Elastic, the Search AI Company, enables everyone to find the answers they need in real time using their data. In this role, the Senior Response Automation Engineer will enhance and maintain workflows supporting threat detection and response processes, working on automations that support alert triage and improve security operations.
Responsibilities:
- Drive the full lifecycle of automation development, from design to maintenance, to significantly advance our threat detection and response capabilities
- Optimize and automate core SOC/IR analyst workflows, focusing on delivering rich alert context and efficient triage processes across all detection sources, including the Elastic Detection Engine
- Establish automated feedback mechanisms that empower the Threat Detection team to continuously refine detections, identify false positives, and uncover new enrichment and automation opportunities
- Build and manage integrations across security tools and platforms to create seamless workflows and enhance data correlation for comprehensive threat detection and response
- Architect and implement automated incident response playbooks for effective containment, eradication, and recovery in various threat scenarios
- Serve as a key automation expert, partnering with security analysts and incident responders to transform manual security operations into highly efficient, automated processes
- Innovate and document best practices for detecting, responding to, and eradicating advanced threats, focusing on reducing overall time to response
- Ensure the integrity and effectiveness of all workflows through rigorous testing and validation
- Collaborate strategically with Threat Detection and Response leadership to identify critical areas for enhancement and execute impactful improvement initiatives
Requirements:
- At least 3 years of experience related to automation engineering in a complex, global environment
- Automation experience focused on security operations / incident response is a plus
- Experience with automating with Security Operations and Response (SOAR) tools or alternative tools supporting similar workflows
- Demonstrated ability to take complex / manual processes and solve them through automation
- Demonstrated ability to think innovatively about solving critical security problems
- Strong communication skills, with the ability to make sound decisions with limited information, and embrace challenging the status quo
- You are eligible to work in DoD Impact Level 4 or above cloud service environments
- Tines experience is a plus
- If you've done this with the help of the Elastic Stack, even better!