Lead Response Technology and Automation Security Engineer
Core
Lead Security Engineer driving the modernization of Security Operations (SecOps) incident investigation and response technology, building AI-augmented workflows and automation for SOC and DFIR teams.
Role type
Lead IC Security Engineer (SecOps Automation & AI)
Builds
SOAR playbooks, AI-augmented response capabilities, agentic AI workflows, investigation notebooks, and response tooling for SOC/DFIR teams.
Domain
Cybersecurity, Security Operations, Incident Response, AI/LLM integration
Deliverable
production ML models | product features
Required skills
SOAR development, AI prompt engineering, Python scripting, PowerShell scripting, REST API integration, incident response lifecycle, EDR platform integration, SIEM integration, cloud security platforms, MITRE ATT&CK mapping
Preferred skills
Digital Forensics, threat hunting, detection-as-code, CI/CD for security content, MCP server architecture, agentic AI frameworks
Technologies
SOAR, Jupyter, LLMs, Agentic AI, Python, PowerShell, Git, REST APIs, OAuth, CrowdStrike, SentinelOne, Defender for Endpoint, Splunk ES, Microsoft Sentinel, Entra ID, Okta, AWS, Azure, GCP, CNAPP, CWPP, CSPM
Responsibilities
Design and maintain SOAR playbooks for incident triage and response; Build and operationalize AI-augmented response capabilities including agentic AI workflows and prompt libraries; Embed with SOC/DFIR analysts to automate high-toil workflows; Tune and optimize playbooks against measurable outcomes like MTTR and false-positive rates; Support major incident response activities by deploying response tooling.
Seniority
Lead, hands-on IC with strategic oversight