← Back to your search

NCC Group

SOAR Engineer (SPLUNK)

Engineering

Employment

Not stated

Level

Not stated

Category

Engineering
Not doable from Austria

Country assessment

Not doable from Austria because it is remote but scoped to United Kingdom.

Our assessment is guidance. Confirm arrangements with the employer.

Skills mentioned in this posting

PythonJavaLinux

Job description

The Senior SOAR Engineer designs, builds and maintains security automations that detect, investigate and respond to cyber threats. The role works closely with Incident Response to identify improvements, create new playbooks and deliver scalable automation within the Splunk ecosystem. Responsibilities include advanced analytics, scripting, creating new use cases, validating automation behaviour, documenting changes and mentoring junior engineers.

Work in partnership with the incident response team to design, identify, and implement opportunities for improvement Develop, and implement automations for detection and response. Be the subject matter experts on big data analytics and automation Participate in special projects, as needed, and perform other duties as assigned Produce System Analytics to prove automation behaviour assumptions Document all system changes in line with Change Management good practices Recommend, Develop and Release new Use Cases to maximize the benefits and efficiencies from a SOAR platform.

Mentor junior members of the SOAR team. Complete Quality Assurance on work completed by other members of the team before it is implemented in production. Experience with Splunk, Splunk Enterprise Security, Splunk SOAR (Formerly Splunk Phantom) and Splunk User Behaviour Analytics Develop, and implement automations for detection and response. Produce System Analytics to prove automation behaviour assumptions A passion for security automation and a solid understanding of security incident response Knowledge of security frameworks including MITRE ATT&CK, NIST, etc.

Working experience and knowledge of operating systems (e.g.: Windows, UNIX/Linux) and databases Knowledge in various scripting and programming languages (Java, Perl, R, Python, C++) Desirable: Understanding of NIS regulations Understanding of CNI and ideally the Energy Sector. Ideally having worked on a CNI environment/client. Understanding of NCSC CAF and IT/OT controls such as NIST Integration of SOAR (Splunk) with OT specific IDS such as Nozomi, Claroty, Dragos, etc.

Playbook development.