Sr. Automation & Cybersecurity Engineer
About the role
TTS-US is a Toyota group company founded in 2011 that develops IT solutions globally. Transforming into a technology and mobility company, TTS-US aims to secure and strengthen its global value chain. The Senior Automation & Cybersecurity Engineer plays a crucial role in designing, building, and scaling automation for the Security Operations Center (SOC).
Responsibilities
Design, build, and maintain automation for alert enrichment, correlation, triage, incident response, and case handoffs across SIEM/SOAR platforms such as Microsoft Sentinel, Defender/XDR, Azure Logic Apps, Tines, ServiceNow, Log Analytics, and Confluence.
Develop integrations and tooling using Python, PowerShell, APIs, and cloud-native services, with production-quality error handling, monitoring, documentation, and reuse.
Collaborate with detection engineers, incident responders, and SOC analysts to identify automation opportunities, improve detection workflows, reduce false positives, and streamline analyst operations.
Design AI-assisted and agentic workflows for enrichment, investigation, summarization, and decision support, ensuring human-in-the-loop approvals, auditability, and measurable quality controls.
Partner with security, infrastructure, platform, compliance, and risk teams; participate in code/design reviews; mentor others; and help establish reusable automation standards and patterns.
Evaluate and implement emerging technologies, including AI capabilities, to enhance security operations while maintaining human oversight.
Requirements
6-9 years of cybersecurity engineering experience, including 3-4 years focused on security automation, SOC engineering, SIEM/SOAR development, or similar work.
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field (preferred).
Strong proficiency with Python, PowerShell, APIs, cloud automation, and production-grade integration patterns.
Hands-on experience with enterprise SIEM/SOAR platforms, Microsoft Sentinel preferred, and working knowledge of Microsoft Defender/XDR, Azure Logic Apps, or similar technologies.
Solid understanding of threat detection, logging pipelines, alert tuning, incident response workflows, and operational metrics.
Excellent problem-solving, documentation, communication, and collaboration skills, with a track record of delivering reliable automation in production.
Preferred Qualifications
Experience with Tines for SOC automation and agentic workflow orchestration.
Experience building an Agentic SOC using LLM/AI agents for enrichment, investigation, triage, response, and feedback-driven evaluation.
Hands-on experience with detection-as-code, CI/CD, MITRE ATT&CK, ASIM schemas, Sigma rules, behavioral detections, or observability pipelines.
Experience with LLMs, intelligent agents, AI/ML-assisted security tooling, prompt design, or agent evaluation.
Relevant certifications such as Microsoft Cybersecurity Architect, GIAC Security Automation, or Azure Security Engineer Associate.