As a Senior Technical Support Engineer specializing in Cortex Xpanse (ASM ) , you will play a critical role in managing all internal and external internet-connected assets for potential attack vectors and exposures, and ensuring our clients security infrastructures are robust and responsive.
Your Impact
Provide advanced technical support for cybersecurity automation tools, including SIEM, SOAR, and EDR solutions.
Diagnose and resolve complex technical issues related to the integration of SIEM solutions with other security tools and data sources.
Analyze and respond to security threats from various sources such as Firewalls, IDS/IPS, Antivirus, and EDR systems.
Develop and maintain scripts using Python, PowerShell, and Linux CLI commands to automate security processes and enhance system integrations
Collaborate with cross-functional teams to troubleshoot integration issues and improve the overall security architecture
Your Experience
BE/B.Tech engineering, equivalent technical degree or equivalent military experience required
Minimum of 3 to 5 years of experience in technical support or a similar role, with exposure on CyberSecurity Technologies, Automation and Architecture such as SIEM, SOAR, Threat Detection and Attack Surface management
Proficiency in scripting languages (Python, PowerShell, Linux CLI).
Strong understanding of network protocols, firewalls, and security architectures.
In Depth understanding of Active Response and Attack Surface Management
Understanding data models, APIs, and user interfaces for user-facing features
Brute-Force attack, Vulnerability Management Across the Cyber Attack Surface
Overview and better working knowledge of EDR, MDM, CMDB, Cloud Assets, Vulnerability Assessment Systems and Ordr Discovery Engine
Excellent problem-solving skills, with the ability to diagnose and resolve complex technical issue
Exceptional communication skills, both written and verbal, with a customer-centric approach
Ability to work independently and as part of a team in a fast-paced, dynamic environment
Experience in incident response and threat detection using SIEM tools.
Ability to troubleshoot integration issues between SIEM and other security tools.
Nice-to-Have
Experience with design, build and optimize data models and queries for speed and scale, using data storage technologies like MySQL and BigQuery
Design and build business logic and API endpoints using Python and Flask
Building user interfaces using Angular and React
Experience with dynamic playbooks and automated workflows in SOAR.
Understanding of attack visualization and automated alert management.