Cyber Security architect
columbia, SC (On-Site)
Job Description:
Scope of the project: the position will work as a security consulting Orchestration, automation, and response engineer within the division of Information security. This role will focus on playbook development and Orchestration, workflow automation, and logic optimization within the state soar platform. They will also build and maintain integrations between the state soar platform, siem, edr, firewalls, and other necessary security tools. Engaging directly with state agencies to promote, support, and improve adoption of centralized security services is a key focus. The engagement is expected to be needed for 12 months with the possibility of extension.
Daily Duties
- Provide technical expertise and experience in creating efficient automation workflows.
- Develop, implement automations and optimize existing automations in response to security alerts and incidents.
- Build and maintain integrations with the soar platform.
- Create custom scripts when required to provide functionality not supported out of the box integrations.
- Document processes, runbooks, and troubleshooting steps related to the soar and integrations.
- Proactively coordinate with engineering, soc, and ir support as needed to meet goals.
- other duties as needed
Additional skills/duties:
- Experience with dashboard creation and reporting.
- Excellent communication and customer service skills for agency-facing engagement.
Preferred skills (rank in order of importance):
- Experience creating automations within the cortex xsoar platform.
- Knowledge of security monitoring use cases and incident response support.
Key Skills:
- SOAR, Playbook, Cortex, Python, PowerShell, RestAPI, JSON,Mitre