Description of Task to be Performed: The
Security Automation (SOAR) Engineer willbuild, optimize, and scale our automated incident response workflows. You will bridge security operations and software engineering, using modern low-code/pro-code tools and AI to cut response times and strengthen our threat posture.
Core Responsibilities:
- Playbook Automation: Design, build, and maintain end-to-end incident response playbooks within our SOAR platform.
- Workflow Logic: Write custom automation logic using a mix of low-code tools and pro-code scripting.
- Integrations: Connect disparate security tools via REST APIs, webhooks, and event-driven architecture.
- Incident Response: Partner with the SOC team to translate manual triage steps into reliable, automated actions.
- AI Integration: Leverage frontier LLMs (such as ChatGPT, Grok, Claude Code, or Codex) to enhance automation intelligence and code generation.
Primary Languages & Technical Stack- Query & Data: SQL and GraphQL.
- Scripting & Development: Proficiency in Python, JavaScript, or TypeScript (at least one required)
Required Qualifications:- Clearance: Active TS/SCI Clearance with CI Polygraph
- Education & Years of Experience: Bachelor's degree and 8 years of experience related to specific functional area.
- Certifications: Active certifications for both IAT Level II (e.g. CompTIA Security+) and Cyber Security Service Provider (CSSP) Infrastructure Support (e.g. CompTIA Cloud+) by program onboarding date.
- The following individual certifications cover both certification requirements for this program: CompTIA Cybersecurity Analyst, CySA+; EC-Council Certified Network Defender (CND); GlAC Global Industrial Cyber Security Professional, GICSP; (ISC)2 System Security Certified Practitioner (SCCP).
- Hands-on experience and knowledge with the following:
- SOAR Playbook Automation: Proven experience building security orchestration and automated response workflows.
- Workflow Logic: Strong grasp of both low-code interface design and pro-code logic handling.
- API & Architectures: Deep hands-on experience with REST API integration, webhook management, and event-driven systems.
- Incident Response: Understanding of core security incidents, triage procedures, and playbook design patterns.
- Frontier LLMs: Familiarity with AI coding tools and LLMs (ChatGPT, Grok, Claude, Claude Code, Codex) is a strong plus.
Preferred Qualifications:- Extensive experience with SOAR Playbook Automation
- Multiple scripting and development languages
- Deep understanding of incident response playbook design
Benefits - Generous cost sharing for medical insurance for the employee and dependents
- 100% company paid dental insurance for employees and dependents
- 100% company paid long-term and short-term disability insurance
- 100% company paid vision insurance for employees and dependents
- 401k plan with generous match and 100% immediate vesting
- Competitive Pay
- Generous paid leave and holiday package
- Tuition and training reimbursement
- Life and AD&D Insurance