Cyber Security Automation Engineer
Must-have:PythonAzureCloudSecurity
Machine translation — original language: Hebrew.Show original
A leading company in the industry and security sector is looking for a Cyber Security Automation Engineer for a role that combines Incident Response, SOC, and the development of automations for cyber incident response processes.
The role includes working on SIEM / SOAR systems, developing and maintaining automations and Playbooks for cyber incident response, integration between security systems, and improving incident and alert handling processes.
The role is particularly suitable for a candidate coming from the SOC / Incident Response worlds, who has accumulated experience in handling cyber incidents and alerts, and subsequently gained experience in developing response automations.
Responsibilities:
- Handling and investigating cyber incidents and alerts at Tier 1–2 levels, with an advantage for Tier 3 level experience.
- Performing Incident Response and investigating cyber incidents.
- Development, maintenance, and improvement of Playbooks and automations in SOAR systems.
- Developing automations using Python and scripts.
- Performing integrations between security systems using APIs.
- Working with SIEM / XDR / SOAR systems.
- Automation of Enrichment, Containment, and Response processes.
- Improving SOC workflows and reducing cyber incident response time.
- Collaboration with SOC, Incident Response, and information security teams.
- At least 2–4 years of experience* in Cyber Security / SOC / Incident Response.
- Practical experience in handling and investigating cyber incidents and alerts.
- Experience working as a SOC Analyst, at least at Tier 1–2 levels.
- Experience in Incident Response (IR) – Mandatory.
- At least one year of experience in developing automations for cyber incident response processes – Mandatory.
- Experience working with SIEM / SOAR systems.
- Experience in script/automation development in Python.
- Experience working with APIs and integrations between security systems – Significant advantage.
- Experience with one or more of the following technologies: Azure, Splunk, Palo Alto.
- Very good English level.
- Israeli citizenship – Mandatory.
Advantages
- Experience with Cortex XSOAR / XSIAM / Cortex XDR.
- Experience with Splunk / Microsoft Sentinel / QRadar.
- Experience in Digital Forensics / DFIR.
- Experience in Threat Hunting or Detection Engineering.
- Experience in large Enterprise environments or security environments.
- Experience in developing complex Playbooks in SOAR.
- Familiarity with Cloud environments, with an emphasis on Azure.
- Professional certifications in the cyber field – Advantage.