The Sr. SOAR Automation Engineer at Global Payments will be responsible for designing, building, and managing automated workflows to enhance the efficiency and effectiveness of the Cyber Security division. This role involves developing and maintaining automated responses to both common and complex security threats, optimizing the incident response process, and ensuring streamlined operations across the organization’s global payment ecosystem.
Key Responsibilities:
Automation Development: Create and implement SOAR playbooks for various security use cases, including phishing, malware analysis, insider threat response, and other automated processes required across Cyber Security. Use Case Collaboration: Work with teams in SOC, SIEM, Insider Threat, and Incident Response to gather requirements and ensure that automation aligns with security needs and business objectives. Platform Management: Oversee the SOAR platform, optimizing integrations with other security tools and maintaining robust performance through updates and customizations. Operational Efficiency: Identify opportunities for further automation to reduce manual workloads, speed up response times, and enable teams to prioritize high-impact threats. Mentorship and Training: Provide guidance to junior team members by sharing SOAR best practices, troubleshooting techniques, and fostering a culture of continuous improvement. Metrics and Reporting: Track SOAR platform performance, report on efficiency gains, and provide insights on ROI from automation efforts.
Required Experience and Skills:
- Extensive SOAR Experience: 5+ years of hands-on experience with SOAR platforms (e.g., Palo Alto Cortex XSOAR, Splunk Phantom, IBM Resilient).
- Incident Response Knowledge: Strong background in incident response, particularly in high-stakes environments like financial or global payments.
- Programming Proficiency: Proficiency in Python, JavaScript, or other languages commonly used in SOAR playbook development.
- Security Tool Integrations: Experience with SIEM, EDR, threat intelligence, and other tools commonly integrated into SOAR.
- Communication Skills: Ability to translate technical requirements into actionable automation solutions for stakeholders across Cyber Security.
Additional Skills and Capabilities:
- Problem-Solving Skills: Highly analytical mindset with strong problem-solving abilities, able to troubleshoot complex technical issues.
- Project Management: Strong organizational skills and experience managing multiple projects, ensuring timely and efficient completion of automation initiatives.
- Attention to Detail: Precision in creating workflows and playbooks, ensuring accurate and reliable automation of security responses.
- Team Collaboration: Excellent interpersonal skills to work effectively with diverse teams and stakeholders within Cyber Security and beyond.
Educational Requirements:
- Bachelor’s Degree in Computer Science, Cybersecurity, Information Technology, or a related field; or equivalent relevant experience.
- Certifications (preferred): Relevant industry certifications such as Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), GIAC Certified Incident Handler (GCIH), or certifications specific to SOAR platforms like Palo Alto or Splunk.
Strategic Importance of the Role: This role is critical for scaling the Cyber Security division’s capabilities, mitigating operational strain, and enabling advanced threat response measures essential to safeguarding Global Payments’ ecosystem.