Cortex SOAR Administrator (Security Orchestration, Automation and Response)
LOCATION - Noida, India
WORK MODE - Onsite, 5 days/week
EMPLOYMENT - Full time
Role Overview
We are seeking an experienced Cortex SOAR Administrator to administer, enhance, and optimize the Palo Alto Networks Cortex XSOAR platform. The role will focus on integrating enterprise security technologies, developing automation and response workflows, and improving the effectiveness and resilience of security operations. The successful candidate will bring strong hands on technical experience and be comfortable working in a client facing, onsite environment.
Key Responsibilities
- Administer, configure, maintain, and support the Cortex XSOAR platform across production and non-production environments.
- Design, develop, test, and optimize playbooks, automations, integrations, incident layouts, dashboards, and workflows.
- Integrate Cortex XSOAR with security and enterprise platforms using supported content packs, REST APIs, webhooks, JSON, and custom Python scripts.
- Connect and orchestrate technologies such as SIEM, EDR/XDR, firewalls, threat intelligence, email security, IAM/PAM, ticketing, vulnerability management, and cloud security platforms.
- Automate repetitive SOC activities, enrichment, triage, containment, notification, escalation, and evidence gathering processes.
- Troubleshoot integration failures, authentication issues, API errors, playbook exceptions, and performance concerns.
- Monitor platform health, job execution, engine connectivity, content updates, and operational availability.
- Collaborate with SOC analysts, incident responders, security engineers, platform teams, and client stakeholders to translate operational needs into secure automation.
- Apply change control, testing, access control, credential protection, versioning, and rollback practices for SOAR content.
- Maintain technical documentation, integration specifications, playbook logic, operational runbooks, and knowledge articles.
Required Technical Skills
- Strong hands on experience in Palo Alto Networks Cortex XSOAR administration, configuration, and troubleshooting.
- Demonstrated experience integrating security tools with Cortex XSOAR in an enterprise SOC environment.
- Proficiency in Python scripting, REST APIs, JSON, webhooks, authentication methods, and error handling.
- Solid understanding of SOC operations, incident response, alert triage, threat intelligence, and security orchestration.
- Working knowledge of SIEM platforms such as Splunk.
- Exposure to EDR/XDR, firewalls, email security, IAM/PAM, vulnerability management, ticketing platforms, and cloud security services.
- Understanding of secure integration design, least privilege, secrets handling, logging, auditability, and production change management.
- Familiarity with the MITRE ATT&CK framework and common security incident types.
Experience and Qualifications
- 5+ years of overall cybersecurity or security operations experience.
- 3+ years of hands-on Cortex XSOAR administration, implementation, integration, or automation experience.
- Bachelor‿s degree in Computer Science, Information Technology, Cybersecurity, or a related discipline, or equivalent practical experience.
- Palo Alto Networks Cortex XSOAR certification is preferred. Relevant certifications such as CISSP, GCIH, CEH, Security+, or cloud security certifications are advantageous.