Senior Automation, Cybersecurity Engineer

Jobtailor

Plano (TX)

On-site

USD 140,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking a cybersecurity automation engineer to design and implement scalable automation across SIEM/SOAR platforms, focusing on alert enrichment and incident response.

You will work with detection engineers and SOC analysts to streamline operations, implement AI-assisted workflows with human oversight, and mentor peers while driving reusable automation standards.

Qualifications

  • 6-9 years of cybersecurity engineering experience with focus on security automation and SOC engineering.
  • Bachelor’s degree in a related field preferred.
  • Strong proficiency with Python, PowerShell, APIs, and cloud automation.
  • Hands-on experience with enterprise SIEM/SOAR platforms, especially Microsoft Sentinel.

Responsibilities

  • Design, build, and maintain automation for alert enrichment, correlation, triage, and incident response.
  • Develop integrations and tooling with production-grade error handling and monitoring.
  • Collaborate with detection engineers and SOC analysts to improve detection workflows and reduce false positives.
  • Design AI-assisted workflows with human-in-the-loop approvals and measurable quality controls.

Skills

Cybersecurity engineering
Automation expertise
Python proficiency
Threat detection
Incident response workflows

Education

Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field

Tools

Python
PowerShell
APIs
Cloud automation
Microsoft Sentinel
Azure Logic Apps
Tines
ServiceNow
Log Analytics
Confluence

Job description

Design, build, and maintain automation for alert enrichment, correlation, triage, incident response, and case handoffs across SIEM/SOAR platforms such as Microsoft Sentinel, Defender/XDR, Azure Logic Apps, Tines, ServiceNow, Log Analytics, and Confluence.
Develop integrations and tooling using Python, PowerShell, APIs, and cloud-native services, with production-quality error handling, monitoring, documentation, and reuse.
Collaborate with detection engineers, incident responders, and SOC analysts to identify automation opportunities, improve detection workflows, reduce false positives, and streamline analyst operations.
Design AI-assisted and agentic workflows for enrichment, investigation, summarization, and decision support, ensuring human-in-the-loop approvals, auditability, and measurable quality controls.
Partner with security, infrastructure, platform, compliance, and risk teams; participate in code/design reviews; mentor others; and help establish reusable automation standards and patterns.

Requirements
  • 6-9 years of cybersecurity engineering experience, including 3-4 years focused on security automation, SOC engineering, SIEM/SOAR development, or similar work.
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field *(preferred)*
  • Strong proficiency with Python, PowerShell, APIs, cloud automation, and production-grade integration patterns.
  • Hands-on experience with enterprise SIEM/SOAR platforms, Microsoft Sentinel preferred, and working knowledge of Microsoft Defender/XDR, Azure Logic Apps, or similar technologies.
  • Solid understanding of threat detection, logging pipelines, alert tuning, incident response workflows, and operational metrics.
  • Excellent problem-solving, documentation, communication, and collaboration skills, with a track record of delivering reliable automation in production.
  • Preferred Qualifications:
  • Experience with Tines for SOC automation and agentic workflow orchestration.
  • Experience building an Agentic SOC using LLM/AI agents for enrichment, investigation, triage, response, and feedback-driven evaluation.
  • Experience with detection-as-code, CI/CD, MITRE ATT&CK, ASIM schemas, Sigma rules, behavioral detections, or observability pipelines.
  • Hands-on experience with LLMs, intelligent agents, AI/ML-assisted security tooling, prompt design, or agent evaluation.
  • Relevant certifications such as Microsoft Cybersecurity Architect, GIAC Security Automation, or Azure Security Engineer Associate.
Core Competencies

Demonstrates expertise in cybersecurity engineering with a strong focus on security automation and SIEM/SOAR development. Proficient in Python, PowerShell, and cloud automation, with a solid understanding of threat detection and incident response workflows.

Highest-signal resume keywords
  • Cybersecurity Engineering Experience
  • Security Automation Expertise
  • Python Proficiency
  • Microsoft Sentinel Experience
  • Incident Response Workflows
ATS Optimization Keywords
Hard Skills
  • Python
  • PowerShell
  • APIs
  • Cloud Automation
  • SIEM/SOAR Development
  • Incident Response
  • Threat Detection
  • Alert Tuning
  • Production-Grade Integration Patterns
  • Detection-As-Code
Soft Skills
  • Problem-Solving
  • Documentation
  • Communication
  • Collaboration
Certifications & Qualifications
  • Microsoft Cybersecurity Architect
  • GIAC Security Automation
  • Azure Security Engineer Associate
Industry Keywords
  • SOC Engineering
  • Automation Standards
  • LLM/AI Agents
  • MITRE ATT&CK
  • Sigma Rules
Tools & Technologies
  • Microsoft Sentinel
  • Defender/XDR
  • Azure Logic Apps
  • Tines
  • ServiceNow
  • Log Analytics
  • Confluence
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Automation & Cybersecurity Engineer
Senior Automation & Cybersecurity Engineer

Cinter Career • Plano (TX)

On-site
USD 140,000 - 190,000
Senior Automation & Cybersecurity Engineer
Senior Automation & Cybersecurity Engineer

Cinter Career Services, LLC • Plano (TX)

On-site
USD 130,000 - 180,000
Senior Automation & Cybersecurity Engineer
Senior Automation & Cybersecurity Engineer

cinter • Plano (TX)

On-site
USD 120,000 - 160,000
Sr. Automation & Cybersecurity Engineer
Sr. Automation & Cybersecurity Engineer

Toyota Tsusho Systems US, Inc. • Plano (TX)

On-site
USD 120,000 - 180,000
AI-Driven Security Automation Engineer
AI-Driven Security Automation Engineer

Jobtailor • Greensboro (NC)

On-site
USD 110,000 - 160,000
Security Incident Response Lead
Security Incident Response Lead

Jobtailor • Colorado

On-site
USD 150,000 - 190,000
Senior Cybersecurity Ops Analyst
Senior Cybersecurity Ops Analyst

Jobtailor • Santa Ana (CA)

On-site
USD 75,000 - 120,000
Security Automation Engineer – Security Engineering
Security Automation Engineer – Security Engineering

Jobtailor • Greensboro (NC)

On-site
USD 110,000 - 160,000
Engineer III – SIEM Integrations
Engineer III – SIEM Integrations

Jobtailor • New York (NY)

On-site
USD 120,000 - 180,000
Engineer II – Cyber Incident Response
Engineer II – Cyber Incident Response

Jobtailor • Pennsylvania

On-site
USD 70,000 - 100,000