
Security Automation Engineer (SOAR Developer, AI-, Playbook Development 5+ Years Exp)
Barracuda Networks, Inc.2 hours ago
Bengaluru, IndiaSenior
Responsibilities
- Engineer and enhance the Barracuda XDR SOAR solution.
- Conduct SOC R&D, detection engineering, threat hunting, threat intelligence research, and purple-team attack-and-defend activities.
- Integrate APIs and security tools into the SOC technology stack.
- Develop and maintain documentation for processes, tools, technologies, and R&D initiatives.
- Expand MITRE ATT&CK coverage through XDR detections and validate detection effectiveness.
- Investigate, triage, and help customers remediate active breaches and incidents during a rotating 24x7x365 on-call schedule.
- Train cybersecurity analysts on technologies and processes.
- Design and implement AI-driven security automations, agentic AI workflows, RAG pipelines, AI agents, and SOC automation tools.
- Integrate and manage MCP servers and agent orchestration frameworks.
- Experiment with and operationalize machine learning models for anomaly detection, alert prioritization, and signal-to-noise improvement.
- Build internal security and AI prototypes to improve SOC efficiency and accuracy.
Requirements
- At least 5 years of cybersecurity or SOC experience.
- Bachelor’s or master’s degree in cybersecurity, information security, or a related field, or related field experience.
- CIH, CEH, CompTIA Network+, CompTIA Security+, or another relevant certification.
- Experience with SIEM, SOAR, EDR, email protection, sandboxes, ticketing systems, and other SOC tools.
- Expertise analyzing advanced cyber attack vectors such as ransomware and business email compromise.
- Experience responding to active security threats and incidents.
- Experience with AWS, Azure, GCP, and APIs.
- Experience with threat intelligence research, IOC gathering, and threat hunting.
- Understanding of cybersecurity frameworks including NIST and MITRE ATT&CK.
- Fundamental understanding of corporate IT environments, networking, and cloud infrastructure.
- Hands-on experience building or working with agentic AI systems, multi-step autonomous workflows, and tool-using agents.
- Experience implementing RAG architectures, including vector databases, embeddings, and context retrieval strategies.
- Familiarity with LLMs, including OpenAI and open-source models, and their cybersecurity applications.
- Experience integrating AI into production environments through API orchestration and automation pipelines.
- Exposure to MCP servers, agent frameworks, or similar orchestration systems.
- Strong understanding of applying AI/ML to security operations problems such as alert fatigue, threat detection, and incident response.
- Ability to evaluate and tune AI outputs for accuracy, reliability, and security relevance in a SOC environment.
- Strong troubleshooting, analytical, problem-solving, verbal communication, and written communication skills.
- Customer service experience.
Benefits
- Equity in the form of non-qualifying options.
- Internal mobility, cross-training, and opportunities for career advancement.
- Rotating 24x7x365 on-call schedule is part of the role.