Sr Spec, IT – SOAR Engineer

MX/GUA - Mexico/Guadalajara

Apply now Apply later

This is where you save and sustain lives

At Baxter, we are deeply connected by our mission. No matter your role at Baxter, your work makes a positive impact on people around the world. You'll feel a sense of purpose throughout the organization, as we know our work improves outcomes for millions of patients.

Baxter's products and therapies are found in almost every hospital worldwide, in clinics and in the home. For over 85 years, we have pioneered significant medical innovations that transform healthcare.

Together, we create a place where we are happy, successful and inspire each other. This is where you can do your best work.

Join us at the intersection of saving and sustaining lives—where your purpose accelerates our mission.

About Baxter

Baxter provides a broad portfolio of essential renal and hospital products, including home, acute and in-centre dialysis; sterile IV solutions; infusion systems and devices; parenteral nutrition; surgery products and anesthetics; and pharmacy automation, software and services. The company’s global footprint and the critical nature of its products and services play a key role in expanding access to healthcare in emerging and developed countries. Baxter’s employees worldwide are building upon the company’s rich heritage of medical breakthroughs to advance the next generation of healthcare innovations that enable patient care 

Job Responsibilities

The IT Sr. Specialist – SOAR Engineer provides direct support for SOAR Operations. The SOAR Engineer will engage stakeholders to identify logging requirements and opportunities for data enrichment to make the data actionable for Incident Response, Threat Hunting, IT Operations, Machine Learning, and other functions. Additionally, the SOAR Engineer will create integrations, manage capacity and forecast future growth, and ensure that alerting is comprehensive and effective against a range of known attacks as well as emerging techniques.

Duties include:

  • Ensure the health of the SOAR environment, monitor usage and data growth. Report on performance, highlighting issues and addressing them with management and key stakeholders
  • Provide timely break-fix support when issues occur, consistently inspecting and correcting issues with data onboarding, normalization and search
  • Engage stakeholders. Consult and advise on platform use to develop custom dashboards and integrations to get the most out of the available data
  • Establish, monitor and maintain connections to external sources of data enrichment such as threat intelligence feeds, configuration management databases and identity stores
  • Create and maintain Playbooks for security alerting, maximizing coverage across the MITRE ATT&CK Framework categories, and anticipating emerging techniques. Monitor the effectiveness of alerting and continue to tune them to ensure detection performs as expected
  • Be a resource providing operational insight during major incidents affecting Security or IT Operations
  • Support additional Engineering, Operations and IT Security projects as requested by management

Qualifications and Skills

  • 5+ years of SOAR/SIEM engineering experience, implementing, maintaining, and tuning Enterprise SOAR/SIEM environments such as Splunk, QRadar, Sentinel, Palo Alto, Crowdstrike, etc.
  • Use Case Development experience, familiarity with MITRE ATT&CK Framework
  • Bachelor's degree in Computer Science, a related field or equivalent demonstrated experience and knowledge
  • Significant experience with Windows and Linux system administration and shell scripting
  • Experience with Cloud Infrastructure and automation frameworks such as Chef, Ansible, Puppet or SaltStack
  • Familiar with Agile Development Practices
  • Familiar with Enterprise IT processes for Asset, Configuration, Change, Incident and Problem Management
  • Excellent English verbal and written communication skills
  • Demonstrated skill working as part of a team, collaborating, and supporting peers in a fast-paced environment
  • Industry certifications nice to have: GCFA, GCIH, CEH or related

EEO (Equal Employment Opportunity)

Baxter is an equal opportunity employer. Baxter evaluates qualified applicants without regard to race, color, religion, gender, national origin, age, sexual orientation, gender identity or expression, protected veteran status, disability/handicap status or any other legally protected characteristic.

Reasonable Accommodations

Baxter is committed to working with and providing reasonable accommodations to individuals with disabilities globally. If, because of a medical condition or disability, you need a reasonable accommodation for any part of the application or interview process, please click on the link here and let us know the nature of your request along with your contact information.

Recruitment Fraud Notice

Baxter has discovered incidents of employment scams, where fraudulent parties pose as Baxter employees, recruiters, or other agents, and engage with online job seekers in an attempt to steal personal and/or financial information. To learn how you can protect yourself, review our Recruitment Fraud Notice.

Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  1  0  0

Tags: Agile Ansible Automation CEH Cloud Computer Science CrowdStrike GCFA GCIH Incident response Linux Machine Learning MITRE ATT&CK Puppet QRadar Scripting Sentinel SIEM SOAR Splunk Threat intelligence Windows

Perks/benefits: Career development Health care

Region: North America
Country: Mexico

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.