Security Automation / Cortex XSOAR Engineer

Perfict Global, Inc.

United States

Remote

USD 120,000 - 160,000

Full time

3 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Perfict Global, Inc. is seeking a Security Automation / Cortex XSOAR Engineer to support and enhance our Security Operations and Incident Response capabilities. You will develop and maintain Cortex XSOAR playbooks, automation workflows, and integrations to improve response speed and consistency.

The ideal candidate has hands-on experience with Cortex XSOAR, Python, and Splunk, and can troubleshoot automation issues while collaborating with Incident Response and SOC teams.

Qualifications

  • High school diploma or equivalent.
  • 5+ years of hands-on cybersecurity, security operations, incident response, or security automation experience.
  • Strong hands-on experience developing and maintaining Palo Alto Cortex XSOAR playbooks.
  • Experience building and supporting SOAR automation workflows.
  • Strong Python scripting/programming skills.
  • Solid understanding of Incident Response processes and security operations workflows.
  • Hands-on experience with Splunk or another enterprise SIEM platform.
  • Strong troubleshooting and security data analysis skills.
  • Experience developing, maintaining, and troubleshooting automated security playbooks.
  • Ability to work effectively with SOC, Incident Response, Cybersecurity, and Infrastructure teams.
  • Strong written and verbal communication skills.

Responsibilities

  • Develop, enhance, and maintain Palo Alto Cortex XSOAR playbooks and automated security workflows.
  • Build automation to support Incident Response and Security Operations processes.
  • Troubleshoot XSOAR integrations, playbooks, scripts, and automation failures.
  • Develop and maintain integrations with security tools, SIEM platforms, and other enterprise technologies.
  • Partner with Incident Response Analysts and SOC teams to identify opportunities for security automation.
  • Analyze security events, incidents, and operational trends to identify areas for improvement.
  • Define and implement new SOAR use cases, automation requirements, and response workflows.
  • Use Python scripting/programming to develop and enhance security automation.
  • Work with security teams to streamline incident response processes and improve operational efficiency.
  • Support Splunk and other security monitoring technologies as part of incident investigation and automation workflows.
  • Document playbooks, integrations, workflows, troubleshooting procedures, and operational processes.
  • Participate in troubleshooting and resolution of security automation and integration issues.
  • Help maintain and improve security operations procedures, standards, and best practices.

Skills

Cortex XSOAR
Python
Splunk
SOAR automation
Security operations
Incident response

Education

High school diploma or equivalent

Tools

Splunk

Job description

Security Automation / Cortex XSOAR Engineer

Location: Remote

Job Type:Contract-to-Hire

Duration: Contract to 8/2028; extensions possible

Job Summary

We are seeking a Security Automation / Cortex XSOAR Engineer to support and enhance our Security Operations and Incident Response capabilities. This role will focus on developing and maintaining Palo Alto Cortex XSOAR playbooks, automation workflows, and integrations that improve the speed, consistency, and effectiveness of security incident response.

The ideal candidate has strong hands-on experience with Cortex XSOAR, Python, Splunk, and security operations, with the ability to troubleshoot automation issues and work closely with Incident Response and SOC teams.

Key Responsibilities
  • Develop, enhance, and maintain Palo Alto Cortex XSOAR playbooks and automated security workflows.
  • Build automation to support Incident Response and Security Operations processes.
  • Troubleshoot XSOAR integrations, playbooks, scripts, and automation failures.
  • Develop and maintain integrations with security tools, SIEM platforms, and other enterprise technologies.
  • Partner with Incident Response Analysts and SOC teams to identify opportunities for security automation.
  • Analyze security events, incidents, and operational trends to identify areas for improvement.
  • Define and implement new SOAR use cases, automation requirements, and response workflows.
  • Use Python scripting/programming to develop and enhance security automation.
  • Work with security teams to streamline incident response processes and improve operational efficiency.
  • Support Splunk and other security monitoring technologies as part of incident investigation and automation workflows.
  • Document playbooks, integrations, workflows, troubleshooting procedures, and operational processes.
  • Participate in troubleshooting and resolution of security automation and integration issues.
  • Help maintain and improve security operations procedures, standards, and best practices.
Required Qualifications
  • High school diploma or equivalent.
  • 5+ years of hands-on cybersecurity, security operations, incident response, or security automation experience.
  • Strong hands-on experience developing and maintaining Palo Alto Cortex XSOAR playbooks.
  • Experience building and supporting SOAR automation workflows.
  • Strong Python scripting/programming skills.
  • Solid understanding of Incident Response processes and security operations workflows.
  • Hands-on experience with Splunk or another enterprise SIEM platform.
  • Strong troubleshooting and security data analysis skills.
  • Experience developing, maintaining, and troubleshooting automated security playbooks.
  • Ability to work effectively with SOC, Incident Response, Cybersecurity, and Infrastructure teams.
  • Strong written and verbal communication skills.
Preferred Qualifications

Candidates with the following experience will receive priority:

  • CrowdStrike
  • Proofpoint
  • Tanium
  • SIEM technologies
  • Network and security infrastructure
  • Security orchestration and automation
  • API integrations and security tool integrations
  • Additional scripting/programming experience
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Automation Engineer – Cortex XSOAR
Automation Engineer – Cortex XSOAR

Veriipro • Atlanta (GA)

On-site
USD 120,000 - 150,000
Automation Engineer
Automation Engineer

PB consulting • Sandy Springs (GA)

On-site
USD 110,000 - 140,000
Remote Cortex XSOAR & SIEM Security Automation Engineer
Remote Cortex XSOAR & SIEM Security Automation Engineer

Perfict Global, Inc. • United States

Remote
USD 120,000 - 160,000
Cortex XSOAR Security Automation Engineer
Cortex XSOAR Security Automation Engineer

PB consulting • Sandy Springs (GA)

On-site
USD 110,000 - 140,000
Professional Services Consultant – XSIAM Automation
Professional Services Consultant – XSIAM Automation

Trantor • United States

Hybrid
USD 140,000 - 180,000
Cortex XSIAM Security Engineer
Cortex XSIAM Security Engineer

CELESTIAL INNOVATIONS GROUP LLC • Washington

On-site
USD 100,000 - 130,000
401(k)
Competitive salary
Dental insurance
+3
Advanced Cyber Security Engineer
Advanced Cyber Security Engineer

NATIONMIND LLC • Cincinnati (OH)

Hybrid
USD 110,000 - 160,000
Senior Cyber Security Engineer
Senior Cyber Security Engineer

CSC • Wilmington (DE)

On-site
USD 100,000 - 130,000
Annual leave
Tuition reimbursement
Referral bonuses
+1
Cortex XSOAR Automation Engineer - Playbooks & Integrations
Cortex XSOAR Automation Engineer - Playbooks & Integrations

Veriipro • Atlanta (GA)

On-site
USD 120,000 - 150,000
Senior Professional Services Consultant – Cortex XSIAM (SIEM & Automation)
Senior Professional Services Consultant – Cortex XSIAM (SIEM & Automation)

Palo Alto Networks • California

Remote
USD 175,000 - 241,000