Jobgether

Principal Security Engineer, Orchestration and Automation

Jobgether

PythonSOARSIEMmachine learningLLMsAPIsCloud SecurityCI/CDInfrastructure as Code

About the Role

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Principal Security Engineer, Orchestration and Automation based in United States. As a Principal Security Engineer, Orchestration and Automation, you will build the automation, orchestration, and AI-driven capabilities that strengthen modern detection and response operations. You will design intelligent workflows and integrations that reduce manual analyst effort, accelerate incident response, and expand security coverage at scale. The role combines deep security expertise with hands-on engineering across SOAR, SIEM, cloud, APIs, and automation technologies. You will apply AI, machine learning, and LLM-assisted techniques to improve alert triage, enrichment, investigation, and decision-making. You will also maintain core SIEM capabilities that enable reliable detection and automated response workflows. Working closely with Security Operations and Detection Engineering, you will help shape a scalable, innovative, and highly automated security environment. This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Principal Security Engineer, Orchestration and Automation based in United States. As a Principal Security Engineer, Orchestration and Automation, you will build the automation, orchestration, and AI-driven capabilities that strengthen modern detection and response operations. You will design intelligent workflows and integrations that reduce manual analyst effort, accelerate incident response, and expand security coverage at scale. The role combines deep security expertise with hands-on engineering across SOAR, SIEM, cloud, APIs, and automation technologies. You will apply AI, machine learning, and LLM-assisted techniques to improve alert triage, enrichment, investigation, and decision-making. You will also maintain core SIEM capabilities that enable reliable detection and automated response workflows. Working closely with Security Operations and Detection Engineering, you will help shape a scalable, innovative, and highly automated security environment. Accountabilities: Design, build, and maintain SOAR playbooks and orchestration workflows that automate security triage, enrichment, containment, and response across the security technology stack. Develop AI/ML and LLM-assisted security capabilities, including automated alert summarization, investigation assistance, enrichment, and anomaly scoring, to improve analyst efficiency and response speed. Build and maintain Python-based integrations and APIs connecting SIEM, SOAR, EDR, ticketing, threat intelligence, cloud, and other security platforms into unified workflows. Design, develop, and continuously tune SIEM correlation rules, alerts, and detection use cases aligned with MITRE ATT&CK and opportunities for automated response. Own core SIEM engineering and administration activities, including data source onboarding, log ingestion monitoring, index and data model health, and platform configuration. Develop custom field extractions, parsers, and content packs to ensure security data is ready for effective detection and automation. Continuously optimize detection and automation logic to improve signal quality, reduce false positives, and lower mean time to respond. Create dashboards and reporting that measure automation coverage, orchestration reliability, AI-assisted triage performance, and detection effectiveness. Apply CI/CD, infrastructure-as-code, testing, and version-control practices to detection content, integrations, and automation workflows. Evaluate and pilot emerging security automation, orchestration, and AI technologies to expand and modernize detection and response capabilities. Requirements: 5+ years of experience building security automation, orchestration, or SOAR playbooks within a cybersecurity or SOC environment. 3+ years of SIEM engineering or administration experience, including data onboarding, correlation rule development, and platform configuration. Strong Python or comparable scripting skills, with hands-on experience developing APIs and integrations across security and IT platforms. Demonstrated experience applying AI/ML or LLM-based technologies to security use cases such as alert triage, summarization, enrichment, anomaly detection, or investigation support; experience building these capabilities is strongly preferred. Strong working knowledge of MITRE ATT&CK and experience mapping detection and automation strategies to adversary tactics and techniques. Hands-on experience with SOAR or security orchestration platforms such as Splunk SOAR, Palo Alto XSOAR, Tines, or comparable technologies. Cloud security experience across AWS, Azure, or GCP, including automating the ingestion and processing of security data from cloud environments. Experience with CI/CD, infrastructure-as-code, automated testing, and version control for detection and security automation content. Familiarity with containerized and serverless environments and their security, logging, and automation considerations. Security automation, SIEM, or SOAR certifications are preferred. Experience with regulatory compliance and security control requirements is a plus. Strong analytical, problem-solving, and communication skills, with the ability to work independently and collaborate effectively with Security Operations and Detection Engineering teams. Benefits: Base salary range of $117,200–$157,500 per year. Medical, dental, and vision insurance. Remote-flexible work environment. Wellness programs and employee well-being resources. 401(k) program with employer match. Flexible paid time off. Generous parental leave. Pet insurance, legal services, and identity protection. Tuition reimbursement program. Opportunities to work with AI, automation, and modern security technologies in a high-impact cybersecurity environment. How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1

You'll be redirected to Jobgether's application page

Job Details

Salary

$117K–$158K

Location

United States

Job type

Full-time

Category

Security Engineering

Experience

5+ years

Posted

Today

Job Highlights

  • $117K–$158K salary
  • 5+ years level role
  • 100% Remote — open to candidates in United States

About Jobgether

This job is hosted by Jobgether. Clicking Apply opens their site.

More jobs from Jobgether on RC9

Remote Work Style

Mixed

Mix of flexible and scheduled meetings

Your Match

See how well your skills line up with this role, and what you're missing.

AI Cover Letter

Generate a cover letter tailored to this job from your profile.