via LinkedIn
$90K - 140K a year
Develop and maintain SOAR playbooks and automation integrations with security tools to enhance alert triage and incident response.
7-10+ years in automation or security engineering with strong scripting, API integration, and SOC process knowledge.
Required Qualifications Candidates must demonstrate strong automation engineering skills, comfort working with APIs and distributed systems, and practical security knowledge relevant to modern enterprise environments. • Develop and maintain SOAR playbooks for alert triage, enrichment, containment, and remediation. • Build and manage automation integrations with security tooling (SIEM, EDR/XDR, IAM, ticketing, vulnerability management, cloud security) using APIs, webhooks, and event-driven architectures. • 7-10+ years of experience in automation engineering, security engineering, security operations engineering, or a related role. • Proficiency in at least one scripting/programming language (Python preferred; PowerShell, or JavaScript). • Experience with Automation and Orchestration tools like Ansible, Itential, Aria Orchestrator or similar product. • Hands-on experience designing and implementing automation using APIs (REST/JSON), webhooks, and authentication methods (OAuth2, tokens, mutual TLS). • Working knowledge of SIEM concepts (log ingestion, correlation, queries) and SOC processes (triage, escalation, incident handling). • Strong understanding of core security domains: IAM, endpoint security, network security, vulnerability management, and cloud security fundamentals. • Experience with Git-based workflows and software engineering practices (code review, branching strategies, testing). • Ability to document solutions clearly (runbooks, diagrams, operating procedures) and communicate effectively with technical and non-technical stakeholders. Preferred Qualifications and Technical Skills • Experience with vulnerability management automation (ticketing workflows, remediation tracking, exception handling, SLA reporting). • Cloud platform experience (AWS, Azure, and/or GCP), including security services and identity models. • Container and Kubernetes security familiarity • Experience integrating with EDR/XDR tools and automating response actions (isolation, kill process, quarantine). • Familiarity with ITSM and workflow tools (ServiceNow, Jira) and structured change management.
This job posting was last updated on 7/8/2026