Detection and Automation Engineer
Core
Develop and maintain security automation playbooks, detection content, and tools for security monitoring and response, acting as an escalation point for incidents.
Role type
Senior IC detection and automation engineer (cybersecurity)
Builds
Security automation playbooks blending deterministic actions with AI-assisted analysis, detection logic, and response workflows
Domain
Cybersecurity, threat detection, and incident response
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Event log management and aggregation, detection rule development and tuning, SOAR platform usage, scripting (Python/PowerShell), adversary tactics knowledge, cloud security (AWS/Azure/GCP), incident triage, security automation design
Preferred skills
Identity and access management expertise, network architecture knowledge, systems hardening, threat hunting, purple team exercises, vulnerability review
Technologies
SOAR platforms, Python, PowerShell, AWS, Azure, GCP, Windows, Linux, macOS
Responsibilities
Source and integrate log/event data to create insights and detections; Develop and maintain detection logic, rules, and alerts based on threat intelligence; Design and improve security automation playbooks; Manage security tools and infrastructure for log processing and response; Triage alerts and perform real-time incident response; Drive threat hunting and purple team exercises; Collaborate with global teams to improve telemetry and secure operations
Seniority
Senior, hands-on IC