Enhancing the efficiency and maturity of the organization’s security operations by designing and implementing robust automated solutions.
Requirements
- Comfortable writing scripts using languages such as Python, PowerShell, or Bash, and experience with automation platforms such as Azure Logic Apps, SOAR tools (e.g., Microsoft Sentinel, Splunk SOAR, Cortex XSOAR).
- Experience designing SOAR workflows for automated security response and incident triage.
- Proven experience with Large Language Models (LLMs) such as GPT-4, OpenAI, Azure OpenAI, or similar frameworks.
- Deep understanding of cybersecurity domains, including incident response, threat detection, and Identity and Access Management (IAM) principles.
- Experience with RESTful APIs, JSON, and integrating various security platforms.
- Familiarity with cloud platforms and cloud-native security services.
- Knowledge of Microsoft Security components such as Microsoft Sentinel, Microsoft Defender XDR, Microsoft Defender for Cloud, Microsoft Intune, etc.
Responsibilities
- Design and deploy AI-driven security agents leveraging state-of-the-art Large Language Models (LLMs) to automate traditionally manual security operations and workflows.
- Leverage LLM-powered platforms such as Microsoft Security Copilot to support cybersecurity tasks including threat hunting, generating policy recommendations, and creating security incident response playbooks.
- Build and maintain SOAR playbooks integrated with various security platforms (e.g., SIEMs, EDRs, identity platforms) to streamline incident response and automation.
- Lead automation initiatives to eliminate manual processes, improve the reliability and visibility of security controls, and define metrics to measure the impact of process improvements.
- Ensure automation workflows and monitoring solutions are resilient, integrated, and optimized for 24/7 detection and response capabilities.
- Support the administration and management of security tools within the Security Engineering team.
- Participate in proof-of-concepts for innovative security and automation solutions.
Other
- Bachelor’s degree in computer science, Information Security, or a related field, or equivalent work experience.
- 5+ years of experience in cybersecurity, with a focus on security engineering and automation.
- Strong communication and collaboration skills, with proven experience working in cross-functional global teams.
- Strong problem-solving and critical thinking skills for addressing security issues and finding effective solutions.
- Ability to work both independently and collaboratively in a fast-paced environment.