SOAR Ownership & Engineering -Proven experience building, maintaining, and optimizing automated workflows and playbooks within a SOAR platform (e.g., Palo Alto XSOAR, Splunk SOAR). -Strong background ...
SOAR Ownership & Engineering -Proven experience building, maintaining, and optimizing automated workflows and playbooks within a SOAR platform (e.g., Palo Alto XSOAR, Splunk SOAR). -Strong background ...
Collaborating with security operations center analysts and threat detection engineers to prioritize ... Experience with SIEM or SOAR tools such as Splunk, Cortex XSOAR, VirusTotal, Mandiant, or Google ...
Collaborating with security operations center analysts and threat detection engineers to prioritize ... Experience with SIEM or SOAR tools such as Splunk, Cortex XSOAR, VirusTotal, Mandiant, or Google ...
Collaborating with security operations center analysts and threat detection engineers to prioritize ... Experience with SIEM or SOAR tools such as Splunk, Cortex XSOAR, VirusTotal, Mandiant, or Google ...
Collaborating with security operations center analysts and threat detection engineers to prioritize ... Experience with SIEM or SOAR tools such as Splunk, Cortex XSOAR, VirusTotal, Mandiant, or Google ...
Collaborating with security operations center analysts and threat detection engineers to prioritize ... Experience with SIEM or SOAR tools such as Splunk, Cortex XSOAR, VirusTotal, Mandiant, or Google ...
Collaborating with security operations center analysts and threat detection engineers to prioritize ... Experience with SIEM or SOAR tools such as Splunk, Cortex XSOAR, VirusTotal, Mandiant, or Google ...
Collaborating with security operations center analysts and threat detection engineers to prioritize ... Experience with SIEM or SOAR tools such as Splunk, Cortex XSOAR, VirusTotal, Mandiant, or Google ...
Collaborating with security operations center analysts and threat detection engineers to prioritize ... Experience with SIEM or SOAR tools such as Splunk, Cortex XSOAR, VirusTotal, Mandiant, or Google ...
Collaborating with security operations center analysts and threat detection engineers to prioritize ... Experience with SIEM or SOAR tools such as Splunk, Cortex XSOAR, VirusTotal, Mandiant, or Google ...
Collaborating with security operations center analysts and threat detection engineers to prioritize ... Experience with SIEM or SOAR tools such as Splunk, Cortex XSOAR, VirusTotal, Mandiant, or Google ...
Collaborating with security operations center analysts and threat detection engineers to prioritize ... Experience with SIEM or SOAR tools such as Splunk, Cortex XSOAR, VirusTotal, Mandiant, or Google ...
Collaborating with security operations center analysts and threat detection engineers to prioritize ... Experience with SIEM or SOAR tools such as Splunk, Cortex XSOAR, VirusTotal, Mandiant, or Google ...
SOAR products such as Splunk SOAR, Cortex XSOAR, FortiSOAR, etc. SOAR playbook development ... Scripting and development activities to appropriately leverage Application Programing Interfaces ...
SOAR products such as Splunk SOAR, Cortex XSOAR, FortiSOAR, etc. SOAR playbook development ... Scripting and development activities to appropriately leverage Application Programing Interfaces ...
SOAR products such as Splunk SOAR, Cortex XSOAR, FortiSOAR, etc. SOAR playbook development ... Scripting and development activities to appropriately leverage Application Programing Interfaces ...
SOAR products such as Splunk SOAR, Cortex XSOAR, FortiSOAR, etc. SOAR playbook development ... Scripting and development activities to appropriately leverage Application Programing Interfaces ...
SOAR products such as Splunk SOAR, Cortex XSOAR, FortiSOAR, etc. SOAR playbook development ... Scripting and development activities to appropriately leverage Application Programing Interfaces ...
SOAR products such as Splunk SOAR, Cortex XSOAR, FortiSOAR, etc. SOAR playbook development ... Scripting and development activities to appropriately leverage Application Programing Interfaces ...
SOAR products such as Splunk SOAR, Cortex XSOAR, FortiSOAR, etc. SOAR playbook development ... Scripting and development activities to appropriately leverage Application Programing Interfaces ...
SOAR products such as Splunk SOAR, Cortex XSOAR, FortiSOAR, etc. SOAR playbook development ... Scripting and development activities to appropriately leverage Application Programing Interfaces ...
Xsoar Engineer information
What are the key skills and qualifications needed to thrive as an XSOAR engineer, and why are they important?
What is an XSOAR engineer?
What are some common challenges XSOAR engineers face when integrating new security tools into an existing SOAR platform?
