Cybersecurity Systems Engineer
The job description
Tech stack. SOAR platforms (Splunk SOAR, Palo Alto XSOAR), REST APIs, Python, SIEM and EDR integrations, Kafka or message queues, Terraform, Git, detection-as-code pipelines
About the role
You will build the connective tissue of a technology company's security stack, integrating dozens of specialized tools into one coherent detection and response system. The team automates away analyst toil so skilled people spend their hours on judgment rather than copy-paste, and you will own the platforms and pipelines that make that possible. You will design event-driven workflows, maintain integration reliability, and treat security tooling as a product with internal customers. This role matters because a security program moves only as fast as its slowest manual step, and you eliminate those steps one integration at a time until the whole system hums. You will also build the detection-as-code pipeline that versions, tests, and deploys every detection rule through CI, so the SOC ships logic with the same rigor as product code.
What you will achieve
- Automate alert enrichment so analysts receive complete context on every ticket without manual lookups, cutting average triage time in half.
- Build SOAR playbooks that automatically contain commodity malware infections within minutes of initial detection, with full audit trails.
- Integrate 15+ security tools through documented APIs into a unified data model the entire team queries consistently.
- Reduce manual reporting toil 80 percent with scheduled, self-service dashboards and exports that leadership genuinely trusts.
- Maintain 99.5 percent uptime across security integrations with proactive health monitoring and automatic failover behavior.
What you will bring
Must-haves
- 2 to 5 years in security engineering, systems integration, or automation-focused IT roles with production systems.
- Strong Python skills for API integrations, data transformation, and resilient workflow automation.
- Experience with SOAR platforms or building equivalent automation purely with code and queues.
- Understanding of REST APIs, webhooks, authentication patterns, and message queue designs for event-driven work.
- Familiarity with SIEM and EDR data models and how detections flow through them from signal to ticket.
- Version control discipline with Git plus infrastructure as code basics for managing your own tooling.
- Product mindset toward internal tooling: you gather analyst feedback and iterate on usability.
Nice-to-haves
- Experience with streaming platforms such as Kafka for high-volume security telemetry pipelines.
- Knowledge of detection-as-code workflows with CI pipelines validating detection content.
- Background in data engineering or ETL pipeline design and optimization.
- Familiarity with infrastructure monitoring for integration health and alerting.
Google
Microsoft
CrowdStrike
Palo Alto Networks
Cisco
Okta