Security Automation Engineer (SOAR) - Mid-Atlantic region (Remote)

3 weeks ago
Full-time
Senior
DevOps and Infrastructure
GuidePoint Security

GuidePoint Security

GuidePoint Security is a trusted cybersecurity consulting firm that provides expertise, solutions, and services to help organizations make informed decisions and minimize risks. Their elite team of experts offers holistic perspectives on cybersecurity,...

Internet Software & Services
251-1K
Founded 2011

Description

  • Design and build security automation and orchestration workflows.
  • Support and improve end-to-end SOC processes including alert triage, escalation, incident response, and case management.
  • Integrate security and IT systems using REST APIs, webhooks, and JSON.
  • Develop custom workflow logic and data transformations using Python scripting.
  • Translate manual security processes into reliable automated workflows with error handling, conditional logic, and secure execution.
  • Work with security tooling such as SIEM, EDR/XDR, ticketing, threat intelligence, and email security platforms.
  • Scope automation requirements with clients and turn them into build plans.
  • Apply automation-as-code and version control practices to workflow development.
  • Collaborate in a consulting or professional services environment and provide solution delivery support.

Requirements

  • 5+ years of experience in security operations with an understanding of how a SOC functions end to end.
  • 3+ years of experience designing and building security automation or orchestration workflows.
  • Hands-on experience with at least one SOAR or automation platform; Tines, Torq, or Cortex XSOAR preferred.
  • Proficiency integrating systems through REST APIs, webhooks, and JSON.
  • Scripting experience, primarily in Python, for custom logic and data transforms.
  • Working knowledge of SIEM, EDR/XDR, ticketing systems such as ServiceNow or Jira, threat intelligence, and email security tools.
  • Ability to decompose manual security processes into automated workflows with error handling, conditional logic, and secure runs.
  • Familiarity with LLMs in development and automation contexts, including Claude Code or Codex, is preferred.
  • Exposure to MCP-based integrations is a plus.
  • Ability to independently scope automation requirements with clients and translate them into a build plan.
  • Platform or vendor certifications in Tines, Torq, Cortex XSOAR, Splunk, Microsoft Sentinel, or CrowdStrike are preferred.
  • Cloud experience with AWS or Azure and familiarity with cloud-native security tooling are preferred.
  • Prior delivery experience in a consulting, professional services, or MSSP environment is preferred.
  • Detection engineering exposure such as detections-as-code or Sigma is preferred.
  • Version control and automation-as-code experience with Git or similar repo controls is preferred.

Benefits

  • Remote-first workforce for U.S.-based employees, with some travel or on-site work required for certain federal positions.
  • Medical insurance options with significant employer premium contributions, including PPO and HSA plan choices.
  • Dental insurance with full employee premium coverage and partial family premium coverage.
  • 12 corporate holidays and a Flexible Time Off (FTO) program.
  • Healthy mobile phone and home internet allowance.
  • Retirement plan eligibility after 2 months at open enrollment.
  • Pet benefit option.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Principal AI Security Specialist - Federal

Zscaler 1K-5K Internet Software & Services

Zscaler is hiring a Principal AI Security Specialist to lead field-facing enterprise AI security engagements, helping Fortune 500 customers adopt GenAI securely across complex sales cycles.

Cybersecurity Generative AI LLM
7 hours, 56 minutes ago

ZScaler Engineer (R-00171)

True Zero Technologies 11-50 Internet Software & Services

True Zero Technologies is seeking a Senior ZScaler Consultant to support enterprise customer deployments by designing, implementing, and operationalizing ZScaler solutions across ongoing projects and presales engagements.

Active Directory CrowdStrike Cybersecurity DNS GitLab SAML SIEM Splunk TLS Wireshark
8 hours, 26 minutes ago

Staff Software Engineer — Identity & Access Management

Xsolla 251-1K Internet Software & Services

Xsolla is hiring a Staff Engineer to lead the architecture and evolution of its Identity & Access Management platform, supporting secure authentication and authorization across its products.

Active Directory CI/CD CockroachDB Git Go Kafka Kubernetes NATS OpenID Connect PostgreSQL SAML TLS
8 hours, 26 minutes ago

Senior Security Engineer II - DSPM

Aledade 1K-5K Health Care Providers & Services

Aledade is hiring a Senior Security Engineer II to help secure its enterprise, cloud-native environments, and applications while improving security through data-driven automation and cross-functional partnership.

AWS Databricks HIPAA PostgreSQL Python Snowflake
8 hours, 41 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers