SOAR And AI Engineer (Managed Security)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
SOAR And AI Engineer (Managed Security): Designing and operating security automation for a 24/7 managed SOC with an accent on SOAR workflows, SIEM integrations, incident response, and AI-assisted operations. Focus on building reliable playbooks, integrating security platforms, applying LLM-enabled workflows, and improving alert triage, response speed, and analyst efficiency.
Location: Remote within the United States
Salary: $120,000–$160,000 per year in on-target earnings, including base salary and any applicable target bonus.
Company
builds digital business platforms by combining cloud infrastructure, automation, analytics, and software delivery for enterprise clients.
What you will do
- Design, develop, maintain, and optimize scalable SOAR workflows and automated playbooks for triage, enrichment, containment, escalation, evidence gathering, and case management.
- Integrate SOAR and SIEM platforms with ticketing, collaboration, endpoint, identity, firewall, threat intelligence, and cloud security tools.
- Partner with SOC analysts, SIEM engineers, detection engineers, incident responders, and client security teams to convert repeatable processes into automation.
- Apply AI and machine learning to alert summarization, triage recommendations, investigation support, knowledge retrieval, workflow decisioning, and reporting.
- Build Python-based tooling, dashboards, metrics, and data transformations while monitoring automation platform reliability and performance.
- Contribute to the Managed Security automation and AI roadmap, including governance, quality controls, and production use-case standardization.
Requirements
- Strong experience with SOAR platforms, preferably Swimlane and Palo Alto XSOAR, including workflow development, integrations, and operational support.
- 2–4 years of experience in information security, incident response, SOAR engineering, security automation, detection engineering, or related disciplines.
- Experience with Python or similar languages, APIs, webhooks, JSON, authentication methods, and event-driven integrations.
- Experience with SIEM platforms, incident handling and response, and common security technologies including IDS, firewalls, EDR, IAM, email security, and cloud security tools.
- Familiarity with AI-assisted operations, LLM-enabled workflow patterns, security threats, attack vectors, vulnerabilities, exploits, regular expressions, and data transformation.
- Strong communication, analytical, problem-solving, judgment, collaboration, and customer-service skills for work in sensitive and high-pressure environments.
Nice to have
- Experience with Elastic, ServiceNow, collaboration tools, and managed security tooling.
- Experience building analyst-assist workflows, case summarization, or AI-powered enrichment pipelines.
- Familiarity with AWS, Azure, GCP, and native cloud security tooling.
- Understanding of governance and risk considerations for production AI in security operations.
- Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field, and certifications such as CISSP, GCIH, GCIA, GMON, GPYC, SOAR, or cloud security credentials.
Culture & Benefits
- Remote work within the United States as part of a managed security organization supporting client environments.
- Medical, dental, and vision insurance.
- 401(k), paid company holidays, paid time off, and paid parental and caregiver leave.
- Professional development through cross-department training and sponsorship of certifications and credentials.
- Inclusive workplace focused on diverse perspectives, belonging, and employee participation.
Hiring process
- Parts of the hiring process may use AI tools to review applications, assess responses, or record and summarize interviews.
- Human reviewers make final hiring decisions, and candidates may opt out of AI-assisted application review or interview recording and transcription.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →