Jr. Engineer - Security

CBTS

United States

Remote

USD 90,000 - 130,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

CBTS is seeking a Security Automation Engineer I to contribute to the growth of our Security Operations team by developing automation playbooks and integrations across SOAR and XDR platforms. You will translate analyst workflows into reliable automation to accelerate triage, enrichment, containment, and remediation in the SOC.

The role requires 2+ years as a SOC analyst, 1–2 years with SOAR (XSOAR or XSIAM preferred), a bachelor’s degree, and hands-on scripting with Python.

Qualifications

  • 2+ years as a SOC analyst with hands-on alert triage and threat investigation.
  • 1-2 years of experience with SOAR platforms (XSOAR/XSIAM preferred).
  • Bachelor’s degree or equivalent practical experience.

Responsibilities

  • Develop, test, and maintain automated playbooks and integrations across SOAR/XDR platforms.
  • Collaborate with SOC analysts to translate manual workflows into automation.
  • Troubleshoot integration and automation failures and improve playbook performance.

Skills

Automation playbooks
Python scripting
REST APIs
JSON
XSOAR/XSIAM
Threat intelligence

Education

Bachelor’s degree or equivalent

Tools

Python
REST APIs
Regex
JSON

Job description

Job Purpose

As a Security Automation Engineer I, you will contribute to the growth and maturity of our Security Operations team by developing and maintaining automation playbooks and workflows within our SOAR and XDR platforms. You will be responsible for translating analyst-driven investigation workflows into automation that accelerates triage, enrichment, containment, and remediation of issues across the SOC. A strong background in security operations is essential for this role. Understanding what happens before and after an alert is received is what separates functional automation from automation that reflects how real investigations work. By collaborating closely with SOC analysts and senior engineers, you will help reduce manual workload, improve response consistency, and support a more resilient security operation.

Experience

2+ years of experience as a SOC analyst, with senior analyst experience preferred. Candidates must demonstrate hands‑on familiarity with alert triage, threat investigation, and escalation decision‑making.

1-2 years of experience working with a SOAR platform, with Palo Alto XSIAM or XSOAR experience strongly preferred.

Education

Four-year college degree resulting in a bachelor’s degree, or equivalent practical experience.

Certifications, Accreditations, Licenses

One or more of the following certifications:

Palo Alto Cortex, CompTIA Security+, CompTIA CySA+, GIAC GSEC, EC-Council CEH, and similar.

Special Knowledge

The ideal candidate has a solid understanding of cybersecurity principles, common attack techniques, and SOC operational workflows. Candidate will have experience with SIEM, SOAR, EDR/XDR, threat intelligence, endpoint protection, and email security technologies. Familiarity with SOAR playbook development is required, with Palo Alto XSIAM and/or XSOAR experience being strongly preferred. Candidates should understand common detection use cases including phishing, endpoint compromise, identity threats, and network anomalies.

Proficiency in Python for scripting and automation tasks is required. Candidates must be comfortable working with REST APIs, Regex, and JSON to build and troubleshoot platform integrations. Familiarity with Windows, MacOS, and Linux environments is expected.

Skills

Develop, test, and maintain automated playbooks and integrations across Palo Alto XSOAR and Cortex XSIAM. Collaborate with SOC analysts to identify manual, repetitive workflows and translate them into reliable automation. Experience integrating security tools and platforms to support cohesive, automated response workflows.

Strong analytical skills to evaluate playbook performance, identify logic gaps, and iterate based on analyst feedback and operational data. Effective problem‑solving to troubleshoot integration and automation failures.

Clear verbal and written communication skills, with the ability to document playbook logic and contribute to design discussions across distributed teams.

Abilities

Ability to work independently, manage time effectively, and stay productive in a remote environment. Must be a collaborative team player capable of contributing to technical conversations and troubleshooting sessions. High attention to detail to ensure automation logic performs accurately under varied conditions.

Commitment to continuous learning and staying current with evolving threats, detection techniques, and automation capabilities. Ability to adapt playbook logic as the threat landscape and tool stack change over time.

Supervisory Responsibilities

No Supervisory Responsibility.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Automation Engineer – Cortex XSOAR
Automation Engineer – Cortex XSOAR

Veriipro • Atlanta (GA)

On-site
USD 120,000 - 150,000
Senior Cyber Security Engineer
Senior Cyber Security Engineer

CSC • Wilmington (DE)

Hybrid
USD 100,000 - 130,000
Annual leave
Tuition reimbursement
Referral bonuses
+1
Senior Security Operations Platform Engineer
Senior Security Operations Platform Engineer

OtB Tech LLC • New York (NY)

Hybrid
USD 130,000 - 170,000
Remote Security Automation Engineer I
Remote Security Automation Engineer I

CBTS • United States

Remote
USD 90,000 - 130,000
Security Automation Engineer I: SOAR/XSOAR Specialist
Security Automation Engineer I: SOAR/XSOAR Specialist

CBTS • Tennessee

On-site
USD 90,000 - 130,000
Senior Security Automation Engineer (Remote in EST)
Senior Security Automation Engineer (Remote in EST)

GuidePoint Security LLC • United States

On-site
USD 120,000 - 160,000
Security Automation (SOAR) Engineer
Security Automation (SOAR) Engineer

Nava • Reston (VA)

On-site
USD 140,000 - 180,000
Generous medical insurance
Dental insurance paid 100%
Vision insurance paid 100%
+4
Security Automation (SOAR) Engineer
Security Automation (SOAR) Engineer

AnaVation LLC • Reston (VA)

On-site
USD 140,000 - 200,000
Medical insurance
Dental insurance
Disability insurance
+6
Senior Automation & Cybersecurity Engineer
Senior Automation & Cybersecurity Engineer

Cinter Career Services, LLC • Plano (TX)

On-site
USD 130,000 - 180,000
Professional Services Consultant – XSIAM Automation
Professional Services Consultant – XSIAM Automation

Trantor • United States

Hybrid
USD 140,000 - 180,000