Die KI-Suchmaschine für Jobs
Cybersecurity SOAR Playbook Engine Developer(m/w/x)
Building SOAR playbook execution engines with Python 3.9+ for online banking at a Swiss leader with 650,000+ clients. Good Python proficiency, YAML syntax, and basic cybersecurity fundamentals required. Direct impact on critical online banking security infrastructure.
Anforderungen
- Good Python proficiency
- Good YAML syntax and workflow definition knowledge
- Basic cybersecurity fundamentals and incident response understanding
- Interest in security operations and SOC processes
- Familiarity with threat landscapes and security concepts
- Basic test writing experience or willingness to learn
- Version control (Git) experience
- SOAR platforms (Splunk SOAR, Cortex XSOAR) experience
- Familiarity with security tools (Splunk, QRadar, Chronicle, CrowdStrike)
- Linting tools experience
- Workflow engines or orchestration systems knowledge
Aufgaben
- Build and enhance the core SOAR playbook execution engine using Python 3.9+
- Implement YAML parsers
- Implement workflow executors
- Implement conditional logic evaluators
- Implement decision tree engines
- Design YAML-based SOAR playbooks for automated incident response
- Create workflows for phishing detection
- Create workflows for malware analysis
- Create workflows for ransomware response
- Create workflows for threat intelligence enrichment
- Create workflows for IOC blocking
- Develop Python utility functions to extend playbook capabilities
- Build data transformation logic
- Build security analysis functions
- Implement error handling, logging, and monitoring
- Optimize performance
- Implement parallel execution
- Implement asynchronous operations
- Write unit tests and create regression test suites
- Test playbooks with realistic security scenarios
- Validate end-to-end automation flows
- Implement and enforce coding standards using linting tools
- Collaborate with the Integration Intern to understand available connectors
- Ensure playbooks effectively utilize all integrations
Ausbildung
- Abgeschlossene BerufsausbildungODER
- Bachelor-AbschlussODER
- Master-Abschluss
Sprachen
- Englisch – verhandlungssicher
Tools & Technologien
- Python
- YAML
- Git
- Splunk SOAR
- Cortex XSOAR
- Splunk
- QRadar
- Chronicle
- CrowdStrike
Noch nicht perfekt?
- SwissquoteVollzeitPraktikumnur vor OrtSchweiz
- Swissquote
Senior Information Security Engineer(m/w/x)
Vollzeitnur vor OrtSeniorSchweiz - Banque Internationale à Luxembourg (Suisse) SA (BIL Suisse)
Azure Cloud Architect(m/w/x)
Vollzeitnur vor OrtSeniorSachseln - Swissquote
Market Surveillance Officer(m/w/x)
Vollzeit/Teilzeitnur vor OrtKeine AngabeSchweiz - Swissquote
Network Engineer(m/w/x)
Vollzeitnur vor OrtBerufserfahrenSchweiz
Cybersecurity SOAR Playbook Engine Developer(m/w/x)
Building SOAR playbook execution engines with Python 3.9+ for online banking at a Swiss leader with 650,000+ clients. Good Python proficiency, YAML syntax, and basic cybersecurity fundamentals required. Direct impact on critical online banking security infrastructure.
Anforderungen
- Good Python proficiency
- Good YAML syntax and workflow definition knowledge
- Basic cybersecurity fundamentals and incident response understanding
- Interest in security operations and SOC processes
- Familiarity with threat landscapes and security concepts
- Basic test writing experience or willingness to learn
- Version control (Git) experience
- SOAR platforms (Splunk SOAR, Cortex XSOAR) experience
- Familiarity with security tools (Splunk, QRadar, Chronicle, CrowdStrike)
- Linting tools experience
- Workflow engines or orchestration systems knowledge
Aufgaben
- Build and enhance the core SOAR playbook execution engine using Python 3.9+
- Implement YAML parsers
- Implement workflow executors
- Implement conditional logic evaluators
- Implement decision tree engines
- Design YAML-based SOAR playbooks for automated incident response
- Create workflows for phishing detection
- Create workflows for malware analysis
- Create workflows for ransomware response
- Create workflows for threat intelligence enrichment
- Create workflows for IOC blocking
- Develop Python utility functions to extend playbook capabilities
- Build data transformation logic
- Build security analysis functions
- Implement error handling, logging, and monitoring
- Optimize performance
- Implement parallel execution
- Implement asynchronous operations
- Write unit tests and create regression test suites
- Test playbooks with realistic security scenarios
- Validate end-to-end automation flows
- Implement and enforce coding standards using linting tools
- Collaborate with the Integration Intern to understand available connectors
- Ensure playbooks effectively utilize all integrations
Ausbildung
- Abgeschlossene BerufsausbildungODER
- Bachelor-AbschlussODER
- Master-Abschluss
Sprachen
- Englisch – verhandlungssicher
Tools & Technologien
- Python
- YAML
- Git
- Splunk SOAR
- Cortex XSOAR
- Splunk
- QRadar
- Chronicle
- CrowdStrike
Über das Unternehmen
Swissquote
Branche
FinancialServices
Beschreibung
The company is the Swiss leader in online banking, providing trading, investing, and banking services to over 500,000 clients.
Noch nicht perfekt?
- Swissquote
Cybersecurity SOAR Integration Engineer(m/w/x)
VollzeitPraktikumnur vor OrtSchweiz - Swissquote
Senior Information Security Engineer(m/w/x)
Vollzeitnur vor OrtSeniorSchweiz - Banque Internationale à Luxembourg (Suisse) SA (BIL Suisse)
Azure Cloud Architect(m/w/x)
Vollzeitnur vor OrtSeniorSachseln - Swissquote
Market Surveillance Officer(m/w/x)
Vollzeit/Teilzeitnur vor OrtKeine AngabeSchweiz - Swissquote
Network Engineer(m/w/x)
Vollzeitnur vor OrtBerufserfahrenSchweiz