> Markdown version of [/jobs/ext/250523-security-automation-engineer](https://www.wearedevelopers.com/jobs/ext/250523-security-automation-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Automation Engineer - **Company:** Barracuda Networks, Inc. - **Location:** United States (Remote available) - **Experience:** Experienced - **Salary:** $105,000.0 - $140,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Microsoft Azure, Cloud Computing, CompTIA Network+, Cyber Security, Intrusion Detection and Prevention, Machine Learning, Open Source Technology, Security Information and Event Management, Systems Integration, Google Cloud, Delivery Pipeline, Large Language Models, Multi-Agent Systems, Mitre Att&ck, Generative AI, Cyber Threat Analysis, Cybercrime, Virtual Agents, Purple Team (Cyber Security), Api Design, Data Pipelines, Security Orchestration, Automation & Response - **Published:** May 30, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=1683d603b1ef724e ## About the Role Do you have experience in Threat intelligence?, Do you have a Master's degree?, * 4-5 years prior cybersecurity or SOC experience * Bachelor's degree or Masters Degree in Cyber Security or Information Security or related field experience. * CIH, CEH, CompTIA Network+ or Security+, or other relevant certification * Experience working with various SOC tools including SIEM, SOAR EDR, email protection, sandboxes, ticketing systems, etc. * Expertise with analyzing attack advanced cyber vectors such as ransomware, Business Email Compromise etc. * Experience responding to active security threats and incidents. * Experience with cloud tools such as AWS, Azure and GCP. * Experience working with APIs. * Experience troubleshooting in a technical environment, analytical, problem-solving skills with SOAR platform. * Customer service experience * Experience with threat intelligence research, IOC gathering, and threat hunting. * Understanding of cybersecurity framework such as NIST, MITRE ATT&CK, etc. * Fundamental understanding of corporate IT environments, including networking, cloud infrastructure, etc. * Excellent verbal and written communication skills. * Hands-on experience building or working with Agentic AI systems, including multi-step autonomous workflows and tool-using agents. * Experience implementing RAG architectures, including vector databases, embeddings, and context retrieval strategies. * Familiarity with LLMs (e.g., OpenAI, open-source models) and their application in cybersecurity use cases. * Experience integrating AI into production environments, including API orchestration and automation pipelines. * Exposure to MCP servers, agent frameworks, or similar orchestration systems for managing AI-driven workflows. * Strong understanding of how to apply AI/ML to security operations problems such as alert fatigue, threat detection, and incident response. * Ability to evaluate and tune AI outputs for accuracy, reliability, and security relevance in a SOC environment. ## Description We are currently looking for a talented Security Automation Engineer. This position is responsible for engineering the Barracuda XDR SOAR platform, conducting R&D efforts on forward facing technologies, and executing offensive security operations efforts through the attack/defend lifecycle to test and validate effectiveness of in-place detections. Purple Team members draw from hands-on experience in both offensive and defensive security disciplines to improve the tools, processes, and capabilities of threat detection and response of our SOC. This position requires a strong background in detection engineering with focus on Barracuda XDR SOAR platform. This role requires flexibility and an eagerness to learn new technologies. What You'll Be Working On * Engineering the Barracuda XDR SOAR solution. * Sprint tasks within the SOC Agile Sprint cycle to continuously improve overall SOC maturity level and R&D efforts. * Develop and maintain documentation on new processes, tools, technologies, and on-going R&D efforts. * Integrating various APIs into the SOC tech stack. * Proactive threat hunting amongst partners' networks to identify malicious activity. * Attack and Defend activities to test current detections and develop new detections. * Ensuring MITRE ATT&CK Framework coverage is obtained by XDR detections. * Conduct threat intelligence research. * Train new and current cyber security analysts on existing or new technologies, new or existing processes. * Will be on a rotating 24x7x365 on-call schedule to investigate, triage, and help customers remediate active breaches/incidents. * Designing and implementing AI-driven security automations, including Agentic AI workflows to autonomously investigate, triage, and respond to alerts. * Building and maintaining Retrieval-Augmented Generation (RAG) pipelines to enhance threat intelligence enrichment, alert context, and analyst decision-making. * Developing and integrating AI agents with SOC tooling (SIEM, SOAR, EDR) to reduce manual effort and improve response times. * Leveraging LLMs and AI frameworks to automate repetitive SOC tasks such as alert analysis, ticket generation, and incident summarization. * Integrating and managing MCP servers and agent orchestration frameworks to enable scalable, modular AI-driven workflows. * Experimenting with and operationalizing machine learning models for anomaly detection, alert prioritization, and signal-to-noise improvement. * Driving R&D initiatives focused on applying Generative AI in cybersecurity, including detection engineering, threat hunting, and purple team exercises. * Building internal tools and prototypes that combine security data pipelines with AI capabilities to improve SOC efficiency and accuracy. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [API Design - Getting Started](https://www.wearedevelopers.com/videos/33-api-design-getting-started) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Rest API Antipatterns](https://www.wearedevelopers.com/videos/100208-rest-api-antipatterns) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [WWC24 - Chris Wysopal, Helmut Reisinger and Johannes Steger - Fighting Digital Threats in the Age of AI](https://www.wearedevelopers.com/videos/926-wwc24-chris-wysopal-helmut-reisinger-and-johannes-steger-fighting-digital-threats-in-the-age-of-ai) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud)