> Markdown version of [/jobs/ext/2256766-senior-detection-platform-engineer-soc-security-automation](https://www.wearedevelopers.com/jobs/ext/2256766-senior-detection-platform-engineer-soc-security-automation). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Detection & Platform Engineer - SOC / Security Automation - **Company:** Tixy Services LLC - **Location:** Dallas, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Automation of Tests, Microsoft Azure, Cloud Computing, Cloud Computing Security, Code Review, Cyber Security, Continuous Integration, DevOps, Github, Intrusion Detection and Prevention, JSON, Python (Programming Language), Runbook, Security Software, Security Information and Event Management, Systems Integration, Scripting, Google Cloud, Data Ingestion, Microsoft Power Automate, Delivery Pipeline, Large Language Models, Mitre Att&ck, Software Troubleshooting, QRadar, Generative AI, Cyber Threat Analysis, Gitlab, Git, Cybercrime, Microsoft Sentinel, Enterprise Integration, Cortex XSOAR Platform, Restful APIs, Splunk, Webhooks, SentinelOne Expertise, Software Version Control, Api Management, Security Orchestration, Automation & Response, Programming Languages - **Published:** August 26, 2026 - **Apply:** https://www.dice.com/job-detail/4aa0f910-f722-4772-bca6-ade0c1375dab ## About the Role * 5+ years of experience in cybersecurity, SOC engineering, detection engineering, security automation, or related fields. * Hands-on experience with Detection-as-Code or automated security detection deployment. * Strong experience with SIEM and SOAR platforms and SOC operational workflows. * Experience developing and tuning security detections across endpoint, cloud, network, email, or DLP telemetry. * Strong experience with Python or similar scripting/programming languages. * Hands-on experience with security automation, SOAR playbooks, REST APIs, and platform integrations. * Experience with Git, CI/CD, version control, automated testing, and deployment pipelines. * Strong understanding of security events, logs, telemetry, detection logic, alerting, and incident response. * Experience integrating multiple security platforms through REST APIs and webhooks. * Strong troubleshooting, analytical, and problem-solving skills. * Ability to work independently in a fast-paced engineering environment., * Experience with Sigma, YARA, or other detection/content-as-code frameworks. * Experience with Splunk, Microsoft Sentinel, IBM QRadar, Elastic, or similar SIEM platforms. * Experience with Cortex XSOAR, Splunk SOAR, Microsoft Sentinel/Logic Apps, or similar SOAR platforms. * Experience with CrowdStrike Falcon, Microsoft Defender, SentinelOne, or similar EDR platforms. * Experience with security telemetry from AWS, Azure, and/or Google Cloud Platform. * Experience with GitHub, GitLab, Azure DevOps, or similar DevOps platforms. * Experience with threat intelligence platforms and automated enrichment. * Experience with Generative AI, LLMs, AI agents, or AI-assisted SOC operations. * Strong understanding of MITRE ATT&CK and modern detection engineering methodologies. * Experience working in a large-scale enterprise SOC environment. Technical Skills Detection Engineering: Detection-as-Code, Sigma, YARA, Detection Logic, Correlation Rules, MITRE ATT&CK SIEM: Splunk, Microsoft Sentinel, QRadar, Elastic, or equivalent SOAR: Cortex XSOAR, Splunk SOAR, Sentinel/Logic Apps, or equivalent Endpoint Security: CrowdStrike, Microsoft Defender, SentinelOne, or equivalent EDR Automation & Development: Python, REST APIs, JSON, Webhooks, Scripting DevOps: Git, GitHub/GitLab, CI/CD, Automated Testing Cloud Security: AWS, Azure, Google Cloud Platform AI: Generative AI, LLMs, AI-Assisted Investigation, AI Agents, Automated Triage Security Frameworks: MITRE ATT&CK, Threat Detection Lifecycle, Incident Response Top 3 Required Skills 1. Detection-as-Code + CI/CD Detection Engineering 2. SIEM/SOAR Engineering + Security Automation 3. Python + REST API Integrations + SOC Detection Engineering Key Competencies * Strong security engineering and automation mindset * Detection engineering and content development * SIEM/SOAR platform engineering * Security automation and API integration * Detection quality and false-positive reduction * Threat detection and incident response * AI-assisted security operations * Production troubleshooting and platform reliability * Strong communication and technical documentation * Ability to work independently and collaborate across security teams ## Description This is not a traditional SOC Analyst role. The ideal candidate will have a strong software-engineering mindset and experience building scalable solutions that improve the effectiveness and efficiency of security operations., The engineer will be responsible for developing and maintaining Detection-as-Code (DaC) pipelines, SIEM/SOAR integrations, security automation, detection content, API integrations, and AI-assisted SOC capabilities. The role will work closely with SOC Analysts, Threat Hunters, Detection Engineers, Threat Intelligence teams, Infrastructure Engineers, and Security Leadership., * Establish detection development standards, automated testing, code review, and deployment processes. * Develop and tune high-fidelity detections across: + Endpoint/EDR telemetry + Cloud security telemetry + Network telemetry + Email security telemetry + DLP telemetry * Reduce false positives while improving detection coverage and alert fidelity. * Maintain detection logic, metadata, documentation, ownership, and lifecycle management. * Translate threat intelligence and SOC analyst requirements into production-ready detection content. * Apply detection engineering methodologies aligned with MITRE ATT&CK and enterprise security requirements., * Develop and maintain SIEM queries, correlation rules, alerts, dashboards, and detection content. * Build and maintain SOAR playbooks for investigation, enrichment, containment, and response. * Develop integrations between SIEM, SOAR, EDR, identity, cloud, email, ticketing, and threat intelligence platforms. * Troubleshoot security data ingestion, platform integrations, automation failures, and detection deployment issues. * Improve the reliability, scalability, and performance of security operations platforms., * Identify repetitive SOC processes and develop automation to reduce manual analyst effort. * Develop reusable Python scripts, APIs, workflows, and automation components. * Integrate security platforms and services using REST APIs, JSON, and webhooks. * Automate alert enrichment using threat intelligence, asset information, identity data, and other contextual sources. * Improve investigation efficiency, response times, consistency, and overall SOC productivity. AI-Assisted SOC Engineering * Identify opportunities to leverage Generative AI, LLMs, and AI agents within security operations. * Support AI-driven alert investigation, triage, enrichment, summarization, and detection development. * Integrate AI capabilities with existing SIEM, SOAR, and SOC workflows. * Establish appropriate validation, governance, and controls for AI-assisted security outcomes. Platform Engineering & Operations * Monitor and optimize the performance, reliability, scalability, and availability of security platforms. * Troubleshoot production issues and participate in incident resolution. * Support platform upgrades, integrations, configuration changes, and operational improvements. * Develop and maintain technical documentation, architecture diagrams, runbooks, and operational procedures. * Collaborate with SOC, Threat Hunting, Threat Intelligence, Detection Engineering, Infrastructure, and Security Leadership teams. ## Related Videos - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Introducing JSON Structure](https://www.wearedevelopers.com/videos/100219-introducing-json-structure) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)