AWSCloudCyber SecurityPythonSplunkTerraformAILarge Language ModelsAgenticPulumiCloudFormationREST APILeadershipCollaboration
About this role
Role Overview
Architect and develop SOAR playbooks and automated workflows to streamline incident triage, containment, and remediation processes, directly improving SOC efficiency and reducing mean time to response
Build and maintain secure integrations across security, identity, and cloud platforms using APIs and custom code, ensuring scalable solutions that meet compliance and governance requirements
Lead cross-functional collaboration with SOC, Detection Engineering, and Incident Response teams to identify automation opportunities and translate operational needs into technical solutions
Deploy cloud-based security infrastructure using infrastructure-as-code practices, managing role-based access controls and supporting disaster recovery initiatives
Incorporate cutting-edge AI technologies including Agentic AI and Large Language Models into security workflows to enhance decision-making and contextual understanding
Produce executive-level reporting on automation performance metrics and ROI, presenting program effectiveness to leadership while supporting strategic security initiatives
Requirements
Bachelor's degree in Computer Science, Cybersecurity, or related field, or equivalent professional experience in security automation and orchestration
5+ years of proven experience designing and implementing security automation solutions in enterprise environments with hands-on SOAR platform expertise
Strong proficiency in Python programming and experience with detection technologies such as YARA, along with REST API development and third-party service integrations
Deep technical expertise across security platforms including SIEM technologies (such as Splunk, QRadar, or Sentinel), SOAR platforms (such as Phantom, Demisto, or Swimlane), and EDR solutions (such as CrowdStrike, SentinelOne, or Microsoft Defender)
Hands-on experience with cloud infrastructure deployment particularly in AWS environments, using infrastructure-as-code tools (such as Terraform, CloudFormation, or Pulumi)
Strong understanding of incident response frameworks including MITRE ATT&CK, security operations workflows, and the ability to translate operational requirements into scalable technical solutions
Tech Stack
AWS
Cloud
Cyber Security
Python
Splunk
Terraform
Benefits
Health & Wellness: Health care coverage designed for the mind and body.
Flexible Downtime: Generous time off helps keep you energized for your time on.
Continuous Learning: Access a wealth of resources to grow your career and learn valuable new skills.
Invest in Your Future: Secure your financial future through competitive pay, retirement planning, a continuing education program with a company-matched student loan contribution, and financial wellness programs.
Family Friendly Perks: It’s not just about you. S&P Global has perks for your partners and little ones, too, with some best-in class benefits for families.
Beyond the Basics: From retail discounts to referral incentive awards—small perks can make a big difference.