MDR Security Engineer
Seeking an MDR Security Engineer to own and scale the automation layer powering global managed detection and response operations. The role involves building production-grade automation systems to reduce manual workload, improve detection quality, and enable consistent incident response in a high-volume SOC environment. The company offers a flexible, hybrid work model.
Responsibilities
- Design, develop, and maintain SOAR playbooks, workflows, and integrations across the MDR platform.
- Build and operate production-grade automation systems for alert triage, enrichment, investigation, and response.
- Define and drive automation strategy by identifying high-impact SOC processes and scaling them through automation.
- Develop integrations across SIEM, EDR/XDR, identity, cloud, and ticketing systems using APIs and scripting.
- Partner with MDR analysts, IR, threat hunters, and engineering teams to translate operational workflows into scalable automation.
- Improve detection and response quality through automation of enrichment, investigation, and containment workflows.
- Contribute to incident response and RCAs by delivering tooling that improves investigation speed, accuracy, and consistency.
- Evaluate and implement new automation capabilities, including AI-assisted workflows and data-driven decisioning.
- Define and own automation KPIs such as automation coverage, MTTD/MTTR improvement, false positive reduction, and analyst time saved.
- Build and maintain dashboards and reporting to measure automation impact on SOC performance and SLAs.
- Ensure production reliability and stability of automation systems, including monitoring workflow success/failure rates and integration health.
- Implement logging, alerting, and observability across automation pipelines.
- Continuously optimize workflows based on data, feedback, and operational performance to ensure consistent 24/7 MDR operation.
Requirements
- 4+ years of experience in Security Operations, MDR, Incident Response, or Security Engineering.
- 2–3+ years of hands-on experience with SOAR platforms and security automation.
- Proven experience owning and operating production-grade automation workflows in a SOC/MDR environment.
- Strong understanding of SOC operations, alert triage, escalation workflows, and incident response.
- Experience with enterprise security technologies (SIEM, SOAR, EDR/XDR, IAM/AD).
- Strong scripting/development skills (Python, PowerShell, Bash) and experience building APIs and integrations.
- Experience with CI/CD, version control (Git), and deploying automation at scale.
- Strong analytical thinking and problem-solving skills with the ability to translate complex workflows into automation.
- Excellent communication and collaboration skills across engineering and operations teams.
Nice to have
- Experience with AI-enhanced automation or large-scale workflow orchestration.
- Experience in high-volume MDR/SOC environments.
- Familiarity with threat hunting or detection engineering.