Gulf Coast Automation Group is seeking an Information Security Engineer – Security Automation and Response. This role focuses on advancing Security Operations through SOAR playbook development and automation, enhancing incident response and operational efficiency in the SOC.
Responsibilities:
- Develop, implement, and maintain SOAR playbooks to automate repetitive security tasks, including alert triage, threat investigation, and incident response, using tools like SOAR, Python, and API integrations
- Advance Security Operations capabilities through AI-driven initiatives, in collaboration with the Information Security Operations Manager
- Investigate malware, intrusions, unauthorized access, and data infiltration/exfiltration events
- Analyze logs, memory, disk images, and network captures to determine attack scope and impact
- Stay current on cyber threats and industry best practices to continuously enhance SOC capabilities
- Work with SIEM platforms and associated query languages (Yara-L, CQL, SPL, etc.)
- Participate in Purple Team activities
- Participate in on-call rotation and respond to critical security events
Requirements:
- BS or BA in Computer Science, Engineering, or equivalent education, training, or work experience
- 5+ years of security experience, or equivalent training and education
- Solid knowledge of computing systems, data network communications, and network architecture
- Hands-on experience with SOAR playbook development
- Required scripting or programming skills (Python, PowerShell, Go, etc.)
- Experience in incident response and threat investigation
- Experience in threat detection and understanding of logging systems
- Effective written and verbal communication skills
- Security certifications (GIAC, CISSP)