TymblHub

© 2026 TymblHub

SIEM - XSOAR Engineer

Deloitte
Posted on
Deloitte logo

Experience
3 - 7 yrs
Job Location
Bengaluru, India
Vacancy
5
Designation
Siem Engineer
Job Type
ONSITE

Job Description

Role & responsibilities

  • 3+ years of hands-on experience with Palo Alto Cortex XSOAR.
  • Strong experience developing and troubleshooting XSOAR playbooks.
  • Good understanding of REST APIs, JSON, HTTP/HTTPS and webhooks.
  • Good understanding of security operations and incident response processes.
  • Working knowledge of Python scripting for XSOAR automation.
  • Ability to troubleshoot Python-based automation scripts.
  • Experience integrating security products using REST APIs.
  • Good understanding of SIEM, EDR/XDR, NDR, Firewall, Threat Intelligence and ITSM technologies.
  • Understanding of MITRE ATT&CK and common SOC detection/response workflows. 
  • Provide L2 engineering and operational support for the Palo Alto Cortex XSOAR platform within a 24x7 SOC environment.
  • Design, develop, configure, test and maintain SOAR playbooks, automations, integrations and incident workflows.
  • Translate SOC use cases and analyst requirements into scalable and repeatable security automation workflows.
  • Troubleshoot failed playbooks, integrations, automation scripts, incident-processing workflows and API connectivity issues.
  • Integrate XSOAR with SIEM, EDR/XDR, NDR, firewalls, WAF, vulnerability management, threat intelligence, email security, IAM and ITSM platforms.
  • Continuously identify opportunities to reduce manual SOC activities through automation and orchestration.
  • Support L1/L2 SOC analysts in troubleshooting automated investigation and response workflows.
  • Ensure SOAR automation follows defined security, change management, audit and operational standards.
  • Configure and administer Cortex XSOAR incidents, incident types, layouts, fields, classifications, mappings and indicators.
  • Develop and maintain XSOAR playbooks for security investigation, enrichment, containment, remediation and ticket management.
  • Configure conditional logic, loops, manual approval steps, data transformations and automated tasks within playbooks.
  • Customize out-of-the-box Palo Alto content packs and playbooks based on client requirements.
  • Troubleshoot playbook execution failures and optimize playbook performance.
  • Manage XSOAR jobs, integrations, instances, content packs and automation dependencies.
  • Maintain documentation for playbooks, integrations, automation workflows and operational procedures.
  • Develop automation for common SOC use cases.  
  • Implement human-in-the-loop controls for high-risk remediation activities.
  • Identify repetitive SOC processes suitable for automation and recommend automation candidates.
  • Develop automation metrics to demonstrate reduction in analyst effort and MTTR.
  • Configure and troubleshoot XSOAR integrations with SIEM platforms, Microsoft Defender other security technologies.
  • Validate API authentication, permissions, connectivity, commands and response payloads.
  • Troubleshoot REST API, webhook, authentication and integration failures.
  • Education: B.E./B.Tech (Tier 1/2) or Masters degree in Information Security, Computer Science, or a related field.
  • Preferred Certifications: Palo Alto Networks Cortex XSOAR certification/training.
  • Security+, CySA+, GCIH or equivalent security certifications



No Referrers Available

There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.