Group Specialist - Cyber Engineering Automation

DP World

Hyderabad

On-site

INR 2,000,000 - 3,500,000

Full time

12 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

DP World is seeking an experienced Security Automation Engineer to design and implement automated workflows across SOC, CSPM, VM, and IAM platforms. You will integrate Sentinel, Wiz, SailPoint, Check Point, and Zscaler via APIs and event-driven automation.

You will build incident-response automation, threat enrichment, and ticketing workflows using SOAR frameworks and cross-platform IT/OT/Cloud security integrations.

Qualifications

  • Bachelor's degree in CS or engineering with 16+ years of relevant experience.
  • 7-12 years of cybersecurity or security engineering experience, with at least 3 years in security automation/SOAR engineering.
  • Hands-on expertise with SOAR platforms and security tooling integration.
  • Knowledge of security APIs and scripting languages; cloud automation experience.
  • Experience with infrastructure-as-code and CI/CD tooling.

Responsibilities

  • Design and implement automated workflows and playbooks across SOC, CSPM, VM, and IAM platforms.
  • Integrate tools like Sentinel, Wiz, SailPoint, Check Point, and Zscaler using APIs and event-driven automation.
  • Build automation for IR, threat enrichment, user isolation, and ticketing workflows using SOAR and orchestration frameworks.
  • Develop cross-platform integrations between IT, OT, and Cloud security tools for unified visibility.
  • Enable real-time telemetry ingestion and correlation using APIs and data pipelines.
  • Create reusable automation modules for global rollout across regions.

Skills

SOAR platforms
Python scripting
PowerShell
REST APIs
JSON
YAML
Terraform
Ansible
Jenkins
GitHub Actions
Security APIs
MITRE ATT&CK

Education

Bachelor's Degree in CS/Engineering

Tools

Cortex XSOAR
FortiSOAR
Microsoft Sentinel
Splunk SOAR
Terraform
Ansible
Jenkins
GitHub Actions
ARM Templates
EventHub

