Track This Job
Add this job to your tracking list to:
- Monitor application status and updates
- Change status (Applied, Interview, Offer, etc.)
- Add personal notes and comments
- Set reminders for follow-ups
- Track your entire application journey
Save This Job
Add this job to your saved collection to:
- Access easily from your saved jobs dashboard
- Review job details later without searching again
- Compare with other saved opportunities
- Keep a collection of interesting positions
- Receive notifications about saved jobs before they expire
AI-Powered Job Summary
Get a concise overview of key job requirements, responsibilities, and qualifications in seconds.
Pro Tip: Use this feature to quickly decide if a job matches your skills before reading the full description.
The Cyber Defense AI & Automation team are seeking Security Automation Engineer to design and deliver enterprise-scale automation that reduces manual workload, suppresses noise, and accelerates cyber defense outcomes. This role is responsible for building secure, auditable, and guardrail-enforced automation workflows that operate across the full spectrum of enterprise control-plane platforms (identity, endpoint, cloud, network, and data) with Microsoft Defender, Sentinel, ADX, and Logic Apps as the core orchestration fabric, and extensions into ServiceNow Flow Designer where enterprise workflow integration is required.
As part of the Cyber Defense AI & Automation team, you will work alongside AI Security Engineers, data scientists, and platform engineers to transform detections and telemetry into structured workflows that take safe automated action. Your work will directly enable faster containment, measurable noise reduction, and reusable automation frameworks that scale across domains.
Responsibilities
- Design and build automation workflows using Microsoft Logic Apps, Python services, and REST APIs.
- Integrate with enterprise platforms (IAM, endpoint, cloud, network, data) via APIs to execute secure, guardrail-enforced actions.
- Extend automation into ServiceNow Flow Designer where ticketing or enterprise workflow integration is needed.
- Operationalize AI outputs: consume AI-generated case packages (JSON) and translate them into safe enforcement workflows.
- Implement safety controls: kill switches, dry-run/test modes, time-limited actions, and staged rollouts (dev → UAT → prod).
- Deliver automation outputs into enterprise workflow and communication channels (Teams, ServiceNow, email, dashboards).
- Automate enrichment: pull asset ownership, user identity, threat intel, and prevalence context into workflows.
- Ensure observability: log all automated actions into ADX with correlation IDs for audit, dashboards, and feedback loops.
- Partner with domain owners to align automated actions with policies while maintaining independence of the automation fabric.
- Continuously improve frameworks by creating reusable templates, connectors, and patterns that scale across multiple platforms.
Qualifications (Required)
- Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or related technical field.
- 3+ years in security engineering with demonstrated experience delivering production automation.
- Hands-on experience with Microsoft Defender XDR, Sentinel, ADX, and Logic Apps.
- Strong programming or scripting in Python or PowerShell, applied to security engineering use cases.
- Strong knowledge of cyber defense workflows (alerting, enrichment, suppression, containment).
- Ability to design automation that is safe, explainable, and auditable.
- Ready to contribute on day one with minimal ramp-up.
Preferred
- Experience integrating automation across IAM, endpoint, cloud, network, and data platforms via APIs.
- Familiarity with KQL for Sentinel/ADX-driven triggers.
- Experience using ServiceNow Flow Designer to extend automation into enterprise workflows.
- Knowledge of automation safety models (rollback, TTL, staged enforcement).
- Exposure to AI-assisted workflows where automation consumes reasoning outputs.
- Strong written and verbal communication to document workflows and explain outcomes.
What Success Looks Like
- Deployment of scalable, production-grade automations that measurably reduce analyst workload and ticket volume.
- Trusted integration of AI outputs into workflows that analysts and leadership can rely on.
- Delivery of auditable, guardrail-enforced automations that are transparent, explainable, and reversible.
- Establishment of reusable automation frameworks that extend across identity, endpoint, cloud, network, and data.
- Increased enterprise confidence in automation through clear logging, dashboards, and observability.
Key Skills
Ranked by relevanceReady to apply?
Join MSD and take your career to the next level!
Application takes less than 5 minutes