Novanta logo
NovantaPosted 3 weeks ago

Security Automation & AI Engineer

On-siteBarcelona, Catalonia, Spain

Full TimeLarge

Job Summary

Design and maintain automated workflows, SOAR playbooks, and detection-as-code pipelines to streamline alert triage, enrichment, containment, and remediation across Novanta's global security operations. Develop AI-assisted investigation tools that auto-correlate signals from SIEM, EDR, DLP, and IAM platforms to accelerate incident response and vulnerability management. Serve as the security team's subject matter expert on R&D CI/CD pipelines, embedding automated security checks into development lifecycles to shift security left. Build API-level integrations between security tools and collaborate cross-functionally with IT, R&D Engineering, Cloud, and DevOps teams to align automation initiatives with