Intern
- Gained valuable experience working within a specific industry, applying learned concepts directly into relevant work situations.
- Support in setting up, configuring, and maintaining security orchestration tools and platforms.
- Collaborate with the security team to ensure integration of various security technologies (SIEM, firewall, endpoint protection, etc.) with the SOAR platform.
- Assist in designing and implementing automated playbooks for common security incidents.
- Develop scripts or workflows to automate response to repetitive tasks, such as phishing detection, malware analysis, and data exfiltration attempts.
- Help in managing and escalating security incidents through the SOAR platform.
- Participate in real-time incident investigations by gathering data and insights from automated workflows.
- Work with senior security team members to analyze incidents and propose improvements to existing security automation and orchestration workflows.
- Help refine playbooks based on lessons learned from incident responses.
- Assist in the integration of external threat intelligence feeds into the SOAR platform to enhance detection and response.
- Contribute to the development of automated threat intelligence parsing and analysis workflows.
- Create and maintain comprehensive documentation for automated workflows, playbooks, and processes.
- Provide training or knowledge sharing sessions for team members on new features or workflows implemented.
- Help in stress-testing the SOAR platform to ensure it can handle high volumes of incidents.
