Jobgether

Principal Security Engineer, Orchestration and Automation

Jobgether United States · $117K–$158K/yr

Internet Marketplace Platforms · 11-50 employees

13 h ago
Remote security Senior (5-10 yrs) Full-time United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

Design and maintain SOAR playbooks and orchestration workflows to automate security triage, containment, and response. Develop AI/ML and LLM-assisted capabilities to enhance detection, investigation, and analyst efficiency.

What they look for

Security automation Orchestration SOAR SIEM Python AI/ML LLM Cloud security API development Incident response MITRE ATT&CK CI/CD Infrastructure-as-code Detection engineering Data ingestion Security operations

Requirements

Requires 5+ years of experience in security automation or SOAR and 3+ years of SIEM engineering experience. Candidates must possess strong Python scripting skills and experience with cloud security and AI/ML integration.

Benefits

Medical insurance Dental insurance Vision insurance Remote-flexible work environment Wellness programs 401(k) program with employer match Flexible paid time off Parental leave Pet insurance Legal services Identity protection Tuition reimbursement program

Full description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Principal Security Engineer, Orchestration and Automation based in United States.

As a Principal Security Engineer, Orchestration and Automation, you will build the automation, orchestration, and AI-driven capabilities that strengthen modern detection and response operations. You will design intelligent workflows and integrations that reduce manual analyst effort, accelerate incident response, and expand security coverage at scale. The role combines deep security expertise with hands-on engineering across SOAR, SIEM, cloud, APIs, and automation technologies. You will apply AI, machine learning, and LLM-assisted techniques to improve alert triage, enrichment, investigation, and decision-making. You will also maintain core SIEM capabilities that enable reliable detection and automated response workflows. Working closely with Security Operations and Detection Engineering, you will help shape a scalable, innovative, and highly automated security environment.

\n

Accountabilities:

  • Design, build, and maintain SOAR playbooks and orchestration workflows that automate security triage, enrichment, containment, and response across the security technology stack.
  • Develop AI/ML and LLM-assisted security capabilities, including automated alert summarization, investigation assistance, enrichment, and anomaly scoring, to improve analyst efficiency and response speed.
  • Build and maintain Python-based integrations and APIs connecting SIEM, SOAR, EDR, ticketing, threat intelligence, cloud, and other security platforms into unified workflows.
  • Design, develop, and continuously tune SIEM correlation rules, alerts, and detection use cases aligned with MITRE ATT&CK and opportunities for automated response.
  • Own core SIEM engineering and administration activities, including data source onboarding, log ingestion monitoring, index and data model health, and platform configuration.
  • Develop custom field extractions, parsers, and content packs to ensure security data is ready for effective detection and automation.
  • Continuously optimize detection and automation logic to improve signal quality, reduce false positives, and lower mean time to respond.
  • Create dashboards and reporting that measure automation coverage, orchestration reliability, AI-assisted triage performance, and detection effectiveness.
  • Apply CI/CD, infrastructure-as-code, testing, and version-control practices to detection content, integrations, and automation workflows.
  • Evaluate and pilot emerging security automation, orchestration, and AI technologies to expand and modernize detection and response capabilities.

Requirements:

  • 5+ years of experience building security automation, orchestration, or SOAR playbooks within a cybersecurity or SOC environment.
  • 3+ years of SIEM engineering or administration experience, including data onboarding, correlation rule development, and platform configuration.
  • Strong Python or comparable scripting skills, with hands-on experience developing APIs and integrations across security and IT platforms.
  • Demonstrated experience applying AI/ML or LLM-based technologies to security use cases such as alert triage, summarization, enrichment, anomaly detection, or investigation support; experience building these capabilities is strongly preferred.
  • Strong working knowledge of MITRE ATT&CK and experience mapping detection and automation strategies to adversary tactics and techniques.
  • Hands-on experience with SOAR or security orchestration platforms such as Splunk SOAR, Palo Alto XSOAR, Tines, or comparable technologies.
  • Cloud security experience across AWS, Azure, or GCP, including automating the ingestion and processing of security data from cloud environments.
  • Experience with CI/CD, infrastructure-as-code, automated testing, and version control for detection and security automation content.
  • Familiarity with containerized and serverless environments and their security, logging, and automation considerations.
  • Security automation, SIEM, or SOAR certifications are preferred.
  • Experience with regulatory compliance and security control requirements is a plus.
  • Strong analytical, problem-solving, and communication skills, with the ability to work independently and collaborate effectively with Security Operations and Detection Engineering teams.

Benefits:

  • Base salary range of $117,200–$157,500 per year.
  • Medical, dental, and vision insurance.
  • Remote-flexible work environment.
  • Wellness programs and employee well-being resources.
  • 401(k) program with employer match.
  • Flexible paid time off.
  • Generous parental leave.
  • Pet insurance, legal services, and identity protection.
  • Tuition reimbursement program.
  • Opportunities to work with AI, automation, and modern security technologies in a high-impact cybersecurity environment.

\nHow Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

Similar roles