SOAR Consultant
Remote from CST
9-12 months
The SIEM/SOAR Consultant will be responsible for developing and implementing log ingestion strategies, detection frameworks, and automation workflows using platforms such as Cortex XSOAR and Cortex XSIAM.
Skills
- 8+ years of experience deploying and integrating SIEM and SOAR solutions in enterprise environments
- Experience with Security Operation Centers tooling and processes
- Proven ability to coordinate event collection, log management, compliance automation, and identity monitoring using SIEM platforms
- Strong skills in Regular Expressions and log analysis
- Demonstrated proficiency in cyber security platforms: SOAR, SIEM, IDS/IPS, DLP, WAF, Endpoint Security
- Experience with SIEM technologies such as Splunk, IBM QRadar, and Cortex XSIAM
- Experience with SOAR platforms such as Cortex XSOAR, including playbook development
- Ability to understand logs and locate/interpret third-party documentation
- Familiarity with SIEM performance metrics (e.g., log collection rate, number of sources)
- Knowledge of Security Analysis & Response across endpoint, network, and cloud environments