> Markdown version of [/jobs/ext/2618472-security-automation-engineer](https://www.wearedevelopers.com/jobs/ext/2618472-security-automation-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Automation Engineer - **Company:** Chubb Limited - **Location:** Philadelphia, PA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Software Debugging, Akamai, Kusto Query Language, Security Information and Event Management, Software Engineering, Web Applications, Scripting, Software Troubleshooting, Cyber Threat Analysis, Material UI, Microsoft Sentinel, Cortex XSOAR Platform, Virtual Agents, Restful APIs, Splunk, Api Management, Security Orchestration, Automation & Response - **Published:** August 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=199b11cd025076c3 ## About the Role * 3-5 years of IT/security engineering experience, including hands-on scripting or automation work * Strong Python scripting ability, with experience building and debugging integrations against third-party REST APIs * Working knowledge of JavaScript for building or maintaining web-based UI components * Experience integrating disparate security tools (SIEM, EDR, ticketing/ITSM, email security, threat intel, or similar) via API * Comfortable using AI coding/analysis tools (Claude Code or similar) to build and maintain automation * Strong troubleshooting and debugging skills across multi-system workflows * Excellent communication skills - able to translate analyst and IR pain points into automated solutions * Solid documentation habits for technical automation logic and integration configurations * Strong time management and organizational skills Preferred Qualifications: * Hands-on experience with a SOAR platform (Splunk SOAR/Phantom, Palo Alto XSOAR, Tines, or similar) * Experience with case or incident management application design and configuration * Exposure to agentic AI frameworks (e.g., LangGraph) for building AI-assisted security workflows * Familiarity with Microsoft Sentinel/KQL or another SIEM * Security certifications such as Security+, GCIH, or similar * Experience with enterprise security/infrastructure APIs (e.g., Microsoft Graph, Akamai EdgeGrid) ## Description * Design, build, and maintain SOAR playbooks and Python-based automations that integrate with EDR, SIEM, ticketing, identity, network, and threat intel tools * Own and evolve our case and incident management application, including analyst-facing workflows and JavaScript-based UI widgets * Build and maintain custom API integrations, including non-standard auth schemes (e.g., HMAC request signing), pagination, and high-volume or rate-limited data sources * Partner with SOC analysts and incident responders to identify manual, repetitive tasks and automate them end-to-end, from alert ingestion through case closure * Build and extend AI-assisted automation (Claude/Claude Code or similar) to accelerate triage, enrichment, and response * Troubleshoot, monitor, and maintain existing automations and integrations, ensuring reliability as underlying tools and APIs change * Document automation logic, connector configurations, and playbook behavior to support team continuity and knowledge transfer * Translate manual security runbooks into automated, auditable workflows * Evaluate new security tools and data sources for integration feasibility and automation potential ## Related Videos - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [What the Heck is Edge Computing Anyway?](https://www.wearedevelopers.com/videos/593-what-the-heck-is-edge-computing-anyway) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)