Jobs · North Carolina

MDR Security Engineer

Varonis · Morrisville, NC · 1 mo ago
HybridFull-time

Responsibilities

  • Upkeep the design, development, and lifecycle of SOAR playbooks, workflows, and integrations across the MDR platform
  • Build and operate production-grade automation systems supporting alert triage, enrichment, investigation, and response
  • Define and drive automation strategy by identifying high-impact, high-volume SOC processes and scaling them through automation
  • Partner with MDR analysts, IR, threat hunters, and engineering teams to translate operational workflows into scalable automation
  • Improve detection and response quality through automation of enrichment, investigation, and containment workflows
  • Contribute to incident response and RCAs by delivering tooling that improves investigation speed, accuracy, and consistency
  • Evaluate and implement new automation capabilities, including AI-assisted workflows and data-driven decisioning
  • Monitor, Metrics & Reliability Ownership: Define and own automation KPIs, including: Automation coverage (% of alerts handled or augmented), MTTD / MTTR improvement, False positive reduction and signal-to-noise improvement, Analyst time saved and throughput increase
  • Build and maintain dashboards and reporting to measure automation impact on SOC performance and SLAs
  • Ensure production reliability and stability of automation systems, including: Monitoring workflow success/failure rates and execution latency, Tracking integration and API health, errors, and retry behavior, Implementing logging, alerting, and observability across automation pipelines, Continuously optimize workflows based on data, feedback, and operational performance to ensure consistent 24/7 MDR operation

Requirements

  • 4+ years of experience in Security Operations, MDR, Incident Response, or Security Engineering
  • 2–3+ years of hands-on experience with SOAR platforms and security automation
  • Proven experience owning and operating production-grade automation workflows in a SOC/MDR environment
  • Strong understanding of SOC operations, alert triage, escalation workflows, and incident response
  • Experience with enterprise security technologies (SIEM, SOAR, EDR/XDR, IAM/AD)
  • Strong scripting/development skills (Python, PowerShell, Bash) and experience building APIs and integrations
  • Experience with CI/CD, version control (Git), and deploying automation at scale
  • Strong analytical thinking and problem-solving skills with the ability to translate complex workflows into automation
  • Excellent communication and collaboration skills across engineering and operations teams

Similar jobs

Security Engineer

MetaBellevue, WA· 3 wk ago
Information Technology$271k–$347k/yrapply on metacareers.com

Security Engineer

ArmadaKirkland, WA· 1 mo ago
Information Technology$131k/yrapply on grnh.se

Security Engineer

ArmadaBellevue, WA· 1 mo ago
Information Technology$131k/yrapply on grnh.se

Security Engineer

Check Point SoftwareDes Moines, IA· 1 mo ago
Information Technologyapply on careers.checkpoint.com

Security Engineer

ClaySan Francisco, CA· 4 mo ago
Information Technologyapply on clay.com

Security Engineer

ether.fiNew York, NY· 4 mo ago
Information Technologyapply on jobs.ashbyhq.com