Tasks
As a SOAR Engineer in the Cyber ??Defense Center (CDC), you will play a key role in automating and optimizing security operations processes. Your focus will be on the implementation and further development of SOAR solutions, particularly based on IBM Resilient and other automation tools. With your technical and methodological expertise, you will design effective and scalable incident response workflows, optimize existing CERT processes, and actively contribute to increasing efficiency in security operations – both internally and for our customers.
The following tasks await you:
Design, implementation, and further development of SOAR playbooks, particularly with IBM Resilient, for the automation and orchestration of incident response processes in the SOC.
Close collaboration with analysts, incident responders, and threat intelligence teams to identify, implement, and continuously improve automation potential.
Integration of IBM Resilient with third-party systems such as SIEM, ticketing systems, threat feeds, and other relevant security components for holistic process automation.
Optimization of CERT and SOC processes through automated, structured workflows, as well as the development and maintenance of use cases and response strategies for more effective incident handling.
Training and coaching of SOC analysts in the use of the SOAR platform and best practices for handling automated processes.
Collaboration on security policies and response plans, as well as continuous evaluation of new SOAR technologies and automation trends to further develop the CDC automation approach.
For more detail, salary and company information, use the apply link