Summary
✨ AI‑Generated
A remote six-month security engineering contract for a cleared professional specializing in security orchestration and automation. You will deploy and configure an automation platform, integrate SIEM, endpoint, identity, firewall, and ticketing systems, build incident-response playbooks, and validate production workflows.
Highlights
Six-month remote security engineering contract focused on deploying and operationalizing security orchestration and automation. The role provides hands-on exposure to incident workflows, SIEM and EDR integrations, automated response playbooks, and enterprise security tooling.
Description
6 month remote contract
Valid Secret security clearance required
XSOAR Engineer (Implementation & Deployment)
Role Overview
Deploy, configure, and operationalize Palo Alto Cortex Security Orchestration, Automation, and Response (XSOAR), implementing automation playbooks, integrations, and incident workflows to support the Security Operations Centre (SOC).
Key Responsibilities
Deploy and configure Cortex XSOAR platform componentsImplement incident ingestion from Elastic SIEM into XSOARBuild and maintain automation playbooks:Phishing responseSuspicious loginMalware alertsConfigure and maintain integrations with:Elastic SIEMEndpoint Detection and Response (EDR) toolsFirewalls and network toolsIdentity and Access Management (IAM) systemsTicketing platforms (ServiceNow, Jira)Implement Role-Based Access Control (RBAC) and tenant separationConfigure incident types, fields, layouts, and workflows (SecIM)Perform testing and validation of playbooks and integrationsTroubleshoot:Integration failuresPlaybook errorsAPI connectivity issuesSupport platform monitoring, upgrades, and maintenanceAssist with automation scripting (Python, APIs)Support deployment automation and configuration managementWork closely with Architects and SOC teams to refine workflows
Required Skills
Hands-on experience with Palo Alto Cortex XSOARExperience building automation playbooks and integrationsStrong knowledge of application programming interfaces (APIs)Scripting experience (Python preferred)Understanding of incident response workflowsExperience with Linux systems and troubleshooting
Ideal Candidate Experience
3–7+ years in Security Operations, Incident Response, or Security Engineering2–4+ years hands-on experience with Cortex XSOARExperience implementing playbooks and automation in production SOC environmentsExperience integrating SIEM, EDR, identity, and ticketing toolsFamiliarity with:Continuous Integration and Continuous Deployment (CI/CD) pipelinesInfrastructure as Code (IaC) (nice to have)Experience in large-scale or enterprise environmentsExposure to regulated environments
ACCESSIBILITY
We’re committed to fostering an inclusive, equitable, and accessible workplace where every team member feels valued, respected, and supported, and has the opportunity to reach their full potential.
We welcome and encourage applications from people with disabilities.
Accommodations are available on request for candidates taking part in all aspects of the selection process.
For a confidential inquiry, simply email your recruiter directly or accessibility@fxinnovation.com to make arrangements.
If you have questions regarding accessible employment at Ateko please email our Human Resources team at accessibility@fxinnovation.com
Ateko
Derek Weber - Senior Recruiter
derek.weber@ateko.com