Your personal AI career agent
Cybersecurity SOAR Playbook Engine Developer(m/w/x)
Building SOAR playbook execution engines with Python 3.9+ for online banking at a Swiss leader with 650,000+ clients. Good Python proficiency, YAML syntax, and basic cybersecurity fundamentals required. Direct impact on critical online banking security infrastructure.
Requirements
- Good Python proficiency
- Good YAML syntax and workflow definition knowledge
- Basic cybersecurity fundamentals and incident response understanding
- Interest in security operations and SOC processes
- Familiarity with threat landscapes and security concepts
- Basic test writing experience or willingness to learn
- Version control (Git) experience
- SOAR platforms (Splunk SOAR, Cortex XSOAR) experience
- Familiarity with security tools (Splunk, QRadar, Chronicle, CrowdStrike)
- Linting tools experience
- Workflow engines or orchestration systems knowledge
Tasks
- Build and enhance the core SOAR playbook execution engine using Python 3.9+
- Implement YAML parsers
- Implement workflow executors
- Implement conditional logic evaluators
- Implement decision tree engines
- Design YAML-based SOAR playbooks for automated incident response
- Create workflows for phishing detection
- Create workflows for malware analysis
- Create workflows for ransomware response
- Create workflows for threat intelligence enrichment
- Create workflows for IOC blocking
- Develop Python utility functions to extend playbook capabilities
- Build data transformation logic
- Build security analysis functions
- Implement error handling, logging, and monitoring
- Optimize performance
- Implement parallel execution
- Implement asynchronous operations
- Write unit tests and create regression test suites
- Test playbooks with realistic security scenarios
- Validate end-to-end automation flows
- Implement and enforce coding standards using linting tools
- Collaborate with the Integration Intern to understand available connectors
- Ensure playbooks effectively utilize all integrations
Education
- Vocational certificationOR
- Bachelor's degreeOR
- Master's degree
Languages
- English – Business Fluent
Tools & Technologies
- Python
- YAML
- Git
- Splunk SOAR
- Cortex XSOAR
- Splunk
- QRadar
- Chronicle
- CrowdStrike
Like this job?
BetaYour Career Agent finds similar jobs for you every day.
Not a perfect match?
- SwissquoteFull-timeInternshipOn-siteSchweiz
- Swissquote
Banking Application Specialist(m/w/x)
Full-timeOn-siteExperiencedSchweiz - Swissquote
Financial Crime Analytics Officer(m/w/x)
Full-timeOn-siteExperiencedSchweiz - Swissquote
Head of Banking Solutions(m/w/x)
Full-timeOn-siteSeniorSchweiz - maxon motor AG
Internship - Measurement Technology(m/w/x)
Full-timeInternshipOn-siteSachseln
Cybersecurity SOAR Playbook Engine Developer(m/w/x)
Building SOAR playbook execution engines with Python 3.9+ for online banking at a Swiss leader with 650,000+ clients. Good Python proficiency, YAML syntax, and basic cybersecurity fundamentals required. Direct impact on critical online banking security infrastructure.
Requirements
- Good Python proficiency
- Good YAML syntax and workflow definition knowledge
- Basic cybersecurity fundamentals and incident response understanding
- Interest in security operations and SOC processes
- Familiarity with threat landscapes and security concepts
- Basic test writing experience or willingness to learn
- Version control (Git) experience
- SOAR platforms (Splunk SOAR, Cortex XSOAR) experience
- Familiarity with security tools (Splunk, QRadar, Chronicle, CrowdStrike)
- Linting tools experience
- Workflow engines or orchestration systems knowledge
Tasks
- Build and enhance the core SOAR playbook execution engine using Python 3.9+
- Implement YAML parsers
- Implement workflow executors
- Implement conditional logic evaluators
- Implement decision tree engines
- Design YAML-based SOAR playbooks for automated incident response
- Create workflows for phishing detection
- Create workflows for malware analysis
- Create workflows for ransomware response
- Create workflows for threat intelligence enrichment
- Create workflows for IOC blocking
- Develop Python utility functions to extend playbook capabilities
- Build data transformation logic
- Build security analysis functions
- Implement error handling, logging, and monitoring
- Optimize performance
- Implement parallel execution
- Implement asynchronous operations
- Write unit tests and create regression test suites
- Test playbooks with realistic security scenarios
- Validate end-to-end automation flows
- Implement and enforce coding standards using linting tools
- Collaborate with the Integration Intern to understand available connectors
- Ensure playbooks effectively utilize all integrations
Education
- Vocational certificationOR
- Bachelor's degreeOR
- Master's degree
Languages
- English – Business Fluent
Tools & Technologies
- Python
- YAML
- Git
- Splunk SOAR
- Cortex XSOAR
- Splunk
- QRadar
- Chronicle
- CrowdStrike
Like this job?
BetaYour Career Agent finds similar jobs for you every day.
About the Company
Swissquote
Industry
FinancialServices
Description
The company is the Swiss leader in online banking, providing trading, investing, and banking services to over 500,000 clients.
Not a perfect match?
- Swissquote
Cybersecurity SOAR Integration Engineer(m/w/x)
Full-timeInternshipOn-siteSchweiz - Swissquote
Banking Application Specialist(m/w/x)
Full-timeOn-siteExperiencedSchweiz - Swissquote
Financial Crime Analytics Officer(m/w/x)
Full-timeOn-siteExperiencedSchweiz - Swissquote
Head of Banking Solutions(m/w/x)
Full-timeOn-siteSeniorSchweiz - maxon motor AG
Internship - Measurement Technology(m/w/x)
Full-timeInternshipOn-siteSachseln