Architect, implement, and develop automations within the SOAR system/case management with a focus on modern platforms including:
Splunk SOAR/Phantom
Palo Alto XSOAR
Microsoft Sentinel
Tines
Torq
Google SecOps / Chronicle
CrowdStrike Fusion
Palo Alto XSIAM
SentinelOne HyperAutomation
Design and develop automations and case management templates to ease analyst investigation/remediation
Expertise developing SOC and security-focused content and automation
Scripting and development skills (BASH, Perl, Python or Java) with strong knowledge of regular expressions
Ability to autonomously prioritize and successfully deliver across a portfolio of projects
Some travel may be required to clients in the Northeast region
Security Implementation Engineers work from remote/virtual when not visiting client locations
Requirements
3-5 years of security engineering experience
Hands-on experience with at least one of the following SOAR platforms:
Splunk SOAR/Phantom
Palo Alto XSOAR
Microsoft Sentinel
Tines
Torq
Google SecOps / Chronicle
CrowdStrike Fusion
Palo Alto XSIAM
SentinelOne HyperAutomation
Familiarity with detection engineering, threat modeling, and MITRE ATT&CK framework.
Proficiency with scripting (e.g., Python, PowerShell, Bash) and regular expressions.
Deep understanding of logging from cloud (AWS, Azure, GCP) and on-prem environments.
Tech Stack
AWS
Azure
Cloud
Google Cloud Platform
Java
Perl
Python
Splunk
Benefits
Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family).
Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans
12 corporate holidays and a Flexible Time Off (FTO) program
Healthy mobile phone and home internet allowance
Eligibility for retirement plan after 2 months at open enrollment