Cyber Security Engineer
Core
Design and implement automated security workflows, integrations, and playbooks to connect detection, response, and remediation pipelines within a SOC environment.
Role type
Cyber Security Engineer (SOAR & Automation)
Builds
Automated security workflows, SOAR playbooks, integrations between SIEM/SOAR and ticketing systems, monitoring infrastructure
Domain
Cybersecurity, Security Operations Center (SOC), Cloud Security
Required skills
Python, Go, Bash, SIEM/SOAR platform integration, SOAR playbook engineering, cloud-native security (Azure/AWS/GCP), container security (Docker/Kubernetes), vulnerability management, RESTful API development, Infrastructure-as-Code (Terraform), GitOps, SOC support experience
Preferred skills
Experience with Cortex XSOAR, Splunk SOAR, Tines, TheHive/Cortex, Fluentd, OpenTelemetry, regulated environments (IT-Grundschutz, C5, ISO 27001, PCI-DSS, TISAX)
Responsibilities
Design and implement automated security workflows connecting detection, response, and remediation pipelines; Build integrations between SIEM/SOAR platforms, case management systems, and internal APIs; Engineer SOAR playbooks to automate repetitive SOC tasks; Integrate external threat feeds and CVE databases with internal asset inventories; Improve existing scripts, enrichment logic, and event correlation rules; Support development of monitoring infrastructure with a security context; Provide engineering support during security incidents and act as Tier 2 support for analysts (via careerplan.io/jobs/41f35848-b2da-4b6b-b271-d34a050482c4-cyber-security-engineer-at-qualysoft)
Seniority
Mid-level (3–5 years experience)