What is the difference between Xsoar Engineer vs Cortex XSOAR Specialist?
| Aspect | Xsoar Engineer | Cortex XSOAR Specialist |
|---|---|---|
| Certifications | Relevant security and cloud certifications, such as Palo Alto Networks certifications | Same certifications, often including Palo Alto Networks certifications |
| Work Environment | Security teams, cybersecurity firms, IT departments | Security operations centers, cybersecurity consulting firms |
| Industry Usage | Used across industries for security automation and orchestration | Primarily in cybersecurity and threat management sectors |
| Job Focus | Design, develop, and maintain Xsoar integrations and automation | Implement, optimize, and manage Cortex XSOAR platforms and playbooks |
Both roles focus on security automation with Cortex XSOAR, but Xsoar Engineers typically develop and maintain integrations, while Cortex XSOAR Specialists focus on platform deployment and management. The roles often overlap, especially in organizations using Cortex XSOAR for security operations.

$114K/yr
Full-time
Re-posted 4 days ago
Job description
H-E-B is a leading innovator in technology, and we continue to invest in our customers' digital experience. Our Digital Technology Partners collaborate to design, construct, implement, and support technology solutions, using the best available technologies to deliver modern engagement, reliability, and scalability to meet customer needs.
As a Senior Security Engineer (SOAR/Automation), you'll build automation that improves SOC efficiency, reducing analyst workload, and accelerating incident response
Once you're eligible, you'll become an Owner in the company, so we're looking for commitment, hard work, and focus on quality and Customer service. 'Partner-owned' means our most important resources--People--drive the innovation, growth, and success that make H-E-B The Greatest Omnichannel Retailing Company.
We are looking for:
SOAR Ownership & Engineering
-Proven experience building, maintaining, and optimizing automated workflows and playbooks within a SOAR platform (e.g., Palo Alto XSOAR, Splunk SOAR).
-Strong background integrating SIEM, EDR, NDR, cloud logging platforms, and ticketing systems into end-to-end automated workflows.
-Ability to identify and automate repetitive SOC tasks to reduce analyst workload and accelerate incident response.
AI/LLM-Driven Automation
-Hands-on experience using AI and LLM tools (e.g., GPT, security-specific copilots) to enhance detection, triage, and analyst workflows.
-Focus on operational implementation-leveraging AI/LLM outputs to improve decision-making and workflow efficiency
Scripting & Software Development Practices
-Proficiency in scripting languages such as Python, Go, PowerShell, or similar.
-Familiarity with Git-based version control, CI/CD pipelines, and treating automation artifacts as production-grade software.
-Ability to write clean, modular, and well-documented code that scales across SOC environments.
What is your background?
- A related degree or comparable formal training, certification, or work experience
- 5+ years of experience designing / developing / configuring / implementing / supporting systems and multi-vendor, diverse security solutions at a large scale.
- 3+ years of experience in information security or IT risk management / compliance
- Experience with published standards, guidance, and frameworks related to info security architecture / controls and practical implementation techniques in an enterprise required.
- Experience with network protocols, PKI, secrets management, and platform / OS security
- Experience working with public cloud infrastructures.
- One or more professional security certifications (e.g., CISSP, OSCP, OSCE, GCIH, CASP, AWS Security)
What is the work?
Design & Development / Information Technology:
- Owns products of H-E-B's information security stack; leads planning, implementation, lifecycle, and care for security measures and controls related to security monitoring, detection, and incident response.
- Assesses existing security posture against industry best practices and control frameworks; proposes solutions and improvements.
- Investigates intrusion attempts, security incidents, malware infections, exploit attempts, and internet usage anomalies; analyzes / investigates security alerts; helps execute threat responses.
- Establishes plans and protocols to protect data and info systems against unauthorized access, modification, and destruction.
- Works with H-E-B teams and external security solution vendors to scope / configure / validate solutions that support our security posture.
- Works with information system owners and Administrators to design / propose / implement security relevant standards, techniques, and processes.
- Collaborates with other engineering teams to lead / drive software-defined infrastructure environment, configuration and build scripts, and CI / CD security components.
- Educates on / ensures others understand implementation of security controls and solutions; ensures gaps, dependencies, and defects are identified / addressed.
- Research / stays current on emerging technologies, threats, and solutions; helps evaluate technologies that align with business goals, reduce costs, and improve reliability, scalability, and security.
- Champions information security: shares / promotes security and safe operating procedures.
- May coach / mentor team Partners
Do you have what it takes to be an H-E-B Senior Security Engineer?
- Strong working knowledge of information systems security standards and practices (e.g., access control and system hardening, system audit and log file monitoring, security policies, and incident handling)
- Strong working knowledge of iMac platforms (e.g., Terraform, AWS CloudFormation)
- Familiarity with related industry regulations (e.g., PCI DSS, HIPAA)
- Strong interpersonal skills and collaborative mindset
- Strong time management and prioritization skills
- Understanding of Agile and other project management methodologies
- Ability to professionally manage confidential information.
- Ability to work well under pressure.
JDSECURITY
JDENGINEERING
DEV3232
About H-E-B Grocery
Sourced by ZipRecruiter