Why This Role Stands Out
This hybrid role offers an exciting opportunity to innovate within security automation, leveraging AI and advanced scripting to significantly enhance threat response for a reputable company. You'll thrive if you possess a strong blend of security operations expertise and software engineering skills, with a passion for building scalable, automated workflows. Join a dynamic team and advance your career by shaping the future of incident response.
Quick Overview
Job Description
OVERVIEW: The Security Automation (SOAR) Engineer will build, optimize, and scale our automated incident response workflows. You will bridge security operations and software engineering, using modern low-code/pro-code tools and AI to cut response times and strengthen our threat posture.
GENERAL DUTIES
- Playbook Automation: Design, build, and maintain end-to-end incident response playbooks within our SOAR platform.
- Workflow Logic : Write custom automation logic using a mix of low-code tools and pro-code scripting.
- Integrations : Connect disparate security tools via REST APIs, webhooks, and event-driven architecture.
- Incident Response: Partner with the SOC team to translate manual triage steps into reliable, automated actions.
- AI Integration: Leverage frontier LLMs (such as ChatGPT, Grok, Claude Code, or Codex) to enhance automation intelligence and code generation.
- Query && Data : SQL and GraphQL.
- Scripting && Development: Proficiency in Python, JavaScript, or TypeScript (at least one required) REQUIRED QUALIFICATIONS:
- Bachelor's degree and 8 years of experience related to specific functional area.
- Active certifications for both IAT Level II (e.g. CompTIA Security+) and Cyber Security Service Provider (CSSP) Infrastructure Support (e.g. CompTIA Cloud+) by program onboarding date.
- The following individual certifications cover both certification requirements for this program: CompTIA Cybersecurity Analyst, CySA+; EC-Council Certified Network Defender (CND); GlAC Global Industrial Cyber Security Professional, GICSP; (ISC)2 System Security Certified Practitioner (SCCP).
- SOAR Playbook Automation: Proven experience building security orchestration and automated response workflows.
- Workflow Logic: Strong grasp of both low-code interface design and pro-code logic handling.
- API && Architectures: Deep hands-on experience with REST API integration, webhook management, and event-driven systems.
- Incident Response: Understanding of core security incidents, triage procedures, and playbook design patterns.
- Frontier LLMs: Familiarity with AI coding tools and LLMs (ChatGPT, Grok, Claude, Claude Code, Codex) is a strong plus.
DESIRED QUALIFICATIONS
- Extensive experience with SOAR Playbook Automation
- Multiple scripting and development languages
- Deep understanding of incident response playbook design CLEARANCE:
- Active Top Secret clearance minimum required
Similar jobs
- ES
Cybersecurity Consultant
NewEstuate Inc.
Houston, TX🇺🇸Hybrid23 hours agoAWSAzureBash+6Technology - TC
Security Engineer
NewTATA Consultancy Services Limited
Austin, TX🇺🇸Hybrid23 hours agoDockerSQLAWS+7Technology - VC
Network Security Analyst 2
NewV-Soft Consulting Group, Inc
Austin, TX🇺🇸HybridYesterdaySplunkTCP/IPAgile+2Technology - TR
Endpoint Security Engineer
NewTror
San Francisco, CA🇺🇸On-site23 hours agoGitTerraformZero TrustTechnology - DE
Infrastructure Security Engineer (Palo Alto Networks) - Bellevue, WA (Onsite) - 12 Months Contract
NewDexperts Inc
Bellevue, WA🇺🇸On-site23 hours agoAWSAnsibleAzure+1Technology - IS
Vulnerability Remediation Engineer
NewInnova Solutions, Inc
Richmond, VA🇺🇸$75 - $85/hrOn-site23 hours agoEngineering