
Principal Security Engineer – Orchestration and Automation
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Design, construct, and sustain orchestration workflows and SOAR playbooks to automate triage, enrichment, containment, and response throughout the security tool stack.
• Utilize AI/ML and LLM-assisted methodologies to streamline alert summarization, investigation support, and anomaly scoring.
• Create and uphold Python-based integrations and APIs that connect SIEM, SOAR, EDR, ticketing systems, threat intelligence, and cloud platforms.
• Design, develop, and fine-tune SIEM correlation rules, alerts, and detection use cases aligned with MITRE ATT&CK.
• Conduct SIEM administration tasks, including onboarding data sources, monitoring index/data model health, overseeing log ingestion, and managing configurations.
• Develop and manage custom field extractions, parsers, and content packs.
• Optimize detections and automation logic to enhance signal-to-noise ratios, decrease false positives, and minimize MTTR.
• Generate dashboards and reports that assess automation coverage, orchestration reliability, AI-assisted triage accuracy, and detection efficacy.
• Implement CI/CD and infrastructure-as-code methodologies to administer detection content, playbooks, and integrations as versioned, testable code.
• Assess and pilot new automation, orchestration, and AI tools.
• Collaborate closely with Security Operations and the Detection Engineering Lead.
• Over 5 years of experience in developing automation, orchestration, or SOAR playbooks within a cybersecurity or SOC setting.
• More than 3 years of SIEM engineering or administration experience, including data onboarding, correlation rule creation, and platform configuration.
• Proficient in Python or similar scripting languages.
• Experience in creating APIs and integrations across security and IT tools.
• Practical experience with AI/ML or LLM-based tools applied to security scenarios such as triage, summarization, enrichment, and anomaly detection.
• Solid understanding of MITRE ATT&CK and experience in mapping detections/automation to adversary tactics and techniques.
• Familiarity with a SOAR or security orchestration platform.
• Experience in cloud security with AWS, Azure, or GCP, including automation for ingesting and processing security data from cloud sources.
• Knowledge of CI/CD, infrastructure-as-code, and version-controlling detection/automation content.
• Awareness of containerized and serverless environments and their automation/logging considerations.
• SIEM, SOAR, or security automation platform certification is preferred.
• Experience with regulatory compliance is an advantage.
• Medical, dental, and vision insurance.
• Remote-flexible workforce.
• Wellness Programs.
• 401(k) program with employer match.
• Flexible paid time off.
• Generous Parental Leave.
• Donations for Doers.
• Pet insurance, legal and identity protection.
• Tuition reimbursement program.
Atos
Meridian Bioscience Inc.
Providence
Frontera
Get handpicked remote jobs straight to your inbox weekly.