8 дней назад
Principal Security Engineer, Orchestration and Automation (AI)
117 200 - 157 500$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Principal Security Engineer, Orchestration and Automation (AI) (SIEM/SOAR, Python, AI): Building orchestration workflows, security integrations, detection logic, and AI-assisted capabilities for cyber detection and response with an accent on automation, SIEM engineering, and cloud security. Focus on developing SOAR playbooks, mapping detections to MITRE ATT&CK, integrating security platforms, and reducing false positives and mean-time-to-respond.
Location: Remote, United States of America
Starting base pay: $117,200–$157,500 per year.
Company
develops purpose-driven technology and responsible AI for organizations creating social impact.
What you will do
- Design, build, and maintain SOAR playbooks and orchestration workflows for automated triage, enrichment, containment, and response.
- Apply AI/ML and LLM-assisted techniques to alert summarization, investigation support, anomaly scoring, and analyst workload reduction.
- Develop Python-based integrations and APIs connecting SIEM, SOAR, EDR, ticketing, threat intelligence, and cloud platforms.
- Build and tune SIEM correlation rules, alerts, parsers, field extractions, and detection use cases mapped to MITRE ATT&CK.
- Maintain SIEM data onboarding, ingestion monitoring, data health, configuration, dashboards, and reporting.
- Use CI/CD and infrastructure-as-code practices to manage detection content, playbooks, and integrations as tested, version-controlled code.
Requirements
- 5+ years of experience building automation, orchestration, or SOAR playbooks in a cybersecurity or SOC environment.
- 3+ years of SIEM engineering or administration experience, including data onboarding, correlation rules, and platform configuration.
- Strong Python or comparable scripting skills with experience building APIs and security-tool integrations.
- Hands-on experience applying AI/ML or LLM-based tooling to security use cases.
- Working knowledge of MITRE ATT&CK, cloud security across AWS, Azure, or GCP, and CI/CD with infrastructure as code.
- Experience with SOAR platforms, containerized or serverless environments, and security data automation.
Nice to have
- SIEM, SOAR, or security automation platform certification.
- Regulatory compliance experience.
Culture & Benefits
- Remote-flexible workforce.
- Medical, dental, and vision insurance.
- 401(k) program with employer match.
- Flexible paid time off and generous parental leave.
- Wellness programs, tuition reimbursement, pet insurance, and legal and identity protection.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
12 дней назад
Security Automation Engineer (AI)
112 500 - 187 500$
11 дней назад
Principal Active Defense Engineer (Cybersecurity)
167 200 - 300 000$
12 дней назад
Staff Security Engineer (Fintech)
160 000 - 195 000$
5 дней назад
Principal Cybersecurity Engineer (AI)
184 800 - 277 200$
8 дней назад
Sr. Application Security Engineer (AI)
104 300 - 193 700$
8 дней назад
Staff Application Security Engineer (AI)
189 000 - 303 000$