Senior Cortex XSOAR (formerly known as Demisto) Engineer- Secret Clearance Required
Spry Squared, Inc.About the role
Company Description
Spry Squared is a Minority and Woman Owned Small Business headquartered in Denver, Colorado with offices across the United States of America. We are an experienced federal government and commercial service provider with security cleared personnel working on various projects across the USA and the globe.
Spry Squared provides organizations with Best in Class Enterprise Solutions, Managed IT Services, Cybersecurity Solutions, IT Professional Services, Recruiting Services, Project/Program Management and technology products. We are your strategic partner and value-added reseller, solving complex business challenges by leveraging technology solutions that reduce costs, optimize productivity and minimize risk.
Job Description
An immediate opening for a motivated Senior XSOAR Engineer.
Cortex™ XSOAR (formerly known as Demisto) is a comprehensive security orchestration, automation and response (SOAR) platform that unifies case management, automation, real-time collaboration and threat intel management to serve security teams across the incident lifecycle.
Our client is focused on achieving and maintaining technical advantages using the latest advancements, including custom built cybersecurity capabilities.
As a key part of the team, your responsibilities will be:
- Leading XSOAR technical implementation and automation operations to integrate XSOAR into CVA/A (TIP) and ACD (SOAR).
- Creating documentation and implement XSOAR playbooks using Intelligence Driven Defense, and Defense in Depth methodologies.
- Communicating effectively in crisis situations within all levels of the organization.
- Supporting enterprise incident response efforts.
- Employing automation of advanced forensic tools and techniques for attack reconstruction and intelligence gathering.
- Proactively researching emerging cyber threats.
- Applying analytical understanding of attacker methodologies and tactics, system vulnerabilities, and key indicators of attacks and exploits.
- Collaborating using information and knowledge sharing networks and professional relationships to achieve common goals.
- Providing on-call support for incident response efforts outside of core hours, as required.
- Mentoring junior and senior colleagues technically and conceptually.
- Strategically leading groups of all sizes to manage long and short-term projects.
- Driving advanced countermeasures through to completion.
- Innovating and delivering new types of countermeasures.
- Increasing the outreach of the team internally and externally through shared intelligence and presentations.
Qualifications
REQUIRED QUALIFICATIONS
- Requires up to 25% ONSITE with remainder working remotely.
- MUST HAVE an active SECRET Clearance.
- BS Degree and 12+ years relevant experience in cyber security or network defense, or 7+ years’ experience with relevant certifications (CISSP, SANS GIAC, CEH, etc.).
- Requires experience in cyber security engineering automation and orchestration platforms, specifically XSOAR (formerly known as Demisto).
- Experience debugging software and determining the root cause.
- Programming experience in Python.
- Experience and familiarity with IDS/IPS, SIEM, Splunk and endpoint solutions.
- Experience supporting and contributing to incident response activities
- Strong understanding of Operating Systems and Network Protocols.
- Proficiency with Microsoft Windows administrative tools, and the Unix/Linux command line.
PREFERRED QUALIFICATIONS
- Understanding of behavioral based threat models, including ATT&CK, Cyber Kill Chain, Diamond Model, etc.
- Experience with Splunk or other SIEM-type platforms.
- Experience in conventional network/host-based intrusion analysis, digital forensics, or malware analysis.
- Capable and comfortable communicating actionable threat intelligence to both technical and executive-level stakeholders.
- Experience defending large cloud infrastructures, including AWS, Azure, etc.
- Experience developing solutions in the cloud, including AWS, Azure, etc.
- Experience using and integrating with various open-source intelligence (OSINT) sources.
- Ability to create, modify, and implement both Snort and YARA signatures.
- Published research papers at conferences or through other mediums (blogs, articles).
- Working knowledge of Computer Network Exploitation (CNE), Computer Network Attack (CNA) and Computer Network Defense (CND) tools and techniques.
- Preferred Certifications
o Palo Alto Networks Certified Security Automation Engineer (PCSAE)
o Palo Alto Networks Micro-Credential for Cortex XSOAR Consultant (PMXrC)
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s