6 days ago
Remote, WorldwideMid Level
Responsibilities
- Design, develop, and maintain Python-based automation workflows for security investigation, alert triage, enrichment, incident handling, and response.
- Develop complex, reliable, scalable, maintainable, and observable workflows using Temporal.io.
- Integrate security products, APIs, databases, and internal and external systems.
- Work with Microsoft Sentinel, Microsoft Defender, Defender XDR, and associated telemetry and APIs.
- Develop and optimize Kusto Query Language queries for investigations, enrichment, detection, and automation.
- Translate SOC analyst pain points and cybersecurity requirements into actionable automation designs.
- Partner with Cyber Defenders and cross-functional SOC, Engineering, Product, AI, and Platform teams.
- Contribute to requirements analysis, technical design, implementation, testing, monitoring, and continuous improvement.
- Improve automation performance, reliability, coverage, and impact on analyst workload.
Requirements
- At least three years of professional experience in software engineering, cybersecurity, security operations, or automation engineering.
- Hands-on software development experience with coding, API integrations, data processing, error handling, and asynchronous programming.
- Solid understanding of SOC operations, including alert triage, incident investigation, enrichment, threat intelligence, and response.
- Experience with the Microsoft Security ecosystem, preferably including Microsoft Sentinel and Microsoft Defender.
- Strong Kusto Query Language skills for security investigation and automation queries.
- Experience with Git and modern development practices including testing, debugging, code reviews, and CI/CD.
- Understanding of distributed systems, asynchronous processing, workflow orchestration, and scalable automation architectures.
- Preferred experience developing automation for Microsoft Sentinel, Microsoft Defender for Endpoint, Defender XDR, or related Microsoft Security products.
- Preferred experience developing production workflows with Temporal.io or a comparable workflow orchestration framework.
- Preferred experience integrating APIs and working with authentication, JSON, webhooks, external services, cybersecurity APIs, or threat intelligence platforms.
- Knowledge of common attack techniques and frameworks, including MITRE ATT&CK.
