IT Security Analyst

Remote, MI
Full Time
Experienced
Job Title: IT Security Analyst
Location: Remote, MI

We are seeking a highly skilled and experienced Cortex XSOAR Professional to join our cybersecurity team. The ideal candidate will be a subject matter expert in the Palo Alto Networks Cortex XSOAR platform, responsible for designing, developing, and deploying security orchestration, automation, and response (SOAR) solutions. This role requires a strong background in scripting, API integration, and a deep understanding of security operations center (SOC) workflows. The successful candidate will play a key role in enhancing our security posture by automating incident response, improving efficiency, and integrating various security tools to create a cohesive and automated security ecosystem. This is a critical position for someone who is passionate about cybersecurity and leveraging automation to solve complex security challenges.

Top 3 Required Skills/Experience –

• Cortex XSOAR Expertise: Extensive experience in designing, developing, and deploying Cortex XSOAR playbooks. A deep understanding of XSOAR context data structures, incident layouts, and war rooms is essential. The ability to debug, optimize, and maintain playbooks for performance and reliability is a core requirement.

• Scripting and Integration Proficiency: Proven proficiency in Python is mandatory. This role requires experience working with REST and other APIs to integrate XSOAR with a wide range of security tools and platforms. The ability to troubleshoot complex API/integration issues and build custom integrations when off-the-shelf solutions are not available is critical.

• Automation of SOC Workflows: Hands-on experience in automating and orchestrating SOC workflows. This includes a strong command of incident triage, enrichment, and remediation use cases, such as phishing response, endpoint isolation, threat intelligence, and vulnerability management. The candidate must be skilled in identifying security or workflow gaps and designing modular, scalable automation solutions to address them.

Preferred Skills/Experience – Optional but preferred skills/experience. Include:

• Experience in integrating SOAR platforms with Splunk and other security tools to enhance incident response capabilities.

• Experience connecting XSOAR with a variety of security tools, including Splunk, CrowdStrike, and email security solutions (Proofpoint).

• Knowledge of other scripting languages beyond Python.

• Strong understanding of general cybersecurity principles and SOC operations.

• Experience building custom dashboards and reports within the XSOAR platform.

• Excellent soft skills, including strong communication, the ability to translate stakeholder requirements into technical solutions, and robust documentation skills.

Education/Certifications – Include:

• Preferred but not required:

o Bachelor's degree in Cyber Security, Computer Science, or related field

Please apply on our secured job site at <<https://intellibee.my.salesforce-sites.com/apps/jobs?id=a0AUU000003gGMn>> or email [email protected]
Share

Apply for this position

Required*
Apply with Indeed
We've received your resume. Click here to update it.
Attach resume as .pdf, .doc, .docx, .odt, .txt, or .rtf (limit 5MB) or Paste resume

Paste your resume here or Attach resume file

To comply with government Equal Employment Opportunity and/or Affirmative Action reporting regulations, we are requesting (but NOT requiring) that you enter this personal data. This information will not be used in connection with any employment decisions, and will be used solely as permitted by state and federal law. Your voluntary cooperation would be appreciated. Learn more.

Invitation for Job Applicants to Self-Identify as a U.S. Veteran
  • A “disabled veteran” is one of the following:
    • a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or
    • a person who was discharged or released from active duty because of a service-connected disability.
  • A “recently separated veteran” means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.
  • An “active duty wartime or campaign badge veteran” means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.
  • An “Armed forces service medal veteran” means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.
Veteran status


Human Check*