SOAR and AI Engineer - Managed Security
π’ Thinkahead Β· all Thinkahead jobs
π Remote Β· North America
π° $120,000 - $160,000 / year
π
Posted 2026-08-08 Β· via RemoteIO
π· Artificial Intelligence,Security,SOAR Engineering,Automation,Incident Response
Apply on original site βPosition Overview
This is a technical hands-on position that requires someone with a strong understanding of the needs of a 24/7 SOC (Security Operations Center). We are looking for a candidate with deep experience in security operations, SOAR engineering, scripting, systems integration, and applied AI who will work closely with the Managed Security staff and other highly technical members across multiple teams, both within AHEAD and in client environments, to continuously improve and enhance AHEADβs automation-first Managed Security capabilities.
Incumbents will possess strong technical and analytical skills while providing accurate analysis of security-related problems. They will have a well-rounded networking and security background and will be responsible for automating operational workflows, improving analyst efficiency, reducing mean time to respond, and helping teams troubleshoot complex client issues. This individual is client- and user-focused and works to resolve needs in a timely manner. These needs may involve automating repetitive analyst tasks, orchestrating security response actions, improving enrichment and triage workflows, integrating security tools, and using AI to improve the speed and quality of security operations.
The SOAR and AI Engineer is responsible for the day-to-day management and evolution of the automation platforms used by the Managed Security Team to monitor client environments and support security investigations and response. This includes workflow design and development, tool integrations, case enrichment, automated triage, alert-to-case orchestration, playbook creation and tuning, chatbot or analyst-assist workflows, and continuous optimization of automation performance and reliability. The SOAR and AI Engineer is expected to be familiar with a wide range of security tools and understand core security operations fundamentals.
Roles and Responsibilities
- Design, develop, and maintain security automation workflows within the SOAR platform, with a strong emphasis on scalable, reliable, and auditable automation.
- Build and maintain automated playbooks for alert triage, enrichment, containment, escalation, evidence gathering, and case management.
- Partner with SOC analysts, SIEM engineers, threat detection engineers, and incident responders to identify repeatable processes and convert them into high-value automation workflows.
- Design and implement integrations between SOAR, SIEM, ticketing systems, collaboration tools, endpoint tools, identity platforms, firewalls, threat intelligence sources, and cloud security platforms.
- Develop automation that improves incident handling speed, consistency, and quality across the Managed Security service.
- AI and machine learning capabilities where appropriate to improve analyst efficiency, alert summarization, triage recommendations, investigation support, knowledge retrieval, workflow decisioning, and operational reporting.
- Evaluate, test, and operationalize AI-assisted security use cases in a secure, measurable, and supportable manner.
- Establish guardrails, quality controls, and validation methods for AI-enabled workflows to ensure output accuracy, consistency, security, and auditability.
- Partner with AHEAD Managed Security SIEM and SOAR resources to improve alert-to-action workflows and strengthen end-to-end detection and response processes.
- Engage with client security and IT infrastructure teams for integration and onboarding activities related to automation, orchestration, and response enablement.
- Create tooling and scripts in Python or similar languages to automate operational tasks, support integrations, normalize data, and improve platform functionality.
- Monitor and manage the health, performance, and reliability of automation platforms and workflows used by the Managed Security Team.
- Perform workflow tuning, exception handling, and optimization to reduce false starts, improve success rates, and minimize unnecessary analyst t