31 Jul
|
S.i. Systems
|
Toronto
31 Jul
S.i. Systems
Toronto
Our financial services client is seeking a Security Platform Engineer (5+ years of experience) to develop security automation workflows using Splunk SOAR, Python, and Ansible Automation Platform Duration: Until
December 31st, Location: Downtown Toronto - Hybrid (at least once a week on Wednesdays) Join a cybersecurity team supporting enterprise-level security automation initiatives within the insurance industry.
This role focuses on developing Splunk SOAR playbooks, building automated workflows in Ansible Automation Platform, and supporting security platform operations across ongoing projects.
The position includes involvement in security initiatives, proof of concept activities, and deployment of new security technologies.
Candidates will also participate in a 24x7 on-call support rotation and major incident management activities.
Must Haves Splunk SOAR experience 2-3 years.
Python development experience 2-3 years.
An Information Technology University degree/college diploma in related discipline(s) or equivalent work experience, and/or 5 years experience in Information Technology 2-3+ years in security IT industry experience Nice to Have Professional IT security certification such as CISM, CISSP, CISA, GIAC, AWS, or CompTIA Experience with Ansible development.
Experience planning, researching, and developing security policies, standards, and procedures.
Knowledge of one or more:end-point detection and response, intrusion detection, crypto technologies, certificate management, email security, web content filtering technologies, cloud security.
Knowledge of Security Information and Event Management platforms including log types.
Experience with Windows and Linux based operating systems.
Experience in deploying enterprise level technology via managed projects.
Knowledge of networking technologies,
firewalls, web application firewalls and intrusion prevention systems.
Knowledge of cloud technologies.
Knowledge of disaster recovery, technologies, and methods.
Robust communicator spoken and written with the ability to communicate technical issues to peers and management.
Responsibilities In Splunk SOAR, the successful candidate will develop playbooks (Python) to triage, alert or otherwise automate manual processes.
Within the Ansible Automation Platform, you will develop automated workflows (YAML) to manage accounts, certificates when new systems are built & deployed.
Triage and remediate errors within the automation environments.
Meet with stakeholders to help refine the requirements for new automation workflows.
The successful candidate will work on security initiatives and enterprise level projects performing proof of technology/concept asks, implementing new security controls and capabilities into existing technologies and be responsible to deploy, support and maintain new security technologies and platforms.
The security platform engineer will be part of a 24x7 on-call support team and be required to join major incident management calls to provide support and consultation for technologies supported by the team.
Continuously improve upon operational and security platform process activities.
Smoothly transition and operationalize each project as the implementation phase ends.
This includes developing roles & responsibilities (RACI) documents and educating the teams who will be performing BAU (Business as usual) the day-to-day work.
Document, update and maintain cyber security playbooks, policies and knowledge base articles used to support the established Incident Management and CSIRT processes.
Interview: 1 or 2 rounds depending on how it goes (in-person only)
📌 Security Platform Engineer to develop security automation workflows using Splunk SOAR, Python, and Ansible Automation Platform - 1643 (Toronto)
🏢 S.i. Systems
📍 Toronto