Posted on: 17/11/2025
Description :
You'll be working as a SOAR developer on our Endpoint Detection Team, responsible for ensuring the quality and scale of our response actions and automated responses to our Security Services teams and customers.
Responsibilities :
- Providing mentorship and technical leadership to the team.
- Audit the current response capabilities versus the opportunities based on individual EDRs' APIs.
- Run end-to-end testing and help improve or automate this process to ensure quality.
- Participate in the full software development life cycle, building well-designed, testable, efficient, secure code.
- Interface with Security Services teams, Product Management, Incident Response, and customers to identify further SOAR capabilities to help expedite investigations/forensics, automate detections, and generally improve the security exposure of customers.
- Update technical documentation to reflect changes in workflows, integrations, and system configurations.
- Help shape the roadmap of our SOAR platform capabilities and architecture.
- Stay informed about the latest security threats, SOAR platform updates, and automation best
practices to continuously improve system effectiveness.
- Develop professional expertise, apply company policies and procedures to resolve a variety of issues.
- Determine a course of action based on guidelines, and modify processes and methods as
required.
- Continuously learning and adopting best practices for code quality, software development methodologies, and programming principles to enhance coding skills and stay updated with
industry advancements.
Requirements :
- 6 or more years of professional experience as a software developer with a focus on JavaScript and Python, including at least 3 years of experience in developing security automation
solutions within SOAR platforms.
- Experience with RESTful APIs, JSON, and other web technologies; familiarity with Python is a
must.
- Hands-on experience with SOAR platforms such as Palo Alto Cortex XSOAR, Splunk SOAR
(formerly Phantom), or IBM Resilient, including playbook development and system integration.
- Experience integrating with security tools like centralized logging (e. g., Splunk, ELK stack),
EDRs, threat intelligence platforms, and ticketing systems (e. g., ServiceNow, Zendesk).
- Strong analytical and problem-solving skills with the ability to troubleshoot complex
integration and automation issues.
- Excellent verbal and written communication skills, with the ability to convey technical
concepts to non-technical stakeholders.
- Experience and interest in mentoring junior employees. This role will help teach detection
engineers how to best leverage SOAR while writing detections and expand their technical
abilities to write their own SOAR playbooks and integrations.
- Experience working in Agile development environments, preferably with formal Agile training,
utilizing tools like JIRA and Confluence.
Did you find something suspicious?
Posted By
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1575988
Interview Questions for you
View All