Skip to content
← Back to job listings

Advanced Cyber Sec Archt/Engr

Honeywell · India

CybersecurityExternal listingfull-timeabout 2 hours ago

About The Role

This role is responsible for developing, enhancing, and supporting security automation solutions across Cortex XSOAR and Splunk. The successful candidate will collaborate with Incident Response, Threat Intelligence, Insider Risk, and SOC stakeholders to build integrations and automated workflows, onboard and maintain security data sources, and improve the reliability and efficiency of security operations. The position requires strong software development experience and the ability to deliver scalable solutions in a fast-paced, cross-functional environment.

Key Responsibilities

  • Collaborate closely with the Incident Response, Threat Intelligence, and Insider Risk teams to design, develop, and enhance capabilities on the Cortex XSOAR platform.
  • Develop and implement automation solutions that reduce manual effort and improve the efficiency of Security Operations Center (SOC) processes.
  • Operate effectively in a fast-paced environment, managing and prioritizing diverse requests from multiple teams.
  • Develop, maintain, and enhance internally built and third-party tools, ensuring their reliability, scalability, and alignment with operational requirements.

Required Qualifications

  • A minimum of seven years of software development experience using Python and web frameworks such as Django and Flask.
  • Working knowledge of front-end technologies, including HTML, CSS, JavaScript, and jQuery.
  • Hands-on experience working in Linux environments, including Red Hat Enterprise Linux (RHEL) and Debian-based distributions.
  • Experience managing source code and collaborating through Git-based repositories.
  • A sound understanding of SQL fundamentals and database management systems (DBMS).
  • A demonstrated eagerness to learn new technologies and adapt quickly to changing requirements.
  • Basic knowledge of Security Operations Center (SOC) operations, including security monitoring, alert triage, incident investigation, and escalation processes.

Added Advantage

  • Experience designing and developing features, integrations, or automated playbooks within Security Orchestration, Automation, and Response (SOAR) platforms.
  • Hands-on experience onboarding, configuring, and validating data sources in Splunk.
  • Proficiency in developing and optimizing complex Splunk Search Processing Language (SPL) queries for security monitoring, investigation, and reporting.
  • Experience working with cybersecurity tools that support incident response and threat intelligence operations.
  • Experience integrating security platforms with IT service management tools and ITIL-aligned workflows, particularly ServiceNow.

This is an external listing. JobSpring does not represent or verify the employer. Report this listing