Back to jobs
SOAR Engineer
Sekuro Asia - An Insight CompanyPhilippinesPosted 2w ago
Cybersecurity Analyst
Job Description
About the role
SekuroAsia - An Insight Company, is searching for a SOAR Engineer to join our busy Security Engineering team. Reporting to the Engineering Manager. You will design, build and maintain automation workflows that power our round-the-clock Security Operations Centre and deliver tangible value to our clients. Expertise with Swimlane. SOAR is a welcome advantage, and strong experience with any other SOAR platform will also be considered. You will guide playbook development, integrations and documentation while helping shape the next generation of our SOC services.
Responsibilities
Incident Detection & Response
- Design, develop and maintain SOAR playbooks that automate incident response and security operations tasks for internal analysts and external clients
- Refactor and optimise existing automation to improve reliability, performance and re-use
- Integrate SOAR with SIEM, EDR, ticketing, cloud and network tools by using REST APIs, webhooks and software development kits
- Write clean, well-documented scripts in Python, PowerShell, JavaScript or similar languages to support integrations and data handling
- Translate complex client security use cases into practical automated workflows in partnership with SOC analysts and Detection Engineering
- Act as the subject matter expert for SOAR during incident triage, providing rapid troubleshooting and adjustments to playbooks
- Use Git-based version control, peer reviews and continuous integration pipelines for all playbook releases while fostering an automation first culture across the SOC
- Produce and maintain run-books and technical documentation for internal teams and clients
- Engage with client stakeholders, present automation outcomes, gather feedback and refine solutions
- Contribute technical input and effort estimates to statements of work for upcoming SOAR projects
- Stay informed on product and technology road-maps to ensure our automation strategy leverages current and emerging capabilities
Desired knowledge and skills:
- At least two years in a security-focused role such as SOC, incident response or security engineering
- Hands-on experience building play-books in at least one SOAR platform such as Swimlane, Splunk SOAR, Palo Alto XSOAR, Microsoft Sentinel or Tines.
- Proficiency in a scripting language (Python preferred) and solid understanding of RESTful APIs, JSON and authentication methods such as OAuth 2.0 and API keys
- Broad knowledge of common security use cases including phishing response, EDR containment, vulnerability triage, threat-intel enrichment and user off-boarding
- Familiarity with SIEM pipelines, log formats and alert lifecycles, plus sound understanding of enterprise logging and collection techniques
- Strong analytical and problem-solving skills with a passion for reducing manual effort through automation
- Clear verbal and written communication skills, comfortable presenting to clients and explaining technical detail to non-technical audiences
- Desirable extras include direct Swimlane development experience or certification, cloud security knowledge (AWS, Azure or GCP), infrastructure-as-code skills (Terraform, CloudFormation), container experience (Docker, Kubernetes) and relevant industry certifications such as SSCP or GCIH
What you bring with you:
- Natural curiosity and a drive to innovate through engineering excellence and automation
- A collaborative approach that values partnering with skilled technical teams to deliver secure, friction-free solutions
- The judgement to make sound design decisions, perform risk assessments and identify vulnerabilities so our platforms function at their best
- A hands-on, accountable attitude that keeps projects moving towards successful outcomes
- A love of knowledge sharing and mentoring, balanced with a commitment to continual learning
- An openness to experiment with new ideas, tools and techniques in pursuit of better results for our SOC and our clients
Requirements added by the job poster
• Authorized to work in Philippines