Security Engineer II

SteerLean Consulting

Gurugram District

On-site

INR 1,800,000 - 2,400,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

SteerLean Consulting is seeking an XSIAM Administrator & Automation Engineer to own day-to-day administration, data onboarding, detection engineering, and automation strategy of the Cortex XSIAM platform. You will design, build, and improve detection content, playbooks, and AI-assisted workflows for SOC operations.

You will collaborate with incident response, threat hunting, and insider risk teams to ensure XSIAM is correctly configured and increasingly autonomous in triage, investigation, and

Qualifications

  • Bachelor's degree in CS/IT or related field.
  • Hands-on admin experience with SIEM/SOAR platforms (XSIAM/XSOAR) preferred.
  • Strong Python scripting and REST API abilities.

Responsibilities

  • Administer Cortex XSIAM tenant, RBAC, licensing, health monitoring, upgrades.
  • Onboard and normalize data sources using XDM mappings and parsing rules.
  • Create and maintain detection content, playbooks, and automation workflows.

Skills

Python scripting
REST APIs
XQL / queries
SOC workflows
CI/CD tooling

Education

Bachelor's degree in CS/IT or related field

Tools

Cortex XSIAM
Cortex XSOAR
Cribl
GitHub Actions

Job description

XSIAM Administrator & Automation Engineer

About The Role

We are looking for an XSIAM Administrator & Automation Engineer to own the day-to-day administration, data onboarding, detection engineering and automation strategy of our Cortex XSIAM (Extended Security Intelligence and Automation Management) platform. This role sits at the intersection of security operations engineering and AI-driven automation — you will design, build, and continuously improve the detection content, playbooks, and AI-assisted workflows that let our SOC operate at machine speed. You will work closely with multiple security operations team such as incident response, threat hunt, insider risk to ensure XSIAM is correctly configured, fully onboarded, and increasingly autonomous in how it triages, investigates, and responds to threats.

Key Responsibilities
Platform Administration
  • Administer and maintain the Cortex XSIAM tenant: user roles, RBAC, licensing, health monitoring, and platform upgrades.
  • Onboard and normalize new data sources (logs, endpoint telemetry, cloud, identity, network) using XDM (Cortex Data Model) mapping and parsing rules.
  • Manage integrations and content packs, including third-party connectors, brokers, and collectors.
  • Tune detection content — BIOCs, correlation rules, analytics, and incident scoring — to reduce noise and improve fidelity.
  • Monitor platform performance, data ingestion costs, and storage tiering, and troubleshoot ingestion or parsing failures.
Logging and Detection Engineering
  • Onboard logs directly from sources or via secure data pipeline management solution such as Cribl
  • Extend detection engineering scope by creating corelation, analytics rule using XSIAM jupyter notebooks.
  • Support detection engineering and threat-hunting initiatives with automation and XQL query development.
Automation & Playbook Engineering
  • Design, build, and maintain automation playbooks (XSOAR/XSIAM playbook engine) to automate alert triage, enrichment, containment, and remediation.
  • Develop custom automations, scripts, and integrations (Python) to extend out-of-the-box XSIAM capabilities.
  • Continuously identify manual SOC workflows and convert them into automated, auditable playbooks, driving down mean time to detect (MTTD) and mean time to respond (MTTR).
  • Build and maintain CI/CD pipelines for playbook and content versioning, testing, and deployment across environments.
AI-Driven Security Operations
  • Apply Cortex XSIAM's native AI/ML capabilities (AI-driven incident scoring, causality analysis, alert clustering, and DRP/attack-surface insights) to accelerate investigation and reduce analyst workload.
  • Integrate large language model (LLM)-based assistants and agentic workflows into playbooks for tasks such as alert summarization, natural-language incident querying, phishing/malware triage, and auto-generated investigation reports.
  • Evaluate and pilot emerging AI/agentic-SOC features (e.g., autonomous investigation agents, AI copilots, natural-language-to-XQL query generation) and lead responsible adoption across the security operations team.
  • Build feedback loops and guardrails (human-in-the-loop approval steps, confidence thresholds, audit logging) to ensure AI-assisted actions remain safe, explainable, and compliant.
  • Use AI-assisted coding tools to accelerate development of custom scripts, integrations, and XQL queries, while maintaining rigorous testing and code-review standards.
Required Qualifications
  • 3+ years of experience in security operations, SIEM/SOAR administration, or detection/automation engineering.
  • Hands-on experience administering Cortex XSIAM, Cortex XSOAR, or a comparable SIEM/SOAR platform (Splunk SOAR, Microsoft Sentinel, IBM QRadar, etc.).
  • Strong scripting ability in Python, and comfort working with REST APIs to build custom integrations.
  • Practical knowledge of XQL (or equivalent query language) for building correlation rules, dashboards, and threat-hunting queries.
  • Solid understanding of SOC workflows: alert triage, incident response, threat intelligence, and case management.
  • Experience with data onboarding/parsing (log normalization, XDM/CIM-style schemas) from diverse sources (EDR, cloud, network, identity).
  • Familiarity with applying or integrating AI/LLM capabilities into operational workflows (prompt design, AI copilots, or agentic automation) — production experience preferred, strong conceptual understanding acceptable.
Preferred Qualifications
  • Palo Alto Networks Certified XSIAM Engineer, XSIAM Analyst, or XSOAR Engineer certification.
  • Experience with CI/CD tooling (Git, Jenkins/GitHub Actions) for security content and playbook lifecycle management.
  • Exposure to cloud platforms (AWS, Azure, GCP) and containerized environments.
  • Experience with MITRE ATT&CK-mapped detection engineering.
  • Prior experience deploying agentic AI workflows, AI-assisted SOC copilots, or natural-language query interfaces in a security context.
Education

Bachelor's degree in Computer Science, Information Technology, or a related field. Relevant certifications (CISSP, CISM, CEH) are preferred.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

XSIAM Engineer
XSIAM Engineer

Lumen Technologies India • Dadri

On-site
INR 1,200,000 - 1,800,000
Security Automation Engineer
Security Automation Engineer

Lumen Technologies India • Dadri

On-site
INR 1,800,000 - 2,800,000
Microsoft SC-200
AZ-204
Power Platform certification
+3
Cyber Security Manager
Cyber Security Manager

Wsne Consulting • Mumbai

On-site
INR 1,000,000 - 1,800,000
Soc Analyst
Soc Analyst

BUSINESSNEXT • Dadri

On-site
INR 1,200,000 - 2,000,000
Security Automation Engineer
Security Automation Engineer

AlphaSense Oy • Pune District

On-site
INR 1,800,000 - 3,200,000
Security Automation Engineer
Security Automation Engineer

AlphaSense Oy • Bengaluru

On-site
INR 2,500,000 - 5,000,000
Security Automation Engineer
Security Automation Engineer

AlphaSense Oy • Delhi

On-site
INR 1,500,000 - 2,500,000
Security Automation Engineer
Security Automation Engineer

Cbts • Chennai District

On-site
INR 1,400,000 - 2,200,000
Cybersecurity – Security Operations (SOC) with Cortex XSIAM
Cybersecurity – Security Operations (SOC) with Cortex XSIAM

Randstad • Hyderabad

On-site
INR 1,500,000 - 2,000,000
Senior Information Security Tech Consultant-I
Senior Information Security Tech Consultant-I

Lumen Technologies India • Dadri

On-site
INR 1,500,000 - 2,800,000