SOAR and AI Engineer - Managed Security

AHEAD
United States
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence User Authentication Cloud Computing Security Cyber Security Data Transformation Identity and Access Management Intrusion Detection and Prevention Intrusion Detection Systems JSON Python (Programming Language) Regular Expressions
+8 more
Security Information and Event Management Systems Integration Scripting Firewalls (Computer Science) Cortex XSOAR Platform Webhooks Security Orchestration, Automation & Response Vulnerability Analysis

Job description

Experteer Overview In this role you will design, build, and continuously improve automation and AI-assisted workflows for AHEAD’s 24/7 Managed Security operations. You’ll work closely with SOC and engineering teams to translate analyst needs into scalable SOAR playbooks, integrations, and AI-enabled capabilities. The position focuses on accelerating incident handling, enrichment, and response through automation while ensuring security and auditability. It’s an opportunity to shape security automation at scale within a culture that values belonging and cross-team collaboration. Compensation / Benefits * Design, develop, and maintain scalable security automation workflows in the SOAR platform * Create automated playbooks for triage, enrichment, containment, and case management * Integrate SOAR with SIEM, ticketing, collaboration, endpoint, identity, and cloud security tools * Develop Python scripts and integrations to automate tasks and normalize data * Apply AI/ML to improve analyst efficiency, alert triage, and workflow decisioning * Establish guardrails and validation for AI-enabled workflows * Collaborate with SOC, SIEM, threat detection, and incident response teams on automation opportunities * Monitor, tune, and optimize automation platforms for reliability and performance * Build dashboards and metrics to track automation adoption and incident response improvements * Contribute to automation/AI roadmap and client onboarding activities Tasks * Strong experience with SOAR platforms (preferably Swimlane and Palo Alto XSOAR) * Security automation, orchestration, and systems integration experience * Proficiency in Python or other scripting languages for automation * Experience with APIs, webhooks, JSON, authentication, and event-driven integrations * Familiarity with SIEM platforms and security operations workflows * Knowledge of AI-assisted operations and practical uses of AI in security * Excellent verbal and written communication skills * Incident handling and response experience * Ability to work independently and collaboratively in a high-sensitivity environment * 2-4 years in Information Security, Incident Response, SOAR engineering, or related fields * Hands-on experience with IDS, Firewall, SIEM, SOAR, EDR, IAM, email security, and cloud security tools * Understanding of security threats, attack vectors, vulnerabilities, and exploits * Knowledge of regular expressions and data transformation concepts * Customer service oriented with professionalism and strong judgment Key requirements * Medical, Dental, and Vision Insurance * 401(k) * Paid holidays * Paid time off * Paid parental and caregiver leave * Plus more benefits

Requirements

belonging alert triage, and workflow decisioning * Establish guardrails and validation for AI-enabled workflows * Collaborate with SOC, SIEM, threat detection, and incident response teams on automation opportunities * Monitor, tune, and optimize automation platforms for reliability and performance * Build dashboards and metrics to track automation adoption and incident response improvements * Contribute to automation/AI roadmap and client onboarding activities Tasks * Strong experience with SOAR platforms (preferably Swimlane and Palo Alto XSOAR) * Security automation, orchestration, and systems integration experience * Proficiency in Python or other scripting languages for automation * Experience with APIs, webhooks, JSON, authentication, and event-driven integrations * Familiarity with SIEM platforms and security operations workflows * Knowledge of AI-assisted operations and practical uses of AI in security * Excellent verbal and written communication skills * Incident handling and aa aaaaJ_ experience * Ability to work independently and collaboratively in a high-sensitivity environment * 2-4 years in Information Security, Incident Response, SOAR engineering, or related fields * Hands-on experience with IDS, Firewall, SIEM, SOAR, EDR, IAM, email security, and cloud security tools * Understanding of security threats, attack vectors, vulnerabilities, and exploits * Knowledge of regular expressions and data transformation concepts * Customer service oriented with professionalism and strong judgment Key requirements * Medical, Dental, and Vision Insurance * 401(k) * Paid holidays * Paid time off * Paid parental and caregiver leave * Plus more benefits

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on us.experteer.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Addressing active AI incident remediation and broad ecosystem support

Matthew Brady Matthew Brady · WWC Europe 2026

3:47 min

Exploring JSON, CBOR, and JOSE for data serialization

Aaron Russell · LIVE

1:28 min

Synchronizing database webhook triggers with pipeline webhooks

Bobur Umurzokov · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:03 min

Distinguishing type definition constructs from data validation routines

Clemens Vasters Clemens Vasters · WWC 2025

Videos

See all

Related articles

See all