Security Automation Engineer
About the Role
We are building an AI-augmented Security Operations capability and need a Security Automation Engineer to sit at the intersection of security engineering and AI systems. You will design, build, and maintain the automation pipelines and tooling that allow our AI-driven detections, investigations, and responses to operate at machine speed. Working alongside detection engineers, threat intelligence analysts, and AI/ML engineers, you will turn manual processes into reliable, observable, and testable automation workflows ing system
Key Responsibilities
AI-Powered Response Automation |
Design and operate SOAR playbooks and agentic AI workflows that triage, enrich, and respond to security alerts with minimal human intervention. |
Detection Engineering Support |
Translate detection logic and AI model outputs into actionable, low-noise alerts. Tune thresholds and automate feedback loops to continuously improve signal quality. |
Integration & Pipeline Development |
Build and maintain integrations between security tools (SIEM, EDR, TIP, identity platforms) and AI inference services using APIs, event streaming, and orchestration frameworks. |
Observability & Reliability |
Instrument automation pipelines with metrics, logging, and alerting so the security ops team can trust and verify AI-driven decisions in production. |
Automation Testing & Validation |
Write tests for playbooks and automation logic. Run purple-team exercises and tabletop simulations to validate that automated responses behave correctly under adversarial conditions. |
Cross-functional Collaboration |
Partner with AI/ML, DevSecOps, and IT teams to embed security automation into infrastructure change management workflows. |
Who You Are
Basic Requirements
5+ years in security engineering, SecOps, or automation roles
Proficiency in Python and/or Go for scripting and tooling
Hands-on SOAR experience (Splunk SOAR, Palo Alto XSOAR, Tines, or similar)
Experience with SIEM platforms (Splunk, Microsoft Sentinel, Google Chronicle)
REST API integration and event-driven architecture
Understanding of threat detection logic (MITRE ATT&CK, kill chain)
Familiarity with LLM/AI APIs and prompt-driven automation workflows
Version control and CI/CD practices (Git, GitHub Actions)
Cloud security fundamentals (AWS, Azure, or GCP)
Strong written documentation habits
Nice to Have
Experience deploying or fine-tuning ML models for anomaly detection or NLP-based log analysis
Familiarity with agentic AI frameworks (LangChain, AutoGen, CrewAI, or similar)
Container and orchestration experience (Docker, Kubernetes)
Certifications: CISSP, AWS Security Specialty, or equivalent
Background in threat intelligence automation or Cyber Thread Intelligence platform integration (Malware Information Sharing Platform, OpenCTI)