Familiarity with SIEM, EDR/XDR, threat intelligence, email security, IAM, firewall, and ITSM platforms.
- Working knowledge of Linux operating systems, networking concepts, log analysis, and secure connectivity principles.
- Strong analytical, troubleshooting, communication, and documentation skills.
- Hands-on experience with Identity and Access Management, including Microsoft Entra ID (Mandatory Skill).
- Experience integrating security platforms and automating operational response processes.
- Knowledge of security orchestration, automated investigation workflows, and incident lifecycle management.
- Understanding of secure credential management, RBAC, governance, and audit requirements.
- Experience supporting enterprise-scale or multi-tenant security operations environments.
- Familiarity with cloud security concepts and cloud platform integrations.
- Exposure to DevSecOps practices, CI/CD pipelines, and infrastructure automation.
- Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related discipline, or equivalent professional experience.
- Palo Alto Networks XSOAR certification or other relevant cybersecurity certifications are advantageous.
- Strong ability to collaborate with SOC analysts, threat hunters, incident responders, and infrastructure teams.
- Commitment to continuous improvement, operational excellence, and security automation innovation.
- Competitive salary and benefits package
- Culture focused on talent development with quarterly growth opportunities and company-sponsored higher education and certifications
- Opportunity to work with cutting-edge technologies
- Employee engagement initiatives such as project parties, flexible work hours, and Long Service awards
- Insurance coverage: group term life, personal accident, and Mediclaim hospitalization for self, spouse, two children, and parents
Values-Driven, People-Centric & Inclusive Work Environment:
Persistent is dedicated to fostering diversity and inclusion in the workplace. We invite applications from all qualified individuals, including those with disabilities, and regardless of gender or gender preference. We welcome diverse candidates from all backgrounds.
- We support hybrid work and flexible hours to fit diverse lifestyles.
- Our office is accessibility-friendly, with ergonomic setups and assistive technologies to support employees with physical disabilities.
- If you are a person with disabilities and have specific requirements, please inform us during the application process or at any time during your employment
“Persistent is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind.”