TT

Sr. Automation & Cybersecurity Engineer

Accepting applications

Toyota Tsusho Systems US, Inc. · Plano, TX

Full-Time Mid_senior AIPythonSOCmentor
Posted
2d ago
Category
Design
Experience
Mid_senior
Country
United States
About TTS-US:

Founded in 2011, Toyota Tsusho Systems US, Inc. (TTS-US) is a Toyota group company, that develops IT solutions wherever global businesses operate. Transforming into a technology and mobility company, TTS-US with it's 8 TTS affiliates worldwide is establishing a secure and resilient Toyota global value chain. The creative capacity to forge such limitless business opportunities is one of the strengths of Toyota Tsusho Systems.

Summary:

The Senior Automation & Cybersecurity Engineer is a hands-on technical leader responsible for designing, building, and scaling automation that powers the Security Operations Center (SOC). This role owns automated detection, enrichment, triage, response, and AI-assisted workflows that reduce analyst toil, improve signal quality, and strengthen incident response.

The ideal candidate combines strong engineering fundamentals—scripting, API integration, SIEM/SOAR development, and cloud automation—with practical cybersecurity judgment. They will partner with detection engineers, incident responders, analysts, and platform owners to convert repeatable processes into reliable, governed automation and safely pilot emerging AI and agentic capabilities.

Essential Functions:

Design, build, and maintain automation for alert enrichment, correlation, triage, incident response, and case handoffs across SIEM/SOAR platforms such as Microsoft Sentinel, Defender/XDR, Azure Logic Apps, Tines, ServiceNow, Log Analytics, and Confluence
Develop integrations and tooling using Python, PowerShell, APIs, and cloud-native services, with production-quality error handling, monitoring, documentation, and reuse
Collaborate with detection engineers, incident responders, and SOC analysts to identify automation opportunities, improve detection workflows, reduce false positives, and streamline analyst operations
Design AI-assisted and agentic workflows for enrichment, investigation, summarization, and decision support, ensuring human-in-the-loop approvals, auditability, and measurable quality controls
Partner with security, infrastructure, platform, compliance, and risk teams; participate in code/design reviews; mentor others; and help establish reusable automation standards and patterns

Competencies:

Develops scalable and reliable security automation that improves SOC efficiency and operational effectiveness
Applies sound cybersecurity judgment to design secure, governed, and auditable automation and AI-assisted workflows
Collaborates effectively with cross-functional teams to improve detection, response, and operational processes
Continuously improves workflows by reducing manual effort, false positives, and analyst workload through automation
Provides technical leadership through mentoring, code reviews, and the promotion of engineering best practices
Evaluates and implements emerging technologies, including AI capabilities, to enhance security operations while maintaining human oversight

Requirements

6-9 years of cybersecurity engineering experience, including 3-4 years focused on security automation, SOC engineering, SIEM/SOAR development, or similar work
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field (preferred)
Strong proficiency with Python, PowerShell, APIs, cloud automation, and production-grade integration patterns
Hands-on experience with enterprise SIEM/SOAR platforms, Microsoft Sentinel preferred, and working knowledge of Microsoft Defender/XDR, Azure Logic Apps, or similar technologies
Solid understanding of threat detection, logging pipelines, alert tuning, incident response workflows, and operational metrics
Excellent problem-solving, documentation, communication, and collaboration skills, with a track record of delivering reliable automation in production

Preferred Qualifications:

Experience with Tines for SOC automation and agentic workflow orchestration
Experience building an Agentic SOC using LLM/AI agents for enrichment, investigation, triage, response, and feedback-driven evaluation
Experience with detection-as-code, CI/CD, MITRE ATT&CK, ASIM schemas, Sigma rules, behavioral detections, or observability pipelines
Hands-on experience with LLMs, intelligent agents, AI/ML-assisted security tooling, prompt design, or agent evaluation
Relevant certifications such as Microsoft Cybersecurity Architect, GIAC Security Automation, or Azure Security Engineer Associate
Show more Show less