InterSources Inc is seeking a Security Analyst/ Architect – Consultant (SOAR Engineer) to focus on SOAR platform engineering, automation, and orchestration. The role involves designing and developing automation workflows, implementing security orchestration processes, and collaborating with various teams to support centralized security solutions across agencies.
Responsibilities:
- Design and develop automation workflows and SOAR playbooks
- Implement and optimize security orchestration processes
- Build and maintain integrations between:
- SOAR platform
- SIEM
- EDR
- Firewalls and other security tools
- Develop custom scripts (Python, Bash, PowerShell) for advanced automation
- Work with REST APIs, JSON, and YAML for integrations
- Create and maintain:
- Runbooks
- Process documentation
- Troubleshooting guides
- Collaborate with:
- SOC teams
- Incident Response teams
- Engineering teams
- Support adoption of centralized security solutions across agencies
- Provide reporting, dashboards, and performance insights
Requirements:
- Bachelor's Degree in IT / Information Security
- OR 8+ years of relevant experience in lieu of degree
- 5+ years of experience with SOAR or automation platforms
- 5+ years supporting large-scale IT environments or deployments
- Strong scripting experience: Python
- Strong scripting experience: Bash
- Strong scripting experience: PowerShell
- Hands-on experience with REST APIs
- Hands-on experience with JSON
- Hands-on experience with YAML
- Familiarity with MITRE ATT&CK framework
- Experience working in multi-tenant environments
- Experience working in enterprise or multi-agency environments
- Experience with Cortex XSOAR
- Knowledge of security monitoring use cases
- Knowledge of incident response processes
- Certifications: CISSP / CISA / CISO
- Certifications: CEH / OSCP / GPEN
- Certifications: SOAR or automation vendor certifications
- Experience with dashboards and reporting
- Strong communication and stakeholder engagement skills