About this SOAR and AI Engineer - Managed Security role at Thinkahead
Position Overview
Incumbents will possess strong technical and analytical skills while providing accurate analysis of security-related problems. They will have a well-rounded networking and security background and will be responsible for automating operational workflows, improving analyst efficiency, reducing mean time to respond, and helping teams troubleshoot complex client issues. This individual is client- and user-focused and works to resolve needs in a timely manner. These needs may involve automating repetitive analyst tasks, orchestrating security response actions, improving enrichment and triage workflows, integrating security tools, and applying AI to improve the speed and quality of security operations.
The SOAR and AI Engineer is responsible for the day-to-day management and evolution of the automation platforms used by the Managed Security Team to monitor client environments and support security investigations and response. This includes workflow design and development, tool integrations, case enrichment, automated triage, alert-to-case orchestration, playbook creation and tuning, chatbot or analyst-assist workflows, and continuous optimization of automation performance and reliability. The SOAR and AI Engineer is expected to be familiar with a wide range of security tools and understand core security operations fundamentals.
Roles and Responsibilities
Build and maintain automated playbooks for alert triage, enrichment, containment, escalation, evidence gathering, and case management
Partner with SOC analysts, SIEM engineers, threat detection engineers, and incident responders to identify repeatable processes and convert them into high-value automation workflows
Design and implement integrations between SOAR, SIEM, ticketing systems, collaboration tools, endpoint tools, identity platforms, firewalls, threat intelligence sources, and cloud security platforms
Develop automation that improves incident handling speed, consistency, and quality across the Managed Security service
Apply AI and machine learning capabilities where appropriate to improve analyst efficiency, alert summarization, triage recommendations, investigation support, knowledge retrieval, workflow decisioning, and operational reporting
Evaluate, test, and operationalize AI-assisted security use cases in a secure, measurable, and supportable manner
Establish guardrails, quality controls, and validation methods for AI-enabled workflows to ensure output accuracy, consistency, security, and auditability
Partner with AHEAD Managed Security SIEM and SOAR resources to improve alert-to-action workflows and strengthen end-to-end detection and response processes
Engage with client security and IT infrastructure teams for integration and onboarding activities related to automation, orchestration, and response enablement
Create tooling and scripts in Python or similar languages to automate operational tasks, support integrations, normalize data, and improve platform functionality
Monitor and manage the health, performance, and reliability of automation platforms and workflows used by the Managed Security Team
Perform workflow tuning, exception handling, and optimization to reduce false starts, improve success rates, and minimize unnecessary analyst touchpoints
Build and maintain dashboards, reports, and metrics related to automation adoption, workflow effectiveness, case throughput, response time improvements, and platform health
Assist with the development of processes and procedures to improve incident response times, analysis quality, automation maturity, and overall Managed Security functions
Participate in client-facing security meetings to review automation capabilities, implementation progress, service improvements, and operational outcomes
Contribute to the roadmap for automation and AI within Managed Security, including identification of use cases, platform enhancements, and process standardization
Position Requirements
Strong experience with security automation, orchestration, and systems integration in enterprise or managed security environments
Experience writing tools to automate tasks and integrate systems in Python or other languages
Experience working with APIs, webhooks, JSON, authentication methods, and event-driven integrations
Experience with SIEM platforms and common security operations workflows, with the ability to translate analyst needs into automation opportunities
Familiarity with AI-assisted operations, LLM-enabled workflow patterns, or practical uses of AI in security operations and automation
The ability to think creatively to find elegant solutions to complex problems
Excellent verbal and written communication skills
Incident handling and response experience
The desire to work both independently and collaboratively with a larger team
A willingness to be challenged along with a strong appetite for learning
2–4 years of experience in Information Security, Incident Response, SOAR engineering, security automation, detection engineering, or related disciplines
Hands-on experience with common security technologies such as IDS, Firewall, SIEM, SOAR, EDR, IAM, email security, and cloud security tools
Knowledge of common security analysis tools and techniques
Understanding of common security threats, attack vectors, vulnerabilities, and exploits
Knowledge of regular expressions and data transformation concepts
Customer service focused and portrays energy, professionalism, and welcoming characteristics
Strong ability to work in a highly sensitive and confidential environment
Ability to meet deadlines and handle sensitive and pressured situations
Ability to identify issues and help develop strategy and tactical plans for various department initiatives
Ability to use good judgment and decision-making skills
Preferred Qualifications
Experience building analyst-assist workflows, case summarization, or AI-powered enrichment pipelines
Familiarity with cloud environments such as AWS, Azure, or GCP and their native security tooling
Experience integrating ServiceNow, collaboration tooling, and case management systems into security operations workflows
Understanding of governance and risk considerations for production AI usage in security operations
Education
One or more of the following certifications preferred: CISSP, GCIH, GCIA, GMON, GPYC, relevant SOAR certifications, cloud security certifications, or security automation-related credentials