Security Detection & Automation Engineer - Product Security Section, Cyber Security Defense Department (CSDD)
Core
Build automated detection logic, security-as-code solutions, and response playbooks to protect private cloud environments and reduce time-to-detect/remediate.
Role type
Security Detection & Automation Engineer
Builds
Automated detection rules, SOAR workflows, security guardrails in CI/CD, custom security tools
Domain
Cyber Security, Cloud Security, DevSecOps
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Security engineering, detection engineering, incident response, container orchestration (Kubernetes), cloud-native environments (AWS/GCP/Azure), Python/Go/Ruby programming, SIEM/EDR rule development, SOAR automation, network protocols, OS internals (Linux/Windows), web application architectures
Preferred skills
MITRE ATT&CK mapping, CI/CD tools (Jenkins/GitLab/GitHub Actions), security-as-code, identity-centric security, micro-segmentation
Technologies
Kubernetes, AWS, GCP, Azure, Python, Go, Ruby, SIEM, EDR, SOAR, Jenkins, GitLab CI, GitHub Actions
Responsibilities
Develop and tune high-fidelity detection rules for SIEM/EDR/Cloud-Native tools; Design and implement automated workflows (SOAR) for threat response; Partner with SRE/DevOps to integrate security guardrails into CI/CD pipelines; Analyze logs and telemetry to identify sophisticated threats; Build automated systems for hybrid cloud configuration verification and drift detection; Build custom internal tools/scripts to bridge security stack gaps
Seniority
Mid-Senior, hands-on IC
