Job Title:  T&T | Cyber : D&R | Assistant Manager | XSOAR | Bengaluru

T&T | Cyber : D&R | Assistant Manager | XSOAR | Bengaluru
Job requisition ID : 111120 
Location: Bengaluru
Entity: Deloitte Touche Tohmatsu India LLP 

 

The team  

Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Learn more about Cybersecurity  

 

Your work profile 

We are seeking a skilled and proactive SOAR Engineering Specialist to join our Security Operations team. The ideal candidate will be responsible for designing, developing, implementing, and maintaining security automation and orchestration capabilities using Palo Alto Cortex XSOAR. The role will play a key part in developing and optimizing playbooks, automations, integrations, and response workflows to streamline security operations, improve incident response efficiency, and reduce manual effort. The candidate will also be responsible for troubleshooting automation workflows, developing API- and Python-based integrations, and continuously enhancing the organization’s SOAR capabilities to support effective and timely detection, investigation, and response to security incidents.

 

Key Skills Required:

  • 3+ years of hands-on experience with Palo Alto Cortex XSOAR.
  • Strong experience developing and troubleshooting XSOAR playbooks.
  • Good understanding of REST APIs, JSON, HTTP/HTTPS and webhooks.
  • Good understanding of security operations and incident response processes.
  • Working knowledge of Python scripting for XSOAR automation.
  • Ability to troubleshoot Python-based automation scripts.
  • Experience integrating security products using REST APIs.
  • Good understanding of SIEM, EDR/XDR, NDR, Firewall, Threat Intelligence and ITSM technologies.
  • Understanding of MITRE ATT&CK and common SOC detection/response workflows. 
  • Provide L2 engineering and operational support for the Palo Alto Cortex XSOAR platform within a 24x7 SOC environment.
  • Design, develop, configure, test and maintain SOAR playbooks, automations, integrations and incident workflows.
  • Translate SOC use cases and analyst requirements into scalable and repeatable security automation workflows.
  • Troubleshoot failed playbooks, integrations, automation scripts, incident-processing workflows and API connectivity issues.
  • Integrate XSOAR with SIEM, EDR/XDR, NDR, firewalls, WAF, vulnerability management, threat intelligence, email security, IAM and ITSM platforms.
  • Continuously identify opportunities to reduce manual SOC activities through automation and orchestration.
  • Support L1/L2 SOC analysts in troubleshooting automated investigation and response workflows.
  • Ensure SOAR automation follows defined security, change management, audit and operational standards.
  • Configure and administer Cortex XSOAR incidents, incident types, layouts, fields, classifications, mappings and indicators.
  • Develop and maintain XSOAR playbooks for security investigation, enrichment, containment, remediation and ticket management.
  • Configure conditional logic, loops, manual approval steps, data transformations and automated tasks within playbooks.
  • Customize out-of-the-box Palo Alto content packs and playbooks based on client requirements.
  • Troubleshoot playbook execution failures and optimize playbook performance.
  • Manage XSOAR jobs, integrations, instances, content packs and automation dependencies.
  • Maintain documentation for playbooks, integrations, automation workflows and operational procedures.
  • Develop automation for common SOC use cases.  
  • Implement human-in-the-loop controls for high-risk remediation activities.
  • Identify repetitive SOC processes suitable for automation and recommend automation candidates.
  • Develop automation metrics to demonstrate reduction in analyst effort and MTTR.
  • Configure and troubleshoot XSOAR integrations with SIEM platforms, Microsoft Defender other security technologies.
  • Validate API authentication, permissions, connectivity, commands and response payloads.
  • Troubleshoot REST API, webhook, authentication and integration failures.
  • Education: B.E./B.Tech (Tier 1/2) or Master’s degree in Information Security, Computer Science, or a related field.
  • Preferred Certifications: Palo Alto Networks Cortex XSOAR certification/training.
  • Security+, CySA+, GCIH or equivalent security certifications