Principal Security Engineer, Orchestration and Automation
PythonSOARSIEMmachine learningLLMsAPIsCloud SecurityCI/CDInfrastructure as Code
About the Role
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Principal Security Engineer, Orchestration and Automation based in United States. As a Principal Security Engineer, Orchestration and Automation, you will build the automation, orchestration, and AI-driven capabilities that strengthen modern detection and response operations. You will design intelligent workflows and integrations that reduce manual analyst effort, accelerate incident response, and expand security coverage at scale. The role combines deep security expertise with hands-on engineering across SOAR, SIEM, cloud, APIs, and automation technologies. You will apply AI, machine learning, and LLM-assisted techniques to improve alert triage, enrichment, investigation, and decision-making. You will also maintain core SIEM capabilities that enable reliable detection and automated response workflows. Working closely with Security Operations and Detection Engineering, you will help shape a scalable, innovative, and highly automated security environment. This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Principal Security Engineer, Orchestration and Automation based in United States. As a Principal Security Engineer, Orchestration and Automation, you will build the automation, orchestration, and AI-driven capabilities that strengthen modern detection and response operations. You will design intelligent workflows and integrations that reduce manual analyst effort, accelerate incident response, and expand security coverage at scale. The role combines deep security expertise with hands-on engineering across SOAR, SIEM, cloud, APIs, and automation technologies. You will apply AI, machine learning, and LLM-assisted techniques to improve alert triage, enrichment, investigation, and decision-making. You will also maintain core SIEM capabilities that enable reliable detection and automated response workflows. Working closely with Security Operations and Detection Engineering, you will help shape a scalable, innovative, and highly automated security environment. Accountabilities: Design, build, and maintain SOAR playbooks and orchestration workflows that automate security triage, enrichment, containment, and response across the security technology stack. Develop AI/ML and LLM-assisted security capabilities, including automated alert summarization, investigation assistance, enrichment, and anomaly scoring, to improve analyst efficiency and response speed. Build and maintain Python-based integrations and APIs connecting SIEM, SOAR, EDR, ticketing, threat intelligence, cloud, and other security platforms into unified workflows. Design, develop, and continuously tune SIEM correlation rules, alerts, and detection use cases aligned with MITRE ATT&CK and opportunities for automated response. Own core SIEM engineering and administration activities, including data source onboarding, log ingestion monitoring, index and data model health, and platform configuration. Develop custom field extractions, parsers, and content packs to ensure security data is ready for effective detection and automation. Continuously optimize detection and automation logic to improve signal quality, reduce false positives, and lower mean time to respond. Create dashboards and reporting that measure automation coverage, orchestration reliability, AI-assisted triage performance, and detection effectiveness. Apply CI/CD, infrastructure-as-code, testing, and version-control practices to detection content, integrations, and automation workflows. Evaluate and pilot emerging security automation, orchestration, and AI technologies to expand and modernize detection and response capabilities. Requirements: 5+ years of experience building security automation, orchestration, or SOAR playbooks within a cybersecurity or SOC environment. 3+ years of SIEM engineering or administration experience, including data onboarding, correlation rule development, and platform configuration. Strong Python or comparable scripting skills, with hands-on experience developing APIs and integrations across security and IT platforms. Demonstrated experience applying AI/ML or LLM-based technologies to security use cases such as alert triage, summarization, enrichment, anomaly detection, or investigation support; experience building these capabilities is strongly preferred. Strong working knowledge of MITRE ATT&CK and experience mapping detection and automation strategies to adversary tactics and techniques. Hands-on experience with SOAR or security orchestration platforms such as Splunk SOAR, Palo Alto XSOAR, Tines, or comparable technologies. Cloud security experience across AWS, Azure, or GCP, including automating the ingestion and processing of security data from cloud environments. Experience with CI/CD, infrastructure-as-code, automated testing, and version control for detection and security automation content. Familiarity with containerized and serverless environments and their security, logging, and automation considerations. Security automation, SIEM, or SOAR certifications are preferred. Experience with regulatory compliance and security control requirements is a plus. Strong analytical, problem-solving, and communication skills, with the ability to work independently and collaborate effectively with Security Operations and Detection Engineering teams. Benefits: Base salary range of $117,200–$157,500 per year. Medical, dental, and vision insurance. Remote-flexible work environment. Wellness programs and employee well-being resources. 401(k) program with employer match. Flexible paid time off. Generous parental leave. Pet insurance, legal services, and identity protection. Tuition reimbursement program. Opportunities to work with AI, automation, and modern security technologies in a high-impact cybersecurity environment. How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1
You'll be redirected to Jobgether's application page
Job Details
Salary
$117K–$158K
Location
United States
Job type
Full-time
Category
Security Engineering
Experience
5+ years
Posted
Today
Job Highlights
- $117K–$158K salary
- 5+ years level role
- 100% Remote — open to candidates in United States
About Jobgether
This job is hosted by Jobgether. Clicking Apply opens their site.
Remote Work Style
Mixed
Mix of flexible and scheduled meetings
Your Match
See how well your skills line up with this role, and what you're missing.
AI Cover Letter
Generate a cover letter tailored to this job from your profile.