Security Automation Specialist / SOAR Consultant
Summary
The Security Automation Specialist will design and maintain automated security workflows and incident response processes using SOAR platforms within a global enterprise environment. The role involves integrating security tools via APIs and requires experience with SIEM, EDR, and scripting languages.
Employer: International Pharmaceutical Company
Location: Remotely from Poland
Working hours: 3:00 PM–11:00 PM Polish time
Cooperation model: B2B
Start date: ASAP
Recruitment process: 2-3 online interviews
For our client, a global organization, we are looking for a Security Automation Specialist / SOAR Consultant to support security operations, automation, and incident response processes within a large enterprise environment.
The role combines SOAR engineering, security automation, SIEM support, and operational consulting. We are looking for someone with around 2–3 years of relevant experience, hands-on experience with any SOAR platform, and a strong interest in developing further with Torq.
Your role is:
- Designing, maintaining, and improving automated security workflows within a SOAR environment.
- Supporting SOC and incident response processes through automation.
- Handling security-related tickets, operational requests, and workflow issues.
- Automating use cases such as phishing, malware, suspicious authentication activity, and other security alerts.
- Integrating security tools using REST APIs, webhooks, and custom connectors.
- Enriching alerts with data from SIEM, EDR, identity, ticketing, and threat intelligence platforms.
- Troubleshooting and optimizing existing security automations.
- Working with security teams to identify processes that can be automated and improved.
- Building hands-on expertise in Torq as part of the project.
Our client offers:
- Great opportunity for personal development in a stable and friendly large multinational company.
- Career growth and additional education.
Your skills and experiences:
- 2–3 years of experience in Security Operations, Security Engineering, Security Automation, SOC, or a similar area.
- Hands-on experience with at least one SOAR platform, e.g. Torq, Palo Alto XSOAR, Splunk SOAR, Tines, Swimlane, or another comparable solution.
- Torq experience is not required — practical SOAR experience and willingness to learn Torq are sufficient.
- Good understanding of SOC processes and incident response workflows.
- Experience with REST APIs, JSON, authentication mechanisms, and webhooks.
- Experience with at least one SIEM platform such as Microsoft Sentinel, Splunk, QRadar, or Elastic.
- Knowledge of EDR technologies such as CrowdStrike, Microsoft Defender for Endpoint, SentinelOne, or Carbon Black.
- Scripting skills in Python, PowerShell, or a similar language.
- Familiarity with Azure, AWS, or GCP.
- Very good communication skills and ability to work independently in an international environment.
- Fluent English.