Security Automation Engineer

AlphaSense · Remote - India · Engineering

Posted 2026-07-22

Apply for this role →

About the Role

We are building an AI-augmented Security Operations capability and need a Security Automation Engineer to sit at the intersection of security engineering and AI systems. You will design, build, and maintain the automation pipelines and tooling that allow our AI-driven detections, investigations, and responses to operate at machine speed. Working alongside detection engineers, threat intelligence analysts, and AI/ML engineers, you will turn manual processes into reliable, observable, and testable automation workflows ing system

Key Responsibilities

AI-Powered Response Automation

Design and operate SOAR playbooks and agentic AI workflows that triage, enrich, and respond to security alerts with minimal human intervention.

Detection Engineering Support

Translate detection logic and AI model outputs into actionable, low-noise alerts. Tune thresholds and automate feedback loops to continuously improve signal quality.

Integration & Pipeline Development

Build and maintain integrations between security tools (SIEM, EDR, TIP, identity platforms) and AI inference services using APIs, event streaming, and orchestration frameworks.

Observability & Reliability

Instrument automation pipelines with metrics, logging, and alerting so the security ops team can trust and verify AI-driven decisions in production.

Automation Testing & Validation

Write tests for playbooks and automation logic. Run purple-team exercises and tabletop simulations to validate that automated responses behave correctly under adversarial conditions.

Cross-functional Collaboration

Partner with AI/ML, DevSecOps, and IT teams to embed security automation into infrastructure change management workflows.

Who You Are

Basic Requirements

5+ years in security engineering, SecOps, or automation roles

Proficiency in Python and/or Go for scripting and tooling

Hands-on SOAR experience (Splunk SOAR, Palo Alto XSOAR, Tines, or similar)

Experience with SIEM platforms (Splunk, Microsoft Sentinel, Google Chronicle)

REST API integration and event-driven architecture

Understanding of threat detection logic (MITRE ATT&CK, kill chain)

Familiarity with LLM/AI APIs and prompt-driven automation workflows

Version control and CI/CD practices (Git, GitHub Actions)

Cloud security fundamentals (AWS, Azure, or GCP)

Strong written documentation habits

Nice to Have

Experience deploying or fine-tuning ML models for anomaly detection or NLP-based log analysis

Familiarity with agentic AI frameworks (LangChain, AutoGen, CrewAI, or similar)

Container and orchestration experience (Docker, Kubernetes)

Certifications: CISSP,  AWS Security Specialty, or equivalent

Background in threat intelligence automation or Cyber Thread Intelligence platform integration (Malware Information Sharing Platform, OpenCTI)

Apply for this role →

← Back to all jobs