Security Engineer II

Steerlean

Gurugram District

On-site

INR 1,800,000 - 2,400,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Steerlean in Gurugram, India, seeks an XSIAM Administrator & Automation Engineer to own day‑to‑day administration, data onboarding, detection content, and automation strategy for Cortex XSIAM.

You will design, build, and improve detection content, playbooks, and AI‑assisted workflows to let the SOC operate at machine speed, collaborating with incident response, threat hunt, and insider risk teams.

Qualifications

  • Hands-on experience with Cortex XSIAM/XSOAR or comparable SIEM/SOAR.
  • Strong Python scripting.
  • Experience with data onboarding and parsing.
  • Familiarity with AI/LLM in operational workflows.

Responsibilities

  • Administer Cortex XSIAM/XSOAR platform including RBAC, licenses, health monitoring.
  • Onboard and normalize data sources using XDM mapping and parsing rules.
  • Manage integrations, content packs, connectors, brokers, and collectors.
  • Tune detection content ( BIOCs, rules, analytics) to reduce noise.
  • Monitor ingestion costs and storage; troubleshoot parsing failures.
  • Onboard logs directly or via Cribl and extend detection using XSIAM notebooks.
  • Develop XQL queries for correlations, dashboards, and hunting.
  • Design and maintain automation playbooks (XSOAR/XSIAM) for triage, enrichment, containment, remediation.
  • Build CI/CD pipelines for playbook/content versioning and deployment.
  • Apply AI capabilities to accelerate investigation and automate SOC workflows.

Skills

Security operations
SIEM/SOAR administration
Python scripting
XQL
Data onboarding/parsing
AI/LLM integration
REST APIs
Incident response

Education

Bachelor's degree in Computer Science or IT

Job description

Job Summary

We are looking for an XSIAM Administrator & Automation Engineer to own the day-to-day administration, data onboarding, detection engineering and automation strategy of our Cortex XSIAM (Extended Security Intelligence and Automation Management) platform. This role sits at the intersection of security operations engineering and AI-driven automation - you will design, build, and continuously improve the detection content, playbooks, and AI-assisted workflows that let our SOC operate at machine speed. You will work closely with multiple security operations team such as incident response, threat hunt, insider risk to ensure XSIAM is correctly configured, fully onboarded, and increasingly autonomous in how it triages, investigates, and responds to threats.

