Security Automation Engineer
Core
Design, build, and oversee end-to-end security automation solutions that improve threat detection, triage, and response through enrichment and auto-closure.
Role type
Security Automation Engineer (AI-enabled)
Builds
AI-assisted workflows blending LLM-generated steps with deterministic logic for security operations
Domain
Cybersecurity / Security Operations Center (SOC)
Deliverable
production ML models | product features
Required skills
Python, API integration (REST/JSON, OAuth), CI/CD, detection-as-code, GitHub workflows, LLM prompt design, validation loops, retry patterns, data normalization
Preferred skills
AI-driven workflow design, agent-style systems, prompt orchestration, judgment on AI risk vs value
Technologies
Python, GitHub, Copilot, Splunk ES, ServiceNow, CrowdStrike, LLM, OAuth, REST, JSON, CI/CD
Responsibilities
Design and build end-to-end automation for enrichment, triage, response, containment, and auto-closure; Develop multi-step agent-like flows to validate data and support automated decisions; Apply detection-as-code practices including version control, testing, and peer review; Reverse-engineer APIs and solve integration challenges involving tokens, pagination, and rate limits; Collaborate with detection engineers and SOC analysts to operationalize detections; Maintain automation libraries and ensure resilience against API failures and third-party instability
Seniority
Mid-level, hands-on IC