SOAR and AI Engineer - Managed Security

AHEAD, LLC

  • NY
  • 1 day ago
  • $120,000–$160,000 Per Year
Want to know if you’re a fit?
Upload your resume and let our AI show you.

Skills

  • Amazon Web Services (AWS)unmatched
  • Analysis Skillsunmatched
  • Application Programming Interface (API)unmatched
  • Artificial Intelligence (AI)unmatched
  • Authenticationunmatched
  • Automationunmatched
  • CASE (Computer-Aided Software Engineering)unmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Case Managementunmatched
  • Channel Strategiesunmatched
  • Cloud Computingunmatched
  • Communication Skillsunmatched
  • Computer Scienceunmatched
  • Computer Securityunmatched
  • Continuous Improvementunmatched
  • Conversation Engineunmatched
  • Customer Relationsunmatched
  • Customer Support/Serviceunmatched
  • Dental Insuranceunmatched
  • Diversityunmatched
  • Email Securityunmatched
  • Enterprise Protectionunmatched
  • Environmental Monitoringunmatched
  • Error Handlingunmatched
  • Establish Prioritiesunmatched
  • Firewallsunmatched
  • GCIA - GIAC Certified Intrusion Analystunmatched
  • GCIH - GIAC Certified Incident Handlerunmatched
  • GCP (Good Clinical Practices)unmatched
  • Identify Issuesunmatched
  • Incident Responseunmatched
  • Information Retrievalunmatched
  • Information Technology & Information Systemsunmatched
  • Information/Data Security (InfoSec)unmatched
  • Intrusion Detection Systemsunmatched
  • JSONunmatched
  • Legalunmatched
  • Machine Learningunmatched
  • Machine Toolunmatched
  • Metricsunmatched
  • Microsoft Windows Azureunmatched
  • Needs Assessmentunmatched
  • Network Securityunmatched
  • Onboardingunmatched
  • Operational Improvementunmatched
  • Operational Supportunmatched
  • Operations Managementunmatched
  • People Managementunmatched
  • Performance Tuning/Optimizationunmatched
  • Presentation/Verbal Skillsunmatched
  • Problem Solving Skillsunmatched
  • Procedure Developmentunmatched
  • Process Developmentunmatched
  • Project/Program Managementunmatched
  • Protective Servicesunmatched
  • Python Programming/Scripting Languageunmatched
  • Regular Expressionsunmatched
  • Reporting Dashboardsunmatched
  • Riskunmatched
  • Sales Pipelineunmatched
  • Scripting (Scripting Languages)unmatched
  • Security Analysisunmatched
  • Security Attacksunmatched
  • Security Information and Event Management (SIEM)unmatched
  • Security Infrastructureunmatched
  • Security Monitoringunmatched
  • ServiceNowunmatched
  • Strategic Planningunmatched
  • System Integration (SI)unmatched
  • System Operationsunmatched
  • Team Lead/Managerunmatched
  • Telemetryunmatched
  • Testingunmatched
  • Time Managementunmatched
  • Use Casesunmatched
  • Vision Planunmatched
  • Workflow Analysisunmatched
  • Writing Skillsunmatched

Description

SOAR and AI Engineer - Managed Security

United States

( Managed Services ) - MS Security /

Full Time /

Remote

apply for this job

AHEAD builds platforms for digital business. By weaving together advances in cloud infrastructure, automation and analytics, and software delivery, we help enterprises deliver on the promise of digital transformation.

At AHEAD, we prioritize creating a culture of belonging, where all perspectives and voices are represented, valued, respected, and heard. We create spaces to empower everyone to speak up, make change, and drive the culture at AHEAD.

We are an equal opportunity employer, and do not discriminate based on an individual''s race, national origin, color, gender, gender identity, gender expression, sexual orientation, religion, age, disability, marital status, or any other protected characteristic under applicable law, whether actual or perceived.

We embrace all candidates that will contribute to the diversification and enrichment of ideas and perspectives at AHEAD.

The Managed Security Team at AHEAD monitors client environments and performs incident detection, validation, response support, and reporting. The SOAR and AI Engineer will be responsible for the design, implementation, and continuous improvement of automation capabilities that increase the scale, speed, and consistency of our Managed Security operations. This role is heavily focused on security automation across SOAR, SIEM, case management, telemetry pipelines, and AI-assisted workflows that support the success of AHEAD's Managed Security program.

Position Overview

This is a technical hands-on position that requires someone with a strong understanding of the needs of a 24/7 SOC (Security Operations Center). We are looking for a candidate with deep experience in security operations, SOAR engineering, scripting, systems integration, and applied AI who will work closely with the Managed Security staff and other highly technical members across multiple teams, both within AHEAD and in client environments, to continuously improve and enhance AHEAD's automation-first Managed Security capabilities.

Incumbents will possess strong technical and analytical skills while providing accurate analysis of security-related problems. They will have a well-rounded networking and security background and will be responsible for automating operational workflows, improving analyst efficiency, reducing mean time to respond, and helping teams troubleshoot complex client issues. This individual is client- and user-focused and works to resolve needs in a timely manner. These needs may involve automating repetitive analyst tasks, orchestrating security response actions, improving enrichment and triage workflows, integrating security tools, and applying AI to improve the speed and quality of security operations.

The SOAR and AI Engineer is responsible for the day-to-day management and evolution of the automation platforms used by the Managed Security Team to monitor client environments and support security investigations and response. This includes workflow design and development, tool integrations, case enrichment, automated triage, alert-to-case orchestration, playbook creation and tuning, chatbot or analyst-assist workflows, and continuous optimization of automation performance and reliability. The SOAR and AI Engineer is expected to be familiar with a wide range of security tools and understand core security operations fundamentals.

