Information Security Engineer – (SOAR)
Indexed description
Job Title: Information Security Engineer – Security Automation and Response
Primary Location: 100% Remote
Position Type: Direct Hire
Must be US Citizen or Green Card
Must-Have Skills (Top Priority — in order of importance
- )SOAR playbook development — hands-on experience automating repetitive security tasks using SOAR tools, Python, and API integrations
- Threat detection development and SOAR automation knowledge, with IR experience
- Strong SIEM knowledge, including query languages: Yara-L, CQL, SPL, etc
- .Experience supporting AI-driven security operations initiatives
- Prior experience developing SOAR playbooks (not just using pre-built ones)
- Has created processes using SOAR automation
- Helped a SOC gain more visibility with logs
- Has developed detections
Experience with the specific query languages above is a strong signal
Overview: An Information Security Engineer – Security Automation and Response. This is a Direct Hire role, fully remote. This position exists to advance Security Operations capabilities through SOAR playbook development, automation, and AI-driven workflows, streamlining incident response and improving SOC operational efficiency.
- What You Bring to the Role (Ideal Experience)
- BS or BA in Computer Science, Engineering, or equivalent education, training, or work experience
- 5+ years of security experience, or equivalent training and education
- Solid knowledge of computing systems, data network communications, and network architecture
- Hands-on experience with SOAR playbook development
- Required scripting or programming skills (Python, PowerShell, Go,etc.)
- Experience in incident response and threat investigation
- Experience in threat detection and understanding of logging systems
- Security certifications (GIAC, CISSP) preferred
Effective written and verbal communication skills
- What You'll Do (Skills Used in this Position)
- Develop, implement, and maintain SOAR playbooks to automate repetitive security tasks, including alert triage, threat investigation, and incident response, using tools like SOAR, Python, and API integrations
- Advance Security Operations capabilities through AI-driven initiatives, in collaboration with the Information Security Operations Manager
- Investigate malware, intrusions, unauthorized access, and data infiltration/exfiltration
- events Analyze logs, memory, disk images, and network captures to determine attack scope and impact
- Stay current on cyber threats and industry best practices to continuously enhance SOC capabilities
- Work with SIEM platforms and associated query languages (Yara-L, CQL, SPL,etc.)
- Participate in Purple Team activities
Participate in on-call rotation and respond to critical security events
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search