via LinkedIn
$85K - 130K a year
Develop and maintain SOAR playbooks to automate security tasks and advance SOC capabilities through AI-driven initiatives.
5+ years security experience with hands-on SOAR playbook development, scripting skills, incident response, threat detection, and strong SIEM knowledge.
Job Title: Information Security Engineer – Security Automation and Response Primary Location: 100% Remote Position Type: Direct Hire Must be US Citizen or Green Card • Improving SOC threat detection visibility • What logs are critical to give SOC threat visibility • Common threat detection use cases. How are we automating them. • Common Cyber threat attacks, what is a dsync attack and etc. • Forensics, malware and etc. Really looking for a SOC Analyst (understands common SOC threats and functions) who jumped into Engineering role with specialization in SOAR, SIEM, Logs, Python Threat detection and etc. with a good personality. Must-Have Skills (Top Priority — in order of importance • )SOAR playbook development — hands-on experience automating repetitive security tasks using SOAR tools, Python, and API integrations • Threat detection development and SOAR automation knowledge, with IR experience • Strong SIEM knowledge, including query languages: Yara-L, CQL, SPL, etc • .Experience supporting AI-driven security operations initiatives • Prior experience developing SOAR playbooks (not just using pre-built ones) • Has created processes using SOAR automation • Helped a SOC gain more visibility with logs • Has developed detections Experience with the specific query languages above is a strong signal Overview: An Information Security Engineer – Security Automation and Response. This is a Direct Hire role, fully remote. This position exists to advance Security Operations capabilities through SOAR playbook development, automation, and AI-driven workflows, streamlining incident response and improving SOC operational efficiency. • What You Bring to the Role (Ideal Experience) • BS or BA in Computer Science, Engineering, or equivalent education, training, or work experience • 5+ years of security experience, or equivalent training and education • Solid knowledge of computing systems, data network communications, and network architecture • Hands-on experience with SOAR playbook development • Required scripting or programming skills (Python, PowerShell, Go,etc.) • Experience in incident response and threat investigation • Experience in threat detection and understanding of logging systems • Security certifications (GIAC, CISSP) preferred Effective written and verbal communication skills • What You'll Do (Skills Used in this Position) • Develop, implement, and maintain SOAR playbooks to automate repetitive security tasks, including alert triage, threat investigation, and incident response, using tools like SOAR, Python, and API integrations • Advance Security Operations capabilities through AI-driven initiatives, in collaboration with the Information Security Operations Manager • Investigate malware, intrusions, unauthorized access, and data infiltration/exfiltration • events Analyze logs, memory, disk images, and network captures to determine attack scope and impact • Stay current on cyber threats and industry best practices to continuously enhance SOC capabilities • Work with SIEM platforms and associated query languages (Yara-L, CQL, SPL,etc.) • Participate in Purple Team activities Participate in on-call rotation and respond to critical security events
This job posting was last updated on 9/22/2026