
Engineering
Posted Jul 13

Posted Jul 13
This is a fully remote position, open to applicants in Ireland.
• Design, develop, test, and maintain SOAR playbooks to facilitate the automation of security incident detection, investigation, and response.
• Integrate the SOAR platform with ITSM solutions, SIEM platforms, security tools, and enterprise applications via APIs and connectors.
• Create scripts and automation workflows utilizing supported scripting languages such as Python, PowerShell, and Bash.
• Implement and orchestrate automated response actions, which include: updating firewall rules and blocking IPs, disabling Active Directory (AD) user accounts, isolating and quarantining endpoints, extracting packet captures (PCAP), and acquiring memory dumps for forensic analysis.
• Develop API integrations with both internal and third-party security solutions.
• Collaborate with SOC analysts and incident responders to automate repetitive security operations and enhance incident handling processes.
• Troubleshoot and optimize automation workflows to ensure they are reliable, efficient, and accurate.
• Document playbooks, integration procedures, automation workflows, and operational runbooks.
• Ensure that automation activities adhere to organizational security policies and governance requirements.
• Participate in continuous improvement initiatives aimed at expanding automation coverage and enhancing SOC maturity.
• Bachelor's degree in Computer Science, Cybersecurity, Information Technology, Engineering, or a related field.
• Demonstrated experience in implementing and managing SOAR platforms.
• Strong proficiency in developing automation playbooks and security workflows.
• Practical experience with REST APIs, scripting (Python, PowerShell, Bash), and system integrations.
• Experience in integrating SOAR with ITSM platforms and security tools.
• Knowledge of SOC operations and incident response processes.
• Experience automating tasks such as firewall blocking, disabling Active Directory accounts, quarantining endpoints, extracting PCAP, and collecting memory dumps.
• Excellent analytical, troubleshooting, and communication skills.
• Clear scope with no ambiguity regarding deliverables.
• Opportunity for repeat engagements based on performance.
ON Partners
Ledgebrook
Get handpicked remote jobs straight to your inbox weekly.