Senior SOAR Engineer
Gabi
Company Description
Ready to make a difference? Experian has evolved into a global tech company and leader in data and analytics. We're passionate about unlocking the power of data in order to transform lives and create opportunities for consumers, businesses and society. We're a constituent of the FTSE 30 and for more than 125 years we've helped economies and communities flourish – and we're not done.
Discover the Unexpected - Our 22k amazing employees in 30+ countries believe the possibilities for you, and the world, are growing. We're investing in the future, through new technologies, talented people and innovation so we can help create a better tomorrow. To do this we employ 'big-thinkers' and 'can-doers' that share our purpose #uniquelyexperian
Job Description
The Systems Security Engineer is part of the security integrations & Analytics team in the Experian GSO. This role will serve as an engineer responsible for the innovation, development, and maintenance of SOAR, SIEM & UEBA systems. Specific focus will be directed to SOAR automation integrating with other software solutions including ServiceNow, SIEM, IOC vendors, Vulnerability Management tools, and other security controls. This Engineer will be responsible for the development, implementation, and maintenance of automating Engineering/GSOC processes and data enrichment in the SIEM system. An ideal candidate will have extensive information security experience particularly in incident response, general security tool operations and able to apply that knowledge to drive future automation to reduce delivery times and process efficiencies. The Systems Security Engineer will work closely with the various internal teams, including but not limited to cyber threat intelligence analysts, SOC analysts, incident management, server and network administrators, security tool administrators, and business unit customers.
What you’ll be doing
- Understand of various security controls and logs that feed the SIEM & UEBA technologies.
- Ability to dissect operational processes converting them to detailed requirements to build an automated workflow.
- Ability to develop leveraging Python leveraging Restful integrations to the different systems at Experian.
- Remediate vulnerabilities in the SOAR environment
- Work with the other security functions and product SMEs to identify opportunities to automate GSOC or engineering processes to prevent security threats.
- Development of parsers/field extractions into the SOAR platform
- Development of custom scripts as required to augment default SIEM functionality
- Participate in root cause analysis on security incidents and provide recommendations for containment and remediation
- Act as the liaison to business units to fulfill audit, regulatory compliance and/or corporate security policy requirements.
- Create, implement and maintain novel analytic methods and techniques for incident detection
- Ensure documentation for automation is available on team wiki- specifically including automated process flows across tools
Qualifications
More about you
Required Qualifications:
- 5+ years Python development skills
- Prior experience developing on a SOAR platform automating security engineering or GSOC playbooks.
- Experience in gathering requirements of existing manual processes and converting them into automated workflows
- Understanding of various log formats and source data for SOAR Analysis
- Strong Experience in working in an Agile environment utilizing SCRUM or KANBAN methodologies
- Solid background with Windows and Linux platforms (security or system administration)
- Ability to effectively communicate with anyone, from end users to senior leadership- facilitating technical and nontechnical conversations.
- Strong incident handling/incident response/security analytics skills
- Deep understanding of technical concepts including networking and various cyber attacks
- Solid comprehension of various security controls, capabilities and use in a corporate environment
- Exceptional problem-solving capabilities
- Strong experience in developing and maintaining Restful API’s
- Strong documentation and communication skills
- Demonstrated history of innovation and/or creativity
- Ability to drive process improvements and identify gaps
- Knowledge of programming/scripting fundamentals
Desired Skills & Experience:
- 3+ years of information security experience, preferably engineering or development
- 2+ years’ experience supporting a SOAR platform in a content development or administrative role
- 2+ years’ experience leading teams directing work efforts utilizing Agile methodologies
- 2+ years’ experience performing SOC analysis and/or incident response
- 2+ years’ experience working with cloud computing
- Bachelor’s Degree or higher degree in Computer Science, Information Security or similar discipline is preferred
- Experience with a wide range of security products
- Industry Security Certifications (CISSP, SANS) preferred
Additional Information
Our uniqueness is that we truly celebrate yours. Experian's culture and people are key differentiators. We take our people agenda very seriously and focus on what truly matters; DEI, work/life balance, development, authenticity, engagement, collaboration, wellness, reward & recognition, volunteering... the list goes on. Experian's strong people first approach is award winning; Great Place To Work™ in 24 countries, FORTUNE Best Companies to work and Glassdoor Best Places to Work (globally 4.4 Stars) to name a few. Check out Experian Life on social or our Careers Site to understand why.
Experian is proud to be an Equal Opportunity and Affirmative Action employer. Innovation is a critical part of Experian's DNA and practices, and our diverse workforce drives our success. Everyone can succeed at Experian and bring their whole self to work, irrespective of their gender, ethnicity, religion, colour, sexuality, physical ability or age. If you have a disability or special need that requires accommodation, please let us know at the earliest opportunity.
Experian Careers - Creating a better tomorrow together
Find out what its like to work for Experian by clicking here