Job Description
Client is seeking a Security Developer / Automation Engineer to support its Information Security team. This role focuses on building, optimizing, and automating security operations within a modern security platform. The position combines cybersecurity expertise and software development skills to automate manual processes, improve threat detection, and accelerate incident response.
Key Responsibilities
- Design, implement, and maintain security operations within a SIEM/SOAR platform
- Ensure reliable data ingestion, parsing, and overall system performance
Threat Detection & Alerting
- Develop and refine detection rules to identify security threats
- Improve alert accuracy and reduce false positives using advanced queries
Automation & Playbooks
- Build and maintain automated workflows (playbooks) for incident response
- Streamline alert triage, investigation, and remediation processes
Integrations & Development
- Create integrations between the security platform and external tools (e.g., IT systems, threat intelligence sources)
- Develop APIs and connectors to enable seamless data flow
Scripting & Tools
- Write automation scripts and custom components using:
- Python
- YAML
- PowerShell
- Develop data parsers and custom actions to support workflows
Containerization
- Use Docker to build and deploy containerized services that support automation and integrations
Collaboration
- Work closely with security operations, incident response, and threat intelligence teams
- Continuously improve detection logic and automated responses
Required Qualifications
- 3+ years of experience in security engineering, automation, or security-focused development
- Hands-on experience with SIEM/SOAR platforms (e.g., Palo Alto Cortex XSIAM/XSOAR or similar tools)
- Strong programming skills in Python (especially for APIs and automation)
- Experience with YAML and scripting for configuration and workflows.