Назад
Company hidden
8 дней назад

Principal Security Engineer, Orchestration and Automation (AI)

117 200 - 157 500$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Principal Security Engineer, Orchestration and Automation (AI) (SIEM/SOAR, Python, AI): Building orchestration workflows, security integrations, detection logic, and AI-assisted capabilities for cyber detection and response with an accent on automation, SIEM engineering, and cloud security. Focus on developing SOAR playbooks, mapping detections to MITRE ATT&CK, integrating security platforms, and reducing false positives and mean-time-to-respond.

Location: Remote, United States of America

Starting base pay: $117,200–$157,500 per year.

Company

hirify.global develops purpose-driven technology and responsible AI for organizations creating social impact.

What you will do

  • Design, build, and maintain SOAR playbooks and orchestration workflows for automated triage, enrichment, containment, and response.
  • Apply AI/ML and LLM-assisted techniques to alert summarization, investigation support, anomaly scoring, and analyst workload reduction.
  • Develop Python-based integrations and APIs connecting SIEM, SOAR, EDR, ticketing, threat intelligence, and cloud platforms.
  • Build and tune SIEM correlation rules, alerts, parsers, field extractions, and detection use cases mapped to MITRE ATT&CK.
  • Maintain SIEM data onboarding, ingestion monitoring, data health, configuration, dashboards, and reporting.
  • Use CI/CD and infrastructure-as-code practices to manage detection content, playbooks, and integrations as tested, version-controlled code.

Requirements

  • 5+ years of experience building automation, orchestration, or SOAR playbooks in a cybersecurity or SOC environment.
  • 3+ years of SIEM engineering or administration experience, including data onboarding, correlation rules, and platform configuration.
  • Strong Python or comparable scripting skills with experience building APIs and security-tool integrations.
  • Hands-on experience applying AI/ML or LLM-based tooling to security use cases.
  • Working knowledge of MITRE ATT&CK, cloud security across AWS, Azure, or GCP, and CI/CD with infrastructure as code.
  • Experience with SOAR platforms, containerized or serverless environments, and security data automation.

Nice to have

  • SIEM, SOAR, or security automation platform certification.
  • Regulatory compliance experience.

Culture & Benefits

  • Remote-flexible workforce.
  • Medical, dental, and vision insurance.
  • 401(k) program with employer match.
  • Flexible paid time off and generous parental leave.
  • Wellness programs, tuition reimbursement, pet insurance, and legal and identity protection.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →