
Posted 12 hours ago
Detection & Automation Lead
HaleonDetection & Automation Lead
Requirements
3 years security operations or detection engineering experience, Experience with SIEM platforms (Splunk, Sentinel, QRadar), Familiarity with EDR/XDR tools, Proficiency in Python, PowerShell, or JavaScript, Experience with SOAR platforms, Knowledge of REST APIs and system integrations
Skills
SOARSIEMPythonEDRCybersecurity
About the role
Responsibilities
- Design, develop, and maintain SOAR playbooks to automate security incident detection and response
- Create and maintain detection rules and use cases across SIEM, EDR, and other security platforms
- Integrate security tools including SIEM, EDR, threat intelligence platforms, and ticketing systems into SOAR platforms
- Develop and maintain APIs, scripts, and connectors for seamless system integration
- Analyze logs and telemetry to identify suspicious activity and improve detection coverage
- Map detections to frameworks such as MITRE ATT&CK to ensure comprehensive coverage
- Tune and optimize alerts to reduce false positives and improve signal quality
- Collaborate with SOC analysts, incident responders, and threat intelligence teams to identify automation opportunities
Requirements
- 3 years of experience in security operations, detection engineering, or SOAR development
- Hands-on experience with SIEM platforms such as Splunk, Sentinel, or QRadar
- Familiarity with EDR/XDR tools like CrowdStrike, Defender, or Carbon Black
- Strong programming and scripting skills in Python, PowerShell, or JavaScript
- Experience with SOAR platforms such as Palo Alto Cortex XSOAR, Splunk SOAR, or IBM Resilient
- Proven experience working with REST APIs and system integrations
- Strong understanding of various log sources including Windows, Linux, network, and cloud
Preferred Qualifications
- Bachelor’s degree in Computer Science, Cyber Security, or a related field
- Knowledge of DevOps practices, CI/CD pipelines, and containerization (Docker, Kubernetes)
- Familiarity with the MITRE ATT&CK framework and attacker TTPs
- Proficiency in query languages such as KQL, SPL, or SQL
- Experience with cloud security monitoring in AWS, Azure, or GCP
- Relevant industry certifications such as CISSP, GCIA, GCDA, GSOC, or GCIH
About the Company
Haleon is a purpose-driven, world-class consumer company dedicated to putting everyday health in the hands of millions. With a trusted portfolio of brands including Sensodyne, Panadol, Advil, and Centrum, we combine deep human understanding with trusted science to deliver better everyday health with humanity.
ScoutJobs Agent
Get matches like this delivered daily
Sign up free — we'll pull jobs that fit your CV from across the web and rank them for you.
Get started — it's freeDetection & Automation Lead
Haleon · Bengaluru
