Engineer automation-first, AI-assisted security capabilities that transform detection signals into real-time, policy-driven response and control actions.
Help evolve security operations from “alert and investigate” to detect, decide, and act.
Design and implement SOAR workflows, detection logic, and automated response playbooks.
Integrate AI/ML-driven insights to improve signal fidelity, decisioning, and response outcomes across detection, response, and control planes.
Document automation patterns, standards, and engineering decisions.
Requirements
Bachelor’s degree and 7+ years of experience in cybersecurity engineering, detection engineering, or automation-focused security roles, OR 11+ years of experience in cybersecurity engineering, detection engineering, or automation-focused security roles.
Strong experience with security automation, orchestration, or SOAR platforms.
Proficiency in Python and/or PowerShell for production-grade automation.
Designing secure, observable, and maintainable AI-enabled solutions
Hands-on experience with SIEM/XDR platforms and cloud-scale security tooling.
Practical working knowledge of the MITRE ATT&CK framework and mapping detections to controls.
Built automation for large, diverse enterprise environments, a plus.
Familiarity with platforms such as Microsoft Defender, Microsoft Sentinel, CrowdStrike, Palo Alto XSOAR/XSIAM, Azure AD/Entra ID, Splunk, a plus.
Experience with CI/CD pipelines, infrastructure-as-code, and policy-as-code, a plus.
Background in detection engineering, threat hunting, or incident response, a plus.
Relevant certifications (GCIH, GCFA, Azure Security, cloud or automation certifications), a plus.
Tech Stack
Azure
Cloud
Cyber Security
Python
Splunk
Benefits
Annual bonus target of 10% subject to terms and conditions of plan