
Cybersecurity Subject Matter Expert
- Bangalore, Karnataka
- Permanent
- Full-time
- Design & Implementation: Lead the design, configuration, and implementation of Cortex XSIAM solutions, ensuring they meet organizational security requirements and integrate with existing infrastructure.
- Expertise in XSIAM: Deep understanding of the XSIAM platform, its features, and capabilities, including log ingestion, correlation rules, detection strategy, and integration with other security tools. Keep up to date with the latest XSIAM features, releases, and security threats, ensuring ongoing expertise
- Log Ingestion and Optimization: Devise and implement log ingestion strategies, ensuring high-quality log sources are ingested. Monitor and optimize log sources for performance
- Detection Strategy: Design and implement effective detection strategies, including the creation and tuning of correlation rules to identify and alert on potential threats
- Correlation Rules: Create and fine-tune correlation rules to enhance security detections.
- Automation & Orchestration: Develop and maintain automated workflows, playbooks, and integrations to streamline incident response, threat detection, and security operations.
- Platform Optimization: Continuously monitor, tune, and optimize Cortex XSIAM performance, ensuring high availability and scalability.
- Security Operations Collaboration: Collaborate with Security Operations Center (SOC) teams to enhance incident management, response times, and threat intelligence sharing.
- Integration with Security Tools: Integrate Cortex XSIAM with SIEM, EDR, threat intelligence platforms, and other security tools to create a comprehensive security ecosystem.
- Problem Solving: Identify, analyze, and resolve technical issues related to XSIAM, providing effective solutions.
- Documentation and Reporting: Create and maintain technical documentation, training materials, and knowledge base articles for XSIAM. Maintain detailed documentation for system configurations, integrations, and workflows. Provide regular status reports to management on platform performance and incident metrics.
- Best Practices: Establish and maintain best practices for Cortex XSIAM configuration, workflow design, and incident response. Understanding of cybersecurity threats, vulnerabilities, and industry best practices.
- Customer Support and Consulting: Serve as a subject matter expert, providing consultative guidance to end-users on optimizing XSIAM usage.
- Training & Support: Provide training to internal teams and clients on Cortex XSIAM features, workflows, and incident response protocols. Act as a go-to resource for troubleshooting and technical support.
- Innovation & Continuous Improvement: Stay current with the latest developments in Cortex XSIAM and cybersecurity automation, bringing innovative ideas to enhance security operations.
- Incident Management and Investigation: Assist in the design and execution of automated response playbooks for common and emerging threats, ensuring rapid and effective resolution of incidents.
- Threat Hunting: May be involved in proactive threat hunting activities, identifying potential vulnerabilities and threats.
When you join Kyndryl, you're not just joining a company – you're entering a space of opportunities. Our partnerships with industry alliances and vendors mean you'll have access to skilling and certification programs needed to excel in Security & Resiliency, while simultaneously supporting your personal growth. Whether you envision your career path as a technical leader within cybersecurity or transition into other technical, consulting, or go-to-market roles – we’re invested in your journey.Who You AreYou’re good at what you do and possess the required experience to prove it. However, equally as important – you have a growth mindset; keen to drive your own personal and professional development. You are customer-focused – someone who prioritizes customer success in their work. And finally, you’re open and borderless – naturally inclusive in how you work with others.Required Skills and Experience
- 8 to 12 years of security analyst experience, preferably in a managed service XSIAM Engineer
- In-depth expertise in Palo Alto Networks Cortex XSIAM (XSOAR) platform.
- Proficient in scripting languages (e.g., Python, JavaScript) for creating automated workflows and integrations.
- Strong understanding of security technologies such as SIEM, SOAR, EDR, XDR and threat intelligence platforms.
- Hands-on experience with Cortex XSIAM integrations (e.g., RESTful APIs, webhooks, etc.).
- Experience with developing and tuning playbooks, tasks, and workflows within the Cortex XSIAM platform.
- Knowledge of security best practices and frameworks such as MITRE ATT&CK, NIST, ISO 27001, etc.
- Cortex XSOAR certification (e.g., Palo Alto Networks Cortex XSOAR Certified Automation Engineer).
- Security Operations and Incident Response certifications (e.g., GIAC, SOC Analyst).