Roles and Responsibilities

Design, develop, and maintain security automation workflows within the SOAR platform, with a strong emphasis on scalable, reliable, and auditable automation

Build and maintain automated playbooks for alert triage, enrichment, containment, escalation, evidence gathering, and case management

Partner with SOC analysts, SIEM engineers, threat detection engineers, and incident responders to identify repeatable processes and convert them into high-value automation workflows

Design and implement integrations between SOAR, SIEM, ticketing systems, collaboration tools, endpoint tools, identity platforms, firewalls, threat intelligence sources, and cloud security platforms

Develop automation that improves incident handling speed, consistency, and quality across the Managed Security service

Apply AI and machine learning capabilities where appropriate to improve analyst efficiency, alert summarization, triage recommendations, investigation support, knowledge retrieval, workflow decisioning, and operational reporting

Evaluate, test, and operationalize AI-assisted security use cases in a secure, measurable, and supportable manner

Establish guardrails, quality controls, and validation methods for AI-enabled workflows to ensure output accuracy, consistency, security, and auditability

Partner with AHEAD Managed Security SIEM and SOAR resources to improve alert-to-action workflows and strengthen end-to-end detection and response processes

Engage with client security and IT infrastructure teams for integration and onboarding activities related to automation, orchestration, and response enablement

Create tooling and scripts in Python or similar languages to automate operational tasks, support integrations, normalize data, and improve platform functionality

Monitor and manage the health, performance, and reliability of automation platforms and workflows used by the Managed Security Team

Perform workflow tuning, exception handling, and optimization to reduce false starts, improve success rates, and minimize unnecessary analyst touchpoints

Build and maintain dashboards, reports, and metrics related to automation adoption, workflow effectiveness, case throughput, response time improvements, and platform health

Assist with the development of processes and procedures to improve incident response times, analysis quality, automation maturity, and overall Managed Security functions

Participate in client-facing security meetings to review automation capabilities, implementation progress, service improvements, and operational outcomes

Contribute to the roadmap for automation and AI within Managed Security, including identification of use cases, platform enhancements, and process standardization

Position Requirements

Strong experience with SOAR platforms, preferably Swimlane and Palo Alto XSOAR, including playbook/workflow development, integrations, and operational support

Strong experience with security automation, orchestration, and systems integration in enterprise or managed security environments

Experience writing tools to automate tasks and integrate systems in Python or other languages

Experience working with APIs, webhooks, JSON, authentication methods, and event-driven integrations

Experience with SIEM platforms and common security operations workflows, with the ability to translate analyst needs into automation opportunities

Familiarity with AI-assisted operations, LLM-enabled workflow patterns, or practical uses of AI in security operations and automation

The ability to think creatively to find elegant solutions to complex problems

Excellent verbal and written communication skills

Incident handling and response experience

The desire to work both independently and collaboratively with a larger team

A willingness to be challenged along with a strong appetite for learning

2-4 years of experience in Information Security, Incident Response, SOAR engineering, security automation, detection engineering, or related disciplines

Hands-on experience with common security technologies such as IDS, Firewall, SIEM, SOAR, EDR, IAM, email security, and cloud security tools

Knowledge of common security analysis tools and techniques

Understanding of common security threats, attack vectors, vulnerabilities, and exploits

Knowledge of regular expressions and data transformation concepts

Customer service focused and portrays energy, professionalism, and welcoming characteristics

Strong ability to work in a highly sensitive and confidential environment

Ability to meet deadlines and handle sensitive and pressured situations

Ability to identify issues and help develop strategy and tactical plans for various department initiatives

Ability to use good judgment and decision-making skills

Preferred Qualifications

Experience with Swimlane, Palo Alto XSOAR, Elastic, and related Managed Security tooling

Experience building analyst-assist workflows, case summarization, or AI-powered enrichment pipelines

Familiarity with cloud environments such as AWS, Azure, or GCP and their native security tooling

Experience integrating ServiceNow, collaboration tooling, and case management systems into security operations workflows

Understanding of governance and risk considerations for production AI usage in security operations

Education

Bachelor's Degree in Computer Science, Information Security, Engineering, or related/equivalent educational or work experience

One or more of the following certifications preferred: CISSP, GCIH, GCIA, GMON, GPYC, relevant SOAR certifications, cloud security certifications, or security automation-related credentials

$120,000 - $160,000 a year

The compensation range indicated in this posting reflects the On-Target Earnings ("OTE") for this role, which includes a base salary and any applicable target bonus amount. This OTE range may vary based on the candidate's relevant experience, qualifications, and geographic location.

Why AHEAD:

Through our daily work and internal groups like Moving Women AHEAD and RISE AHEAD, we value and benefit from diversity of people, ideas, experience, and everything in between.

We fuel growth by stacking our office with top-notch technologies in a multi-million-dollar lab, by encouraging cross department training and development, sponsoring certifications and credentials for continued learning.

USA Employment Benefits include:

  • Medical, Dental, and Vision Insurance
  • 401(k)
  • Paid company holidays
  • Paid time off
  • Paid parental and caregiver leave
  • Plus more! See benefits https://www.aheadbenefits.com/ for additional details.

Use of AI:

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, assessing responses, or to capture recordings and create transcriptions or summaries during interviews. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans.

If you would like more information about how your data is processed, please refer to the Candidate Privacy Notice or contact us at [email protected].

You may opt-out of the review or analysis of your application and resume by AI tools by using the General Application. Please include the role you wish to apply for in the Additional Information field. You may also choose to opt-out of recording and transcription at any time, including after joining an interview. Candidates will not be penalized for choosing to opt-out.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

apply for this job

Numbers & Facts

LocationNY
Salary$120,000–$160,000 Per Year

Similar Jobs

See more jobs