Security Automation Engineer (DevSecOps)
Posted
Aug 17, 2026 (12d ago)
Seniority
Not Specified
Work Model
Not Specified
Type
Not Specified
Category
Salary
Not specified
Skills
Description
Position Summary The Security Automation Engineer is part of ECI's Security Engineering team and focuses on building and operating the automation layer that powers security services at scale. This is a hands-on engineering role with strong emphasis on production Python, integration engineering, and reliable delivery. You will design and maintain automation services, detection-as-code pipelines, and SOAR workflows that integrate with the wider security platform. As part of our modern engineering approach, this role uses AI-assisted workflows to improve delivery quality, reduce repetitive operational effort, and accelerate security outcomes across detection, response, and platform services. You will work within the Automation function, where your focus is building and operating the code, workflows, and integrations that deliver detection and response outcomes. You will partner closely with Platform Engineering, which is accountable for the Elastic environment, Logstash estate, and core data pipelines that provide the telemetry your automations depend on. In practice, this means Automation owns how workflows are engineered, tested, deployed, and maintained, while Platform owns data ingestion, parsing standards, schema quality, and platform reliability. Responsibilities Build and maintain production Python services, internal tooling, and reusable libraries for security automation. Build and operate detection-as-code workflows including rule lifecycle, testing, versioning, and release controls. Develop and maintain SOAR workflows for investigation and response orchestration. Engineer robust integrations across internal systems and third-party tools using REST APIs, webhooks, and event-driven patterns. Build and maintain CI/CD pipelines, automated tests, and quality gates for automation and detection content. Contribute automation capabilities that support Platform-led client onboarding, offboarding, and technology enablement processes. Improve reliability, observability, and maintainability of automation services through metrics, logging, alerting, and runbooks. Collaborate in architecture and code review practices to raise engineering standards across the function. Explore and apply AI-assisted engineering practices to improve automation quality, testing, documentation, and delivery efficiency. Requirements Degree in Computer Science, Cyber Security, Engineering, or equivalent practical experience. 3+ years building and maintaining production Python applications, services, or automation systems. Strong software engineering fundamentals: modular design, testing strategy, error handling, code review, and maintainable code structure. Experience building API integrations and automation workflows in production environments. Practical CI/CD experience with automated testing and controlled deployment workflows. Proficiency with Git and collaborative development practices. Working knowledge of Linux administration in engineering environments. Working knowledge of cloud platforms and services, including IAM, networking, and secure integration patterns in AWS, Azure, or GCP. Foundational understanding of detection and incident response concepts within security operations. Interest in AI-assisted engineering, emerging technologies, and modern engineering practices that improve delivery quality and efficiency. Interest in evolving security threats, cyber security trends, and the changing technology landscape. Preferred Experience with SOAR platforms and workflow orchestration in enterprise security environments. Experience with detection engineering in Elastic Security, Splunk, or Microsoft Sentinel. Familiarity with MITRE ATT&CK, Sigma, or detection-as-code practices. Experience integrating AI-assisted capabilities into operational workflows. Exposure to containerized deployment patterns with Docker or Kubernetes. Experience developing shared internal tooling used by multiple engineering teams. What Good Looks Like You ship high-quality Python services and tooling that are reliable, testable, and easy for others to extend. Detection and automation changes move through a repeatable engineering lifecycle with clear quality controls. Integrations are robust, observable, and resilient under real operational load. Automation delivery reduces manual operational effort while improving consistency and response speed. You raise team engineering standards through strong design, documentation, and review discipline. You use AI-assisted workflows in practical, controlled ways that improve automation quality, reduce manual effort, and accelerate response outcomes.
Similar Jobs
Application Security Engineer II
Abnormal · Anywhere in the World
Security Engineer - Product
wizinc · Berlin
Senior Application Security Engineer
Temporal Technologies · Anywhere in the World
Software Engineer – Gloucester – National Security West
BAE Systems · Gloucester, England, United Kingdom