Information Security Engineer – (SOAR)
Job Title: Information Security Engineer – Security Automation and ResponsePrimary Location: 100% RemotePosition Type: Direct HireMust be US Citizen or Green Card Must-Have Skills (Top Priority — in order of importance)SOAR playbook development — hands-on experience automating repetitive security tasks using SOAR tools, Python, and API integrationsThreat detection development and SOAR automation knowledge, with IR experienceStrong SIEM knowledge, including query languages: Yara-L, CQL, SPL, etc.Experience supporting AI-driven security operations initiativesPrior experience developing SOAR playbooks (not just using pre-built ones)Has created processes using SOAR automationHelped a SOC gain more visibility with logsHas developed detectionsExperience with the specific query languages above is a strong signalOverview: An Information Security Engineer – Security Automation and Response. This is a Direct Hire role, fully remote. This position exists to advance Security Operations capabilities through SOAR playbook development, automation, and AI-driven workflows, streamlining incident response and improving SOC operational efficiency.What You Bring to the Role (Ideal Experience)BS or BA in Computer Science, Engineering, or equivalent education, training, or work experience5+ years of security experience, or equivalent training and educationSolid knowledge of computing systems, data network communications, and network architectureHands-on experience with SOAR playbook developmentRequired scripting or programming skills (Python, PowerShell, Go,etc.)Experience in incident response and threat investigationExperience in threat detection and understanding of logging systemsSecurity certifications (GIAC, CISSP) preferredEffective written and verbal communication skillsWhat You'll Do (Skills Used in this Position)Develop, implement, and maintain SOAR playbooks to automate repetitive security tasks, including alert triage, threat investigation, and incident response, using tools like SOAR, Python, and API integrationsAdvance Security Operations capabilities through AI-driven initiatives, in collaboration with the Information Security Operations ManagerInvestigate malware, intrusions, unauthorized access, and data infiltration/exfiltrationevents Analyze logs, memory, disk images, and network captures to determine attack scope and impact Stay current on cyber threats and industry best practices to continuously enhance SOC capabilitiesWork with SIEM platforms and associated query languages (Yara-L, CQL, SPL,etc.)Participate in Purple Team activitiesParticipate in on-call rotation and respond to critical security events