Job DescriptionJob Title: Security Operations Center (SOC) 2&plus years of experience with SOAR platforms such as Phantom, Cortex XSOAR, Swimlane, etc Job Description: SOAR Developer / Senior Consultant Are you interested in improving the cyber and organizational risk profiles of leading companies? Do you want to be involved in projects ranging from Fusion Center / Security Operations Center (SOC) strategic development to maturity assessments to implementation of leading threat monitoring, detection and analytics technologies? Can you deal with changing requirements from project to project, learn what you need to get the job done, and produce accurate and timely results? If yes, then Client's Cyber team could be the place for you! Client's Cyber services help organizations create a cyber-minded culture and become stronger, faster, more innovative, and more resilient in the face of persistent and ever-changing cyber threats Join our team of Cyber professionals who focus on helping clients design and implement transformation enterprise security programs with an emphasis on defending against, recovering from, and remediating major cyberattacks As a Cyber Senior Consultant for Client's Cyber services, you'll work with our diverse teams of leading professionals to help design and implement solutions to some of today's toughest cybersecurity challenges so they can achieve business growth and manage risk In your role as a Senior Consultant, you will support a team in delivering projects across a variety of cyber topics, including such examples as: Providing Client's perspective on the latest SOC trends via current state maturity assessment, do now/do next/do later roadmap Assisting clients in identifying and deploying security analytics, alerting and automation solutions based on their organizational requirements technical integration with key data inputs (e.
g raw security telemetry coupled with referential data) Conduct detailed process and technical analysis to identify candidate IR processes for automation and implement process improvements and automations to improve incident triage, investigate and containment activities Enhancing and documenting existing SOC processes to increase centralized visibility in order to identify suspicious activity to reduce the mean time to detect and respond to cyber threats Responsibilities: Increase maturity of key SOC capabilities across governance, people, processes and technology to proactively monitor, detect, investigate, and respond to known and unknown attacks Drive impact of SIEM solution changes on the operational efficiencies of the Security, Network operational teams Evaluate current state against target state,,identifying issues such as workflow gaps, technology limitations or deficiencies, and resource dependencies and design incident response programs supporting security automation and orchestration Facilitate and/or gather inputs and requirements to formulate content to include workflows, reports, dashboards, playbooks, threat Client, incident analysis etc Assist with process development and process improvement for Security Operations to include creation/modification of SOPs, Playbooks, and Work instructions Author, test, and maintain automation scripts/workflows within SOAR platform Design, implement, and maintain efficient and reusable Python code Review, debug, and resolve technical issues throughout all stages of Playbook development Integrate SOAR platform with other security tools and APIs through platform inbuilt apps and custom apps to execute automated workflows Measure effectiveness of process improvement and automation efforts via metrics and KPIs Facilitate process walkthrough discussions to document end-to-end business processes and functional requirements Assist in the selection and tailoring of approaches, methods and tools to support service offering or industry projects Support effective project and program kickoff, identification of all program stakeholders, defining and clarifying program roles and responsibilities.
Ability to demonstrate an investigative mindset Not just being able to execute a task but being able to understand the reason for that task, and determine next steps depending on the results while maintaining a firm grasp of the overall goals of the entire process Excellent communication, listening & facilitation skills Preferred: Experience interpreting, searching, and manipulating data within enterprise logging solutions (eg SIEM, IT Service Management (ITSM) tools, workflow, and automation) Certifications CISSP, CISA, CISM, GCIH, GMON, GCDA, GPEN, GCFA, GCTI Experience with consulting skills (client service orientation, conflict resolution, analysis/synthesis of information, negotiation, project management, etc) Demonstrated leadership and team-building abilities Demonstrable personal interest in computing, security, and digital communicatio