G

Senior Security Automation Engineer (Remote in EST)

GuidePoint Security โ€ข United States

remotefull-time
Posted Sep 1, 2026

**Role & seniority: ** Security Automation Engineer / Security Operations (5+ yrs security ops; 3+ yrs building automation/orchestration workflows)

**Stack/tools: **

  • SOAR/automation: Tines, Torq, Cortex XSOAR (hands-on)

  • Integrations: REST APIs, webhooks, JSON

  • Scripting: Python

  • Connected tooling: SIEM, EDR/XDR, threat intelligence, email security, ticketing (ServiceNow/Jira)

  • Emerging tech: AI tools (LLM/agentic coding exposure)

  • Top 3 responsibilities:

    • Design/build SOAR automation workflows that mirror manual SOC processes (triage โ†’ escalation โ†’ incident response โ†’ case management)

    • Implement integrations across SOC tools (SIEM/EDR/TI/email + ticketing) using APIs/webhooks and reliable data handling

    • Create automated workflows with error handling, conditional logic, and secure execution; maintain and iterate based on SOC needs

  • Must-have skills:

    • End-to-end SOC understanding (alert triage, escalation, incident response, case management)

    • Hands-on SOAR automation/orchestration (at least one platform)

    • Python scripting for transforms/logic within workflows

    • Ability to convert manual security steps into robust automated processes

  • Nice-to-haves:

    • LLM usage for development/automation; familiarity with agentic coding tools (e.g., Claude Code/Codex); MCP integrations exposure

    • Ability to scope requirements with clients and translate into a build plan

    • Vendor/platform certifica

Full Description

Required Qualifications 5+ years in security operations with a working understanding of how a SOC functions end to end (alert triage, escalation, incident response, case management) 3+ years specifically designing and building security automation/orchestration workflows Hands-on experience with at least one SOAR/automation platform; Tines, Torq, or Cortex XSOAR preferred Proficiency integrating security and IT systems via REST APIs, webhooks, and JSON Scripting ability, primarily Python, for custom logic, data transforms, and handling within automated workflows

Working knowledge of the tooling categories automations connect to: SIEM, EDR/XDR, ticketing (ServiceNow, Jira), threat intelligence, and email security Ability to decompose a manual security process into a reliable automated workflow, including error handling, conditional logic, and secure runs Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes

Preferred Qualifications

  • Familiarity using LLMs in a development and automation context, including AI assisted or agentic coding tools such as Claude Code or Codex; exposure to MCP based integrations is a plus
  • Ability to independently scope automation requirements with clients and translate them into a build plan

Platform or vendor certifications: Tines, Torq, Cortex XSOAR; or SIEM/EDR certs (such as Splunk, Microsoft Sentinel, CrowdStrike) Cloud experience (AWS or Azure) and familiarity with cloud native security tooling Prior delivery experience in a consulting, professional services, or MSSP environment Detection engineering exposure in areas such as detections-as-code (DaC), Sigma, or similar Version control and automation-as-code practices (Git or similar repo controls)

Security AutomationSOARPythonREST APIsJSONIncident ResponseSIEMEDR/XDRTinesTorqCortex XSOARCloud SecurityDetection EngineeringGitLLM IntegrationCase Management

Cookies & analytics consent

We serve candidates globally, so we only activate Google Tag Manager and other analytics after you opt in. This keeps us aligned with GDPR/UK DPA, ePrivacy, LGPD, and similar rules. Essential features still run without analytics cookies.

Read how we use data in our Privacy Policy and Terms of Service.