Design build and maintain automation frameworks and integrations that enhance security operations threat intelligence and detection engineering effortsCollaborate with security teams to develop and optimize security workflows automation playbooks and integrations between security tools SIEMs SOAR platforms EDR XDR and case management systemsEngineer and maintain cloud native security solutions in AWS Azure and other cloud environments ensuring security compliance and scalabilityDevelop and implement Infrastructure as Code IaC solutions using Terraform Ansible or similar technologies to deploy and manage security toolingWork closely with the software engineering and DevOps teams to embed security into CICD pipelines ensuring secure code deployment and automated security testingSupport log aggregation enrichment and correlation across multiple data sources to enhance threat detection and response capabilities Implement and maintain API driven integrations between security platforms automation tools and threat intelligence feedsOptimize security telemetry ingestion correlation and alerting workflows to improve security detection and response effectivenessLead engineering efforts for security tooling ensuring alignment with overall security architecture and operational requirementsConduct security assessments of automation tools and integrations identifying gaps and implementing security enhancementsPartner with the security and operations teams to build and refine detection logic response automation and platform tuning for SOC efficiencyQualifications and Experience5 plus years of experience in SecDevOps Security Automation or a related engineering roleStrong hands on experience with security automation platforms eg Torq Phantom Cortex XSOAR or similar SOAR solutionsExpertise in scripting and automation using Python PowerShell Bash or GoExperience working with SIEMs Splunk Stellar Cyber Sentinel etc and designing log aggregation correlation and alerting workflowsProficiency in cloud security engineering for AWS Azure or GCP including deployment of security controls and monitoring solutionsExperience with Infrastructure as Code IaC tools like Terraform Ansible or CloudFormationStrong understanding of DevOps principles and experience securing CICD pipelines with tools such as GitHub Actions GitLab CICD Jenkins or similarProficiency in API development and integration leveraging RESTful APIs webhooks and automation frameworksExperience with container security Docker Kubernetes and implementing security controls for microservices architecturesFamiliarity with threat intelligence platforms TIPs and their integration with security toolsKnowledge of secure coding practices and ability to perform security reviews of automation code and integrations Strong problem solving skills and ability to work in a fast paced collaborative environmentPreferred QualificationsExperience working in an MSSP or SOC environmentCertifications such as AWS Certified Security Specialty Azure Security Engineer GIAC GCFA GCIA CISSP or OSCPExperience with Kafka Elastic Stack or other log aggregation and analytics platformsKnowledge of machine learning models for security automation and AI enhanced security analyticsBackground in offensive security red teaming or penetration testing with a focus on automation and tool development
The SecDevOps Engineer plays a key role in architecting deploying and maintaining security-driven automation integrations and platform engineering initiatives that support security operations threat intelligence and incident response functions. This position focuses on enabling scalable efficient and resilient security tooling across a global infrastructure
Collaboration with cross-functional teams including Security Automation Threat Intelligence Software Engineering and Security Operations is essential to design build and optimize robust and reliable security solutions. The role contributes to strengthening the overall security posture through automation system integration and infrastructure modernization
Key Responsibilities
Architect develop and maintain secure and scalable automation solutions to enhance security operations and incident response
Design and implement integrations between security platforms tools and services to improve threat detection and response capabilities
Identify and deliver automation opportunities that increase operational efficiency and consistency
Build and maintain infrastructure and CICD pipelines with security and compliance best practices
Ensure consistency with internal standards industry benchmarks and regulatory requirements
Continuously improve internal security tooling and operational processes through innovation and automation