Lead Engineer, Cyber Defense Automation
Core
Design, build, and maintain security response automations on an agentic AI SOC platform, leading the migration of existing Splunk SOAR playbooks.
Role type
Lead IC security automation engineer (agentic AI)
Builds
Agentic workflows, security response automations, and integrations across the security stack
Domain
Cybersecurity, Security Operations Center (SOC), Agentic AI
Deliverable
production ML models | product features
Required skills
Python, REST APIs, SOAR platforms, LLM platforms, Git, CI/CD, SOC operations, incident response
Preferred skills
Agentic AI security platforms, LLM fine-tuning/evaluation, Splunk Enterprise Security, Case management/ITSM, AWS, Docker/Kubernetes, Terraform
Technologies
Python, Splunk SOAR, Anthropic Claude, OpenAI, Amazon Bedrock, REST, Git, AWS, Docker, Kubernetes, Terraform, FastAPI, Flask, ServiceNow
Responsibilities
Design and build security response automations on agentic AI SOC platform; Build agentic workflows end to end including prompt design, tool integration, and human-in-the-loop review; Develop and maintain integrations across the security stack using REST APIs and webhooks; Administer and improve the case management platform and its workflows; Partner with detection engineering to operationalize new detections into automated response; Measure automation throughput, MTTR, and analyst time saved.
Seniority
Senior, hands-on IC with leadership responsibilities
