Automation Engineer II, Falcon Complete (Remote)
Core
Develop security automation workflows, SOAR playbooks, and AI-powered scripts to streamline detection, triage, and response in a Managed Detection & Response (MDR) environment.
Role type
Mid-level IC Automation Engineer (Security Operations)
Builds
SOAR playbooks, PowerShell/Python scripts, and AI-integrated workflows for security incident response
Domain
Cybersecurity, Security Operations Center (SOC), Managed Detection & Response (MDR)
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
PowerShell scripting, Python for automation, SIEM query languages, JSON parsing, Regular Expressions, Git version control, incident detection workflows, data parsing
Preferred skills
Falcon SOAR platform, LogScale (Humio), AI workflow frameworks, LLM integration, NIST/MITRE ATT&CK frameworks, cloud platforms (AWS/Azure/GCP), CrowdStrike Falcon APIs, generative AI concepts
Technologies
SOAR, PowerShell, Python, Git, SIEM, JSON, Regular Expressions, LogScale, AWS, Azure, GCP, CrowdStrike Falcon
Responsibilities
Build and maintain security automation workflows and playbooks in SOAR platforms; Develop PowerShell and Python scripts for security enrichment and remediation; Integrate SIEM queries into automated workflows; Collaborate with SOC analysts to identify automation opportunities; Maintain version control of automation scripts; Evaluate emerging technologies for MDR operations
Seniority
Mid-level, hands-on IC