TC-CS-CDR-SOAR Analyst-Senior
Job description
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.
Security Automation Developer
Summary:
Partners with various cross-functional teams to design, build and maintain automated security playbooks to streamline security incident and task workflows. Integrate with various security tools and systems to enable efficient detection, analysis and remediation of threats. Provides technical leadership, expertise, and mentorship for the SOAR team.
Responsibilities
- Design, implement, and maintain SOAR playbooks to automate routine security tasks and incident response processes.
- Develop and maintain integrations between the SOAR platform and various security tools such as SIEM, EDR, DLP and threat intelligence feeds.
- Collaborate with CSOC teams to identify automation opportunities and improve response times.
- Establish and enforce best practices for playbook design, code quality, and documentation.
- Work with cross-functional teams to gather requirements, design solutions, and ensure alignment with business objectives.
- Develop metrics to measure the effectiveness of automated workflows and identify areas of improvement.
- Provide training and documentation to CSOC analysts and other stakeholders on SOAR platform capabilities and playbook usage.
- Provides advanced level technical support to maintain our SOAR platform.
Qualifications:
- Undergraduate degree in Computer Science or Information Technology-related field or equivalent combination of training and experience.
- Proficiency in scripting and programming languages (e.g., Python, JavaScript, PowerShell)
- Experience with REST APIs, webhooks, JSON and/or web application development.
- Familiarity with development workflows and patterns
- Strong problem-solving and analytical skills
- Excellent communication and collaboration abilities.
- Strong understanding of cybersecurity concepts
- Experience with SOAR platforms. e.g. Tines
- Experience in security automation, incident response, or related fields.
- Experience with cloud environments (AWS, Azure, GCP)
- Relevant cybersecurity certifications
EY | Building a better working world
EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.
Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.
Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.