Top 3 requirements:
- 2+ years of hands-on experience in Splunk SOAR, including writing playbooks and troubleshooting.
- 2+ years of hands-on experience using Splunk for both searching/data analysis and for passing data to SOAR.
- Python
- Proficiency with Git
- Experience working with REST and other third-party API integrations.
- Strong understanding of IT security concepts and practices
- Familiarity with enterprise change management
- Ability to debug and diagnose problems and tune orchestrations.
- Are any of them flexible? SOAR – can take people with exp with Phantom.
Day to Day Responsibilities/project specifics:
Work with stakeholders directly to build, design, deliver, re-write, and maintain efficient, reusable, and reliable security automations using Splunk SOAR. This role is highly detail oriented and will require hands-on knowledge of programming languages, APIs, and integrations.
- Review API documentation and connect third-party services to the SOAR platform.
- This role will be responsible for the whole lifecycle of an automation playbook, from requirements gathering and -planning to design, testing, implementation, and maintenance.
- Create detailed technical documentation regarding to your orchestration
- Collaborate with other internal teams as part of setting up SOAR integrations.
- Follow all change management processes and requirements as part of setting up SOAR integrations.