Security Automation Engineer
Core
Designing, developing, and maintaining security automation solutions to enhance detection, response, workflow efficiency, and operational consistency across Operational Security.
Role type
Security Automation Engineer (SOAR)
Builds
SOAR playbooks, integrations, scripts, AI-assisted workflows, and orchestration pipelines
Domain
Cybersecurity / Security Operations Center (SOC)
Deliverable
production ML models | product features
Required skills
SOAR platforms (Cortex XSOAR, Splunk SOAR, Chronicle SOAR), Python, PowerShell, REST APIs, SIEM integration, EDR integration, event-driven automation, data transformation, telemetry orchestration
Preferred skills
AI/ML-driven enrichment logic, anomaly detection, cloud certifications (Azure, GCP), security certifications (GIAC)
Technologies
Cortex XSOAR, Splunk SOAR, Chronicle SOAR, Python, PowerShell, REST APIs, JSON, SIEM, EDR, TIP
Responsibilities
Develop SOAR playbooks for alert triage, enrichment, containment, and remediation; Build scalable, reusable automation components and integrations; Integrate SOAR with cloud-native security tools and case management systems; Translate SOPs and response runbooks into automated processes; Collaborate with Detection Engineering and Incident Response teams to automate use cases; Optimize accuracy, resilience, and efficiency across automation workflows
Seniority
Mid-Senior, hands-on IC