- Location
- MANILA NET PARK OFFICE, Philippines
- Type
- Full-time
- Department
- Engineering
- Seniority
- Senior
- Experience
- 5+ years
- Source
- Workday
Description
Job Location
MANILA NET PARK OFFICEJob Description
Job Description - Security Engineer - Band 2
Job Title: Security Engineer - Band 2
Job Family: Cyber Defense & Information Technology Security
Overview of the job
As a Senior Automation Engineer (AI-Accelerated Threat Response), you will serve a critical role in our InfoSec’s Cyber Defense Technology team. You will focus on enhancing our organization’s automation, orchestration, and response capabilities through the strategic use of SOAR technology, ensuring our response speed keeps pace with the rise of frontier AI models capable of autonomously discovering and exploiting vulnerabilities at machine speed. You will lead the implementation of our SOAR platform, aiming to boost our overall efficiency and effectiveness in Global Cyber Defense.
In this role, you will collaborate with various stakeholders to understand business requirements and strategize the utilization of automation for enhanced efficiency. Working closely with the Security Operations Center (SOC) team, Detection Engineering, and Incident Response Team (IRT), you will assist in the implementation and management of SOAR technologies, ensuring novel AI-accelerated attack techniques are contained and remediated with minimal human latency.
Responsibilities of the role
- Cooperate with the SOC, Detection Engineering, and broader Global Cyber Defense teams to enhance existing automation and deliver robust security solutions capable of matching the speed of AI-accelerated attacks.
- Evaluate, design, and upgrade SOC processes and workflows, focusing on integrating automation through SOAR tools and technologies to reduce mean-time-to-contain (MTTC) for novel, AI-driven attack techniques.
- Initiate new SOC automation, ensuring compatibility with existing detection and response tools, and rapidly operationalize new automated response actions as Detection Engineering identifies emerging AI-accelerated TTPs.
- Integrate new log sources and develop playbooks to efficiently triage and respond to security incidents while minimizing analysis time, prioritizing machine-speed response for incidents suspected of AI-assisted exploitation.
- Design custom scripts and evaluate AI/LLM-assisted tooling to automate existing detection and response workflows, increasing the speed and consistency of triage and containment.
- Assess SOC alerts statistics and workflows to minimize false positives and accurately direct engineering efforts.
- Create pipelines to enrich logs and alert results, providing a comprehensive view for SOC analysts.
- Operate and mature a SOC playbook, workflow automations, and use cases, with particular focus on scenarios involving frontier AI-enabled reconnaissance, exploit generation, and attack automation.
- Engage with stakeholders to identify business requirements and provide recommendations on leveraging data and automation effectively.
Role Requirements
- Comprehensive knowledge of both classic and emerging threat actor tactics, techniques, and procedures, including the growing use of frontier AI/LLM systems for reconnaissance, exploit development, and attack automation.
- Proven experience in using Python for automating security operations and incident response processes, including integrating AI/LLM APIs to accelerate triage and enrichment.
- Strong understanding of security architecture, tool integration, API development, and automation.
- Extensive knowledge of Incident Response processes, with an emphasis on reducing response time for machine-speed, AI-accelerated attacks.
- Familiarity with common SOC and SOAR processes and workflows.
- Rich background and experience in Security Information and Event Management (SIEM) systems.
- Experience with security-related datasets, log formats, and protocols.
- Excellent communication and collaboration skills to work effectively with cross-functional teams, particularly Detection Engineering.
Job Qualifications
- Bachelor’s degree in information systems, Information Technology (IT), Computer Science, Engineering, or other technical / IT field and / or at least 5+ years of relevant experience.
- Certification *Preferred* Requirements: CISSP, CCSP, OSCP, AWS Certified Solutions Architect (Amazon Web Services), AWS Certified Developer, Relevant certifications in AI/ML or Security Automation
Job Schedule
Full timeJob Number
R000155196Job Segmentation
Experienced Professionals