SOAR DevOps expertise within a CSIRT

Challenge
Our service was provided in the CSIRT of a leader in the banking sector. The service tasks involved were as follows:
- Develop and maintain the alert and SOAR (Security Orchestration Automation and Response) platform from development to monitoring in production;
- Deploy and adapt this platform for the different regional and security business units;
- Gather development needs from CSIRT members and from other security teams;
- Integrate the various security tools into the platform;
- Develop, test, implement and maintain
- Document the platform (code, infrastructure) and define the roadmap.
The keys to success
1
Security expertise and an advanced understanding of security production issues in banking;
2
Proven DevOps expertise on high-volume security monitoring infrastructures;
3
Good interpersonal skills and excellent ability to adapt to deal with a large number of contact persons and address the complexity of the customer's organisation;
4
Good communication skills to support change management in projects.