Security Automation & AI Engineer
On-siteBarcelona, Catalonia, Spain
Job Summary
Design and maintain automated workflows, SOAR playbooks, and detection-as-code pipelines to streamline alert triage, enrichment, containment, and remediation across Novanta's global security operations. Develop AI-assisted investigation tools that auto-correlate signals from SIEM, EDR, DLP, and IAM platforms to accelerate incident response and vulnerability management. Serve as the security team's subject matter expert on R&D CI/CD pipelines, embedding automated security checks into development lifecycles to shift security left. Build API-level integrations between security tools and collaborate cross-functionally with IT, R&D Engineering, Cloud, and DevOps teams to align automation initiatives with broader technology strategies.
Required Qualifications
- Bachelor's degree in Computer Science, Cybersecurity, Software Engineering, or a related field (or equivalent practical experience)
- 3–5 years of experience in security operations, security engineering, or DevSecOps, with a demonstrated focus on automation and tooling development
- Strong proficiency in Python
- experience with PowerShell, Bash, or other scripting languages
- Ability to write production-quality, maintainable code
- Hands-on experience with CI/CD platforms (e.g., GitHub Actions, Azure DevOps Pipelines, Jenkins) and version control systems (Git)
- Understanding of software development lifecycle and DevOps practices
- Experience with SIEM platforms, EDR solutions, and/or SOAR platforms
- Working knowledge of cloud platforms (AWS, Azure, or GCP) and infrastructure-as-code concepts
- Strong experience building and consuming RESTful APIs for tool integration and data orchestration
- Familiarity with AI/ML concepts and their practical application in cybersecurity (e.g., anomaly detection, automated classification, LLM-based workflows)
- Understanding of security frameworks such as NIST, MITRE ATT&CK, and CIS
- Knowledge of GDPR and its impact on security across a global company
Desired Qualifications
- Relevant certifications such as GIAC (GCSA, GMON), PCSAE (Palo Alto Certified Security Automation Engineer), AWS Security Specialty, or equivalent
- Familiarity with DLP and IAM tools
- Experience with AI frameworks or platforms
- Can effectively cope with change; can shift gears comfortably; can decide and act without having the total picture; comfortable handling risk and uncertainty in fast-paced security environments
- Approaches problems systematically; breaks down complex workflows into automatable components; uses data to drive decisions and measure the effectiveness of automation
- Delivers innovative automation solutions that improve security outcomes for internal stakeholders
- Seeks feedback from SOC analysts, threat hunters, and engineers to optimise workflows
- Has the functional and technical knowledge and skills to design, build, and maintain production-grade security automation at a high level of accomplishment
- Works effectively across global, cross-functional teams
- Can translate complex automation concepts into clear language for technical and non-technical audiences alike
- Can write clearly and succinctly in a variety of communication settings and styles; produces high-quality technical documentation and runbooks
- Demonstrates curiosity and a commitment to staying current with emerging security automation, AI, and DevSecOps trends and technologies
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.