Job description

Key Accountabilities
  • Design and implement automated workflows and playbooks across SOC, CSPM, VM, and IAM platforms.
  • Integrate diverse tools such as Sentinel (SIEM/XDR), Wiz (CSPM/CNAPP), SailPoint (IAM), Check Point (EDR/DLP), and Zscaler (SSE) using APIs and event-driven automation.
  • Build automation for incident response (IR), threat enrichment, user isolation, and ticketing workflows using SOAR and orchestration frameworks (e.g., Microsoft Sentinel Logic Apps, Cortex XSOAR, FortiSOAR, or custom Python-based frameworks).
  • Develop and maintain cross-platform integrations between IT, OT, and Cloud security tools for unified visibility.
  • Enable real-time telemetry ingestion and correlation using APIs, data pipelines, or event hubs.
  • Create reusable automation modules and templates for consistent rollout across global regions.
  • Automate cloud posture monitoring and remediation (Azure, AWS, GCP) using CSPM/CNAPP APIs
  • Engineer infrastructure-as-code (IaC) security controls and guardrails using Terraform, Ansible, or ARM templates.
  • Integrate automation into DevSecOps pipelines for continuous compliance, vulnerability scanning, and drift detection.
  • Implement AI-driven response and enrichment playbooks for phishing, malware, and insider threat cases.
  • Develop automation for threat intel enrichment (VirusTotal, MISP, Recorded Future, etc.) and ticket closure workflows (JIRA, ServiceNow).
  • Continuously tune automation based on MITRE ATT&CK and MITRE ATLAS techniques.
JOB DESCRIPTION
  • Design and implement automated workflows and playbooks across SOC, CSPM, VM, and IAM platforms.
  • Integrate diverse tools such as Sentinel (SIEM/XDR), Wiz (CSPM/CNAPP), SailPoint (IAM), Check Point (EDR/DLP), and Zscaler (SSE) using APIs and event-driven automation.
  • Build automation for incident response (IR), threat enrichment, user isolation, and ticketing workflows using SOAR and orchestration frameworks (e.g., Microsoft Sentinel Logic Apps, Cortex XSOAR, FortiSOAR, or custom Python-based frameworks).
  • Develop and maintain cross-platform integrations between IT, OT, and Cloud security tools for unified visibility.
  • Enable real-time telemetry ingestion and correlation using APIs, data pipelines, or event hubs.
  • Create reusable automation modules and templates for consistent rollout across global regions.
  • Automate cloud posture monitoring and remediation (Azure, AWS, GCP) using CSPM/CNAPP APIs
  • Engineer infrastructure-as-code (IaC) security controls and guardrails using Terraform, Ansible, or ARM templates.
  • Integrate automation into DevSecOps pipelines for continuous compliance, vulnerability scanning, and drift detection.
  • Implement AI-driven response and enrichment playbooks for phishing, malware, and insider threat cases.
  • Develop automation for threat intel enrichment (VirusTotal, MISP, Recorded Future, etc.) and ticket closure workflows (JIRA, ServiceNow).
  • Continuously tune automation based on MITRE ATT&CK and MITRE ATLAS techniques.
OTHER
  • Act as an ambassador for DP World always when working; promoting and demonstrating positive behaviours in harmony with DP World’s Founder’s Principles, values and culture; ensuring the highest level of safety is applied in all activities; understanding and following DP World’s Code of Conduct and Ethics policies
  • Perform other related duties as assigned
Qualifications, Experience And Skills
  • A Bachelor's Degree in Computer Science, Engineering with 16+ years of relevant experience
  • 7-12 years of cybersecurity or security engineering experience, with at least 3 years in security automation/SOAR engineering.
  • Hands-on expertise with:
    • SOAR platforms: Cortex XSOAR, FortiSOAR, Microsoft Sentinel Logic Apps, Splunk SOAR, or custom Python-based orchestration.
    • Security APIs and scripting: Python, PowerShell, REST API, JSON, YAML.
    • Cloud environments: Azure, AWS, GCP automation (Lambda, Logic Apps, Functions, EventHub).
    • Infrastructure tools: Terraform, Ansible, Jenkins, GitHub Actions.
    • Knowledge of security tools integration across SIEM, EDR/XDR, IAM, DLP, CSPM, CNAPP, CASB, and vulnerability scanners.
    • Strong understanding of incident response, SOC processes, and MITRE ATT&CK frameworks.
    • Proven track record of reducing manual operational workload via automation at scale.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Group Specialist - Cyber Engineering Automation
Group Specialist - Cyber Engineering Automation

The Peninsular and Oriental Steam Navigation Company • Hyderabad

On-site
INR 1,800,000 - 3,000,000
Group Specialist - Cyber Engineering Automation
Group Specialist - Cyber Engineering Automation

DP World • Gurugram District

On-site
INR 3,500,000 - 6,000,000
Group Security Operations Center Specialist
Group Security Operations Center Specialist

DP World • Bengaluru

On-site
INR 1,500,000 - 2,000,000
Assoc. Manager, IT Security
Assoc. Manager, IT Security

KFC Corporation • India

Hybrid
INR 1,500,000 - 2,800,000
Automation Development Engineer
Automation Development Engineer

nTech Workforce • Hyderabad

On-site
INR 800,000 - 1,200,000
Security Automation Engineer
Security Automation Engineer

Lumen Technologies India • Dadri

On-site
INR 1,800,000 - 2,800,000
Microsoft SC-200
AZ-204
Power Platform certification
+3
Assoc. Manager, IT Security
Assoc. Manager, IT Security

Yum! Brands • Gurugram District

On-site
INR 3,000,000 - 6,000,000
Security Automation Engineer
Security Automation Engineer

Wpp • Chennai District

Hybrid
INR 1,200,000 - 1,800,000
Hybrid work model
Security Automation Engineer
Security Automation Engineer

Cbts • Chennai District

On-site
INR 1,400,000 - 2,200,000
Intrusion Analyst III
Intrusion Analyst III

Jobtailor • Bengaluru

Hybrid
INR 1,800,000 - 2,800,000