About The Position

The SOAR and AI Engineer is responsible for designing, implementing, maintaining, and optimizing security automation and orchestration capabilities across the Security Operations Center. The position also uses AI to accelerate the cybersecurity response process and manage security breaches or system failures specifically targeting AI models and environments. This position develops automated workflows that reduce manual effort, improve response speed, and increase operational consistency. The engineer integrates security tools, develops automated response actions, builds investigation playbooks, and continuously improves operational efficiency. The SOAR Engineer works closely with SOC analysts, incident responders, threat hunters, and security engineers to identify repetitive tasks that can be automated. The engineer transforms manual workflows into scalable automated processes that enable the SOC to operate at greater speed and effectiveness. The position plays a critical role in modernizing security operations and reducing analyst workload while improving response quality.

Requirements

  • Strong knowledge of security operations, incident response processes, API integrations, artificial intelligence, workflow automation, scripting, and orchestration platforms.
  • Experience integrating SIEM platforms, EDR solutions, threat intelligence feeds, ticketing systems, cloud security services, vulnerability management tools, and communication platforms.
  • Strong scripting and automation skills, including experience with Python, PowerShell, REST APIs, JSON, and workflow design.
  • Deep understanding of SOC processes to automate them effectively.
  • Required certifications include Security+, CASP+, CISSP, vendor-specific SOAR certifications, or equivalent experience.

Responsibilities

  • Designing, implementing, maintaining, and optimizing security automation and orchestration capabilities.
  • Using AI to accelerate the cybersecurity response process.
  • Managing security breaches or system failures specifically targeting AI models and environments.
  • Developing automated workflows that reduce manual effort, improve response speed, and increase operational consistency.
  • Integrating security tools.
  • Developing automated response actions.
  • Building investigation playbooks.
  • Continuously improving operational efficiency.
  • Working closely with SOC analysts, incident responders, threat hunters, and security engineers to identify repetitive tasks that can be automated.
  • Transforming manual workflows into scalable automated processes.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service