Job Requirements
San Antonio, TX
Top Secret/SCI Polygraph not specified
Mid Level Career (5+ yrs experience)
Salary not specified
Join Premium to unlock estimated salaries
Job Description
GES is seeking an experienced SOAR Engineer to support a large-scale cybersecurity operations environment. The selected candidate will help integrate and maintain a Global Security Information and Event Management (SIEM) platform with a Global Security Orchestration, Automation and Response (SOAR) platform, while developing automation and integrations that improve security analyst efficiency.
This role is ideal for a cybersecurity professional with hands-on experience with Palo Alto Cortex XSOAR, SIEM/SOAR integrations, automation playbooks, connectors, cloud-hosted applications, and enterprise security tools.
Clearance Requirement
Active Top Secret (TS) clearance is required.
What You Will Do
Support the integration of the Global SIEM with the Global SOAR platform to enable automated receipt and triage of SIEM-generated alerts.
Develop and maintain integrations between SOAR and U.S. Air Force (USAF) systems, including Tanium, Microsoft Defender, Patriot, and other mission-relevant platforms.
Partner with SIEM engineering teams to identify vendor data sources and establish appropriate connectivity and integrations.
Design, develop, test, and maintain SOAR automation playbooks in Palo Alto Cortex XSOAR.
Partner with content development teams to create playbooks that reduce manual analyst workload and improve operational efficiency.
Monitor SOAR cluster health and detection rule performance, identifying and resolving issues affecting orchestration, automation, and alerting.
Build and troubleshoot connectors and integrations between SOAR and third-party security platforms.
Validate dashboards for accuracy, availability, and relevance to cybersecurity operations and end users.
Gather analyst feedback and translate it into improvements to SOAR playbooks, dashboards, and workflows.
Analyze system health and performance data to troubleshoot orchestration and operational issues.
Support applications hosted in cloud environments.
Collaborate with cybersecurity analysts, content developers, engineering teams, and government stakeholders.
Develop and maintain technical documentation and communicate technical information effectively.
Required Qualifications
Active Top Secret (TS) clearance.
Working knowledge of SOAR platforms, particularly Palo Alto Cortex XSOAR/XSOAR.
Experience integrating SOAR platforms with SIEM technologies, such as Elastic SIEM.
Hands-on experience developing, testing, and maintaining automation playbooks within a SOAR environment.
Experience building and troubleshooting connectors and integrations between SOAR and third-party vendor systems.
Familiarity with cybersecurity tools and enterprise security data sources such as Tanium, Microsoft Defender, Patriot, or comparable platforms.
Ability to analyze detection rule and SOAR cluster health data and troubleshoot orchestration or performance issues.
Experience managing or supporting cloud-hosted applications.
Strong collaboration skills and the ability to work effectively with cybersecurity analysts, content developers, engineers, and government stakeholders.
Strong written and verbal communication skills with the ability to translate analyst feedback into actionable engineering improvements.
Preferred Qualifications
Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related field, or equivalent experience.
Experience in SOAR/SIEM engineering or cybersecurity operations.
Previous experience supporting government or DoD cybersecurity operations environments.
Familiarity with Air Force Cloud One and running applications within Air Force cloud environments
This role is ideal for a cybersecurity professional with hands-on experience with Palo Alto Cortex XSOAR, SIEM/SOAR integrations, automation playbooks, connectors, cloud-hosted applications, and enterprise security tools.
Clearance Requirement
Active Top Secret (TS) clearance is required.
What You Will Do
Support the integration of the Global SIEM with the Global SOAR platform to enable automated receipt and triage of SIEM-generated alerts.
Develop and maintain integrations between SOAR and U.S. Air Force (USAF) systems, including Tanium, Microsoft Defender, Patriot, and other mission-relevant platforms.
Partner with SIEM engineering teams to identify vendor data sources and establish appropriate connectivity and integrations.
Design, develop, test, and maintain SOAR automation playbooks in Palo Alto Cortex XSOAR.
Partner with content development teams to create playbooks that reduce manual analyst workload and improve operational efficiency.
Monitor SOAR cluster health and detection rule performance, identifying and resolving issues affecting orchestration, automation, and alerting.
Build and troubleshoot connectors and integrations between SOAR and third-party security platforms.
Validate dashboards for accuracy, availability, and relevance to cybersecurity operations and end users.
Gather analyst feedback and translate it into improvements to SOAR playbooks, dashboards, and workflows.
Analyze system health and performance data to troubleshoot orchestration and operational issues.
Support applications hosted in cloud environments.
Collaborate with cybersecurity analysts, content developers, engineering teams, and government stakeholders.
Develop and maintain technical documentation and communicate technical information effectively.
Required Qualifications
Active Top Secret (TS) clearance.
Working knowledge of SOAR platforms, particularly Palo Alto Cortex XSOAR/XSOAR.
Experience integrating SOAR platforms with SIEM technologies, such as Elastic SIEM.
Hands-on experience developing, testing, and maintaining automation playbooks within a SOAR environment.
Experience building and troubleshooting connectors and integrations between SOAR and third-party vendor systems.
Familiarity with cybersecurity tools and enterprise security data sources such as Tanium, Microsoft Defender, Patriot, or comparable platforms.
Ability to analyze detection rule and SOAR cluster health data and troubleshoot orchestration or performance issues.
Experience managing or supporting cloud-hosted applications.
Strong collaboration skills and the ability to work effectively with cybersecurity analysts, content developers, engineers, and government stakeholders.
Strong written and verbal communication skills with the ability to translate analyst feedback into actionable engineering improvements.
Preferred Qualifications
Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related field, or equivalent experience.
Experience in SOAR/SIEM engineering or cybersecurity operations.
Previous experience supporting government or DoD cybersecurity operations environments.
Familiarity with Air Force Cloud One and running applications within Air Force cloud environments
group id: 91136213