LT

Security Automation Engineer

Accepting applications

Lumen Technologies India · Noida, Uttar Pradesh, India

Full-Time Senior PythonSOC
Estimated market salary
₹25-44 LPA

This is a SiliconBoard market estimate, not an employer-posted salary.

Posted
20h ago
Category
Design
Experience
Senior
Country
India
Summary

The Security Automation Engineer is responsible for developing, maintaining, and improving automation workflows that support SOC operations, SIEM engineering, EDR integrations, incident enrichment, alert routing, reporting, and customer onboarding. This role focuses on reducing manual effort, improving consistency, and enabling scalable operations across platforms such as Microsoft Sentinel, Cortex XSIAM, CrowdStrike, ServiceNow, and related security tools.

Key Responsibilities

Develop and maintain automation workflows, playbooks, runbooks, and scripts supporting SOC and platform engineering operations.
Build integrations between SIEM, SOAR, EDR, ITSM, ticketing, identity, email security, cloud, and threat intelligence platforms.
Support automation for alert enrichment, escalation routing, case creation, customer notification, and reporting.
Assist with Sentinel Logic Apps, XSIAM playbooks, API integrations, and reusable automation components.
Maintain GitHub repositories, version control practices, deployment templates, and documentation.
Create and maintain parameterized onboarding templates for new customers, log sources, detections, and workflows.
Support automation testing, validation, error handling, and operational handoff.
Partner with SOC analysts to identify repetitive tasks that can be automated or simplified.
Build dashboards, SLA trackers, and operational reporting workflows.
Collaborate with SOC, SIEM, EDR, IT, and customer teams to ensure automations are practical, maintainable, and aligned to operational needs.

Required Qualifications

6-10 years of hands-on experience with security automation, scripting, platform engineering, or SOC tooling.
Experience with Python, PowerShell, Bash, JavaScript, or similar scripting languages.
Familiarity with REST APIs, JSON, webhooks, authentication methods, and integration patterns.
Basic understanding of SIEM, SOAR, EDR, ITSM, and incident response workflows.
Experience working with Microsoft Sentinel, Cortex XSIAM, CrowdStrike, ServiceNow, or similar platforms preferred.
Strong documentation, troubleshooting, and process improvement skills.

Preferred Certifications

Microsoft SC-200 Security Operations Analyst
Microsoft AZ-204 Azure Developer Associate
Microsoft Power Platform certification
CompTIA Security+
Palo Alto Cortex XSIAM/XSOAR certification
CrowdStrike Falcon certification We are an equal opportunity employer committed to fair and ethical hiring practices. We do not charge any fees or accept any payment from candidates at any stage of the recruitment process.

SIEM, Infosec

Show more Show less