> Markdown version of [/jobs/ext/2684660-security-automation-engineer](https://www.wearedevelopers.com/jobs/ext/2684660-security-automation-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Automation Engineer - **Company:** TransUnion LLC - **Location:** Woodlyn, PA, United States - **Experience:** Expert - **Salary:** $112,500.0 - $187,500.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Automation of Tests, Code Review, Cyber Security, Continuous Delivery, Continuous Integration, DevOps, Intrusion Detection and Prevention, JSON, Python (Programming Language), Key Management, OAuth, Security Information and Event Management, Software Engineering, Systems Integration, Web Services, Flask (Web Framework), Large Language Models, Prompt Engineering, Mitre Att&ck, Cyber Threat Analysis, Git, Fastapi, Kubernetes, Cortex XSOAR Platform, Front End Software Development, Restful APIs, Terraform, Splunk, Webhooks, Docker, Security Orchestration, Automation & Response, Servicenow - **Published:** September 2, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/18142869?backUrl=%2Fcareer%2F18142869%2FSecurity-Automation-Engineer-Pennsylvania-Crum-Lynne ## About the Role * 10+ years of experience in security engineering, security automation, or software engineering with a strong cybersecurity focus. * Hands-on experience with SOAR or security automation platforms such as Splunk SOAR, Cortex XSOAR, Tines, Torq, or similar technologies. * Experience building solutions with modern Large Language Model platforms such as Anthropic Claude, OpenAI, Amazon Bedrock, or similar platforms, including agent design, prompt design, tool-use patterns, and model-output evaluation. * Working knowledge of Security Operations Center operations, incident response workflows, and the MITRE ATT&CK framework. * Strong software engineering fundamentals, documentation practices, written communication skills, and experience working effectively within a distributed global team. Required Technical Skills * Strong production-level Python development experience. * Experience developing and integrating REST APIs, JSON-based services, webhooks, and event-driven solutions. * Knowledge of authentication and secure integration patterns, including OAuth, API keys, and secrets management. * Experience with Git-based development, code review, automated testing, and Continuous Integration and Continuous Delivery practices. * Hands-on experience using APIs, Software Development Kits, and tool-use patterns to build LLM-powered tools, integrations, workflows, or agents. We're also looking for the preferred skills below. Whether you are proficient or could use some brushing up, we're happy to support your career development and growth in: * Experience building autonomous or semi-autonomous agent systems or working with agentic AI security platforms in production. * Experience with LLM fine-tuning, systematic evaluations, safety testing, or red-teaming. * Exposure to Splunk Enterprise Security, Search Processing Language, detection logic, or detection-as-code practices. * Experience with ServiceNow or similar case management and ITSM platforms, along with web-service frameworks such as FastAPI or Flask. * Knowledge of AWS, Docker, Kubernetes, Terraform, DevOps practices, front-end development, or experience mentoring engineers and leading technical workstreams. ## Description The SOAR Development team designs and delivers automation capabilities that strengthen Security Operations Center response and reduce manual effort for security analysts. The team works across security operations, detection engineering, and supporting technology teams to build scalable, AI-driven security solutions within a global and distributed environment. This role reports to Information Security Engineering Manager This is a hybrid position and involves regular performance of job responsibilities virtually as well as in-person at an assigned TU office location for a minimum of two days a week., * Lead the design, development, and maintenance of security response automations on the agentic AI SOC platform, including the migration of existing Splunk SOAR playbooks. * Build agentic workflows from end to end, including prompt and agent design, tool integration, guardrails, output evaluation, and human-in-the-loop review for AI-driven triage and response. * Develop and maintain integrations across SIEM, EDR, threat intelligence, case management, and ITSM platforms using REST APIs, webhooks, and event-driven patterns. * Build internal tools, services, and APIs primarily in Python to expand platform capabilities and reduce repetitive work for security analysts. * Administer and improve the case management platform and its supporting workflows. * Partner with detection engineering teams to convert new security detections into automated response workflows. * Contribute to shared engineering standards through Git-based development, code reviews, automated testing, and CI/CD practices. * Measure the effectiveness of automation through throughput, mean time to respond or remediate, false-positive burden, and analyst time saved. * Create clear technical documentation and runbooks while collaborating across a global, distributed team. ## Related Videos - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)