Responsibilities
  • Platform Administration: Administer and maintain the Cortex XSIAM tenant: user roles, RBAC, licensing, health monitoring, and platform upgrades.
  • Platform Administration: Onboard and normalize new data sources (logs, endpoint telemetry, cloud, identity, network) using XDM (Cortex Data Model) mapping and parsing rules.
  • Platform Administration: Manage integrations and content packs, including third-party connectors, brokers, and collectors.
  • Platform Administration: Tune detection content - BIOCs, correlation rules, analytics, and incident scoring - to reduce noise and improve fidelity.
  • Platform Administration: Monitor platform performance, data ingestion costs, and storage tiering, and troubleshoot ingestion or parsing failures.
  • Logging and Detection Engineering: Onboard logs directly from sources or via secure data pipeline management solution such as Cribl
  • Logging and Detection Engineering: Extend detection engineering scope by creating corelation, analytics rule using XSIAM jupyter notebooks.
  • Logging and Detection Engineering: Support detection engineering and threat-hunting initiatives with automation and XQL query development.
  • Automation & Playbook Engineering: Design, build, and maintain automation playbooks (XSOAR/XSIAM playbook engine) to automate alert triage, enrichment, containment, and remediation.
  • Automation & Playbook Engineering: Develop custom automations, scripts, and integrations (Python) to extend out-of-the-box XSIAM capabilities.
  • Automation & Playbook Engineering: Continuously identify manual SOC workflows and convert them into automated, auditable playbooks, driving down mean time to detect (MTTD) and mean time to respond (MTTR).
  • Automation & Playbook Engineering: Build and maintain CI/CD pipelines for playbook and content versioning, testing, and deployment across environments.
  • AI-Driven Security Operations: Apply Cortex XSIAMs native AI/ML capabilities (AI-driven incident scoring, causality analysis, alert clustering, and DRP/attack-surface insights) to accelerate investigation and reduce analyst workload.
  • AI-Driven Security Operations: Integrate large language model (LLM)-based assistants and agentic workflows into playbooks for tasks such as alert summarization, natural-language incident querying, phishing/malware triage, and auto-generated investigation reports.
  • AI-Driven Security Operations: Evaluate and pilot emerging AI/agentic-SOC features (e.g., autonomous investigation agents, AI copilots, natural-language-to-XQL query generation) and lead responsible adoption across the security operations team.
  • AI-Driven Security Operations: Build feedback loops and guardrails (human-in-the-loop approval steps, confidence thresholds, audit logging) to ensure AI-assisted actions remain safe, explainable, and compliant.
  • AI-Driven Security Operations: Use AI-assisted coding tools to accelerate development of custom scripts, integrations, and XQL queries, while maintaining rigorous testing and code-review standards.
Required Qualifications
  • 3+ years of experience in security operations, SIEM/SOAR administration, or detection/automation engineering.
  • Hands-on experience administering Cortex XSIAM, Cortex XSOAR, or a comparable SIEM/SOAR platform (Splunk SOAR, Microsoft Sentinel, IBM QRadar, etc.).
  • Strong scripting ability in Python, and comfort working with REST APIs to build custom integrations.
  • Practical knowledge of XQL (or equivalent query language) for building correlation rules, dashboards, and threat-hunting queries.
  • Solid understanding of SOC workflows: alert triage, incident response, threat intelligence, and case management.
  • Experience with data onboarding/parsing (log normalization, XDM/CIM-style schemas) from diverse sources (EDR, cloud, network, identity).
  • Familiarity with applying or integrating AI/LLM capabilities into operational workflows (prompt design, AI copilots, or agentic automation) - production experience preferred, strong conceptual understanding acceptable.
Preferred Qualifications
  • Palo Alto Networks Certified XSIAM Engineer, XSIAM Analyst, or XSOAR Engineer certification.
  • Experience with CI/CD tooling (Git, Jenkins/GitHub Actions) for security content and playbook lifecycle management.
  • Exposure to cloud platforms (AWS, Azure, GCP) and containerized environments.
  • Experience with MITRE ATT&CK-mapped detection engineering.
  • Prior experience deploying agentic AI workflows, AI-assisted SOC copilots, or natural-language query interfaces in a security context.
Education

Bachelors degree in Computer Science, Information Technology, or a related field. Relevant certifications (CISSP, CISM, CEH) are preferred.

Disclaimer: This job description has been sourced from a public domain and may have been modified by Naukri.com to improve clarity for our users. We encourage job seekers to verify all details directly with the employer via their official channels before applying.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer II
Security Engineer II

SteerLean Consulting • Gurugram District

On-site
INR 1,800,000 - 2,400,000
XSIAM Engineer
XSIAM Engineer

Lumen Technologies India • Dadri

On-site
INR 1,200,000 - 1,800,000
Security Automation Engineer
Security Automation Engineer

Cbts • Chennai District

On-site
INR 1,400,000 - 2,200,000
Sr Security Consultant - Data Security(XSIAM)
Sr Security Consultant - Data Security(XSIAM)

IBM • Mumbai

On-site
INR 2,200,000 - 3,500,000
Security Automation Engineer
Security Automation Engineer

Lumen Technologies India • Dadri

On-site
INR 1,800,000 - 2,800,000
Microsoft SC-200
AZ-204
Power Platform certification
+3
Cybersecurity – Security Operations (SOC) with Cortex XSIAM
Cybersecurity – Security Operations (SOC) with Cortex XSIAM

Randstad • Hyderabad

On-site
INR 1,500,000 - 2,000,000
SISA Information Security - Security Operations Center Manager - SIEM/SOAR
SISA Information Security - Security Operations Center Manager - SIEM/SOAR

SISA • Bengaluru

On-site
INR 3,000,000 - 5,200,000
Soc Analyst
Soc Analyst

BUSINESSNEXT • Dadri

On-site
INR 1,200,000 - 2,000,000
Sr. Security Operations Analyst
Sr. Security Operations Analyst

Simfluent • Dadri

On-site
INR 1,200,000 - 1,800,000
Cyber Security Manager
Cyber Security Manager

Wsne Consulting • Mumbai

On-site
INR 1,000,000 - 1,800,000