Sr. Automation & Cybersecurity Engineer in Plano

Energy Jobline
Plano, TX, United States
2 days ago
Apply on www.energyjobline.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Confluence Audit Trail Microsoft Azure Cloud Computing Cloud Database Code Review Cyber Security Continuous Integration Decision Support Systems Intrusion Detection and Prevention
+15 more
Python (Programming Language) Log Analysis Windows PowerShell Security Information and Event Management Systems Integration Data Logging Scripting Large Language Models Prompt Engineering Mitre Att&ck Information Technology Microsoft Sentinel Virtual Agents Security Orchestration, Automation & Response Servicenow

Job description

The Senior Automation & Cybersecurity Engineer is a hands-on technical leader responsible for designing, building, and scaling automation that powers the Security Operations Center (SOC). This role owns automated detection, enrichment, triage, response, and AI-assisted workflows that reduce analyst toil, improve signal quality, and strengthen incident response.

The ideal candidate combines strong engineering fundamentals-scripting, API integration, SIEM/SOAR development, and cloud automation-with practical cybersecurity judgment. They will partner with detection engineers, incident responders, analysts, and platform owners to convert repeatable processes into reliable, governed automation and safely pilot emerging AI and agentic capabilities.

Essential Functions:

· Design, build, and maintain automation for alert enrichment, correlation, triage, incident response, and case handoffs across SIEM/SOAR platforms such as Microsoft Sentinel, Defender/XDR, Azure Logic Apps, Tines, ServiceNow, Log Analytics, and Confluence.

· Develop integrations and tooling using Python, PowerShell, APIs, and cloud- services, with production-quality error handling, monitoring, documentation, and reuse.

· Collaborate with detection engineers, incident responders, and SOC analysts to identify automation opportunities, improve detection workflows, reduce false positives, and streamline analyst operations.

· Design AI-assisted and agentic workflows for enrichment, investigation, summarization, and decision support, ensuring human-in-the-loop approvals, auditability, and measurable quality controls.

· Partner with security, infrastructure, platform, compliance, and risk teams; participate in code/design reviews; mentor others; and help establish reusable automation standards and patterns.

Competencies:

· Develops scalable and reliable security automation that improves SOC efficiency and operational effectiveness.

· Applies sound cybersecurity judgment to design secure, governed, and auditable automation and AI-assisted workflows.

· Collaborates effectively with cross-functional teams to improve detection, response, and operational processes.

· Continuously improves workflows by reducing manual effort, false positives, and analyst workload through automation.

· Provides technical leadership through mentoring, code reviews, and the promotion of engineering best practices.

· Evaluates and implements emerging technologies, including AI capabilities, to enhance security operations while maintaining human oversight.

Requirements

· 6-9 years of cybersecurity engineering experience, including 3-4 years focused on security automation, SOC engineering, SIEM/SOAR development, or similar work.

· Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field ()

· Strong proficiency with Python, PowerShell, APIs, cloud automation, and production-grade integration patterns.

· Hands-on experience with enterprise SIEM/SOAR platforms, Microsoft Sentinel , and working knowledge of Microsoft Defender/XDR, Azure Logic Apps, or similar technologies.

· Solid understanding of threat detection, logging pipelines, alert tuning, incident response workflows, and operational metrics.

· Excellent problem-solving, documentation, communication, and collaboration skills, with a track record of delivering reliable automation in production.

Qualifications:

· Experience with Tines for SOC automation and agentic workflow orchestration.

· Experience building an Agentic SOC using LLM/AI agents for enrichment, investigation, triage, response, and feedback-driven evaluation.

· Experience with detection-as-code, CI/CD, MITRE ATT&CK, ASIM schemas, Sigma rules, behavioral detections, or observability pipelines.

· Hands-on experience with LLMs, intelligent agents, AI/ML-assisted security tooling, prompt design, or agent evaluation.

· Relevant certifications such as Microsoft Cybersecurity Architect, GIAC Security Automation, or Azure Security Engineer Associate.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.energyjobline.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:33 min

Expanding enterprise search integrations with Jira, Confluence, and GitHub

Prashanth Chandrasekar Prashanth Chandrasekar · World Congress 2024

56 sec

Integrating automated approval workflows into the portal

Markus Eisele Markus Eisele · World Congress 2025

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

5:01 min

Bridging the gap between software development and security

Vandana Verma · LIVE

5:15 min

Managing token consumption and knowledge base context

Simon A.T. Jiménez Simon A.T. Jiménez · Europe 2026 Virtual

2:27 min

Establishing a simulated technical environment for the workflow demo

Tobias Dunn-Krahn · LIVE

Videos

See all

Related articles

See all