Search...

Security Automation Engineer

Tribeca Venture Partners logo
Tribeca Venture Partners

Stealth

Distributed
View jobs by Tribeca Venture Partners

Skills

About the Role

You will design, build, and maintain the automation pipelines and tooling that allow AI-driven detections, investigations, and responses to operate at machine speed. You will work alongside detection engineers, threat intelligence analysts, and AI/ML engineers to turn manual processes into reliable, observable, and testable automation workflows. You will design and operate SOAR playbooks and agentic AI workflows that triage, enrich, and respond to security alerts with minimal human intervention. You will translate detection logic and AI model outputs into actionable, low-noise alerts, tune thresholds, and automate feedback loops. You will build integrations between security tools such as SIEM, EDR, TIP, and identity platforms and AI inference services using APIs, event streaming, and orchestration frameworks. You will instrument automation pipelines with metrics, logging, and alerting, write tests for playbooks, run purple-team exercises and tabletop simulations, and partner with AI/ML, DevSecOps, and IT teams to embed security automation into infrastructure change management workflows.

Requirements

  • 5+ years in security engineering, SecOps, or automation roles
  • Proficiency in Python and/or Go for scripting and tooling
  • Hands-on SOAR experience (Splunk SOAR, Palo Alto XSOAR, Tines, or similar)
  • Experience with SIEM platforms (Splunk, Microsoft Sentinel, Google Chronicle)
  • REST API integration and event-driven architecture
  • Understanding of threat detection logic (MITRE ATT&CK, kill chain)
  • Familiarity with LLM/AI APIs and prompt-driven automation workflows
  • Version control and CI/CD practices (Git, GitHub Actions)
  • Cloud security fundamentals (AWS, Azure, or GCP)
  • Strong written documentation habits

Responsibilities

  • Design and operate SOAR playbooks and agentic AI workflows that triage, enrich, and respond to security alerts with minimal human intervention
  • Translate detection logic and AI model outputs into actionable, low-noise alerts and tune thresholds to improve signal quality
  • Build and maintain integrations between security tools (SIEM, EDR, TIP, identity platforms) and AI inference services using APIs, event streaming, and orchestration frameworks
  • Instrument automation pipelines with metrics, logging, and alerting to verify AI-driven decisions in production
  • Write tests for playbooks and automation logic and run purple-team exercises and tabletop simulations
  • Partner with AI/ML, DevSecOps, and IT teams to embed security automation into infrastructure change management workflows