Security Automation Engineer
About the Role
We are building an AI-augmented Security Operations capability and need a Security Automation Engineer to sit at the intersection of security engineering and AI systems. You will design, build, and maintain the automation pipelines and tooling that allow our AI-driven detections, investigations, and responses to operate at machine speed. Working alongside detection engineers, threat intelligence analysts, and AI/ML engineers, you will turn manual processes into reliable, observable, and testable automation workflows ing system
Key Responsibilities
AI-Powered Response Automation
Design and operate SOAR playbooks and agentic AI workflows that triage, enrich, and respond to security alerts with minimal human intervention.
Detection Engineering Support
Translate detection logic and AI model outputs into actionable, low-noise alerts. Tune thresholds and automate feedback loops to continuously improve signal quality.
Integration & Pipeline Development
Build and maintain integrations between security tools (SIEM, EDR, TIP, identity platforms) and AI inference services using APIs, event streaming, and orchestration frameworks.
Observability & Reliability
Instrument automation pipelines with metrics, logging, and alerting so the security ops team can trust and verify AI-driven decisions in production.
Automation Testing & Validation
Write tests for playbooks and automation logic. Run purple-team exercises and tabletop simulations to validate that automated responses behave correctly under adversarial conditions.
Cross-functional Collaboration
Partner with AI/ML, DevSecOps, and IT teams to embed security automation into infrastructure change management workflows.
Who You Are
Basic Requirements
5+ years in security engineering, SecOps, or automation roles
Proficiency in Python and/or Go for scripting and tooling
Hands-on SOAR experience (Splunk SOAR, Palo Alto XSOAR, Tines, or similar)
Experience with SIEM platforms (Splunk, Microsoft Sentinel, Google Chronicle)
REST API integration and event-driven architecture
Understanding of threat detection logic (MITRE ATT&CK, kill chain)
Familiarity with LLM/AI APIs and prompt-driven automation workflows
Version control and CI/CD practices (Git, GitHub Actions)
Cloud security fundamentals (AWS, Azure, or GCP)
Strong written documentation habits
Nice to Have
Experience deploying or fine-tuning ML models for anomaly detection or NLP-based log analysis
Familiarity with agentic AI frameworks (LangChain, AutoGen, CrewAI, or similar)
Container and orchestration experience (Docker, Kubernetes)
Certifications: CISSP, AWS Security Specialty, or equivalent
Background in threat intelligence automation or Cyber Thread Intelligence platform integration (Malware Information Sharing Platform, OpenCTI)