Security SOAR Engineering Python Developer - 100% US REMOTE
ExperianAbout the role
Company Description
Experian is the world’s leading global information services company, unlocking the power of data to create more opportunities for consumers, businesses and society. We are thrilled to share that FORTUNE has named Experian one of the 100 Best Companies to work for. In addition, for the last five years we’ve been named in the 100 “World’s Most Innovative Companies” by Forbes Magazine.
Job Description
The Systems Security Engineer is part of the security integrations & Analytics team in the Experian GSO. This role will serve as an engineer responsible for the innovation, development, and maintenance of SOAR, SIEM & UEBA systems. Specific focus will be directed to SOAR automation integrating with other software solutions including ServiceNow, SIEM, IOC vendors, Vulnerability Management tools, and other security controls. This Engineer will be responsible for the development, implementation, and maintenance of automating Engineering/GSOC processes and data enrichment in the SIEM system. An ideal candidate will have extensive information security experience particularly in incident response, general security tool operations and able to apply that knowledge to drive future automation to reduce delivery times and process efficiencies. The Systems Security Engineer will work closely with the various internal teams, including but not limited to cyber threat intelligence analysts, SOC analysts, incident management, server and network administrators, security tool administrators, and business unit customers.
Major Responsibilities include:
Understand of various security controls and logs that feed the SIEM & UEBA technologies.
Ability to dissect operational processes converting them to detailed requirements to build an automated workflow.
Ability to develop leveraging Python leveraging Restful integrations to the different systems at Experian.
Remediate vulnerabilities in the SOAR environment
Work with the other security functions and product SMEs to identify opportunities to automate GSOC or engineering processes to prevent security threats.
Development of parsers/field extractions into the SOAR platform
Development of custom scripts as required to augment default SIEM functionality
Participate in root cause analysis on security incidents and provide recommendations for containment and remediation
Act as the liaison to business units to fulfill audit, regulatory compliance and/or corporate security policy requirements.
Create, implement and maintain novel analytic methods and techniques for incident detection
Ensure documentation for automation is available on team wiki- specifically including automated process flows across tools
Qualifications
Required Skills & Experience:
5+ years Python development skills
Prior experience developing on a SOAR platform automating security engineering or GSOC playbooks.
Experience in gathering requirements of existing manual processes and converting them into automated workflows
Understanding of various log formats and source data for SOAR Analysis
Strong Experience in working in an Agile environment utilizing SCRUM or KANBAN methodologies
Solid background with Windows and Linux platforms (security or system administration)
Ability to effectively communicate with anyone, from end users to senior leadership- facilitating technical and non-technical conversations.
Strong incident handling/incident response/security analytics skills
Deep understanding of technical concepts including networking and various cyber attacks
Solid comprehension of various security controls, capabilities and use in a corporate environment
Exceptional problem-solving capabilities
Strong experience in developing and maintaining Restful API’s
Strong documentation and communication skills
Demonstrated history of innovation and/or creativity
Ability to drive process improvements and identify gaps
Knowledge of programming/scripting fundamentals
Desired Skills & Experience:
3+ years’ of information security experience, preferably engineering or development
2+ years’ experience supporting a SOAR platform in a content development or administrative role
2+ years experience leading teams directing work efforts utilizing Agile methodologies
2+ years’ experience performing SOC analysis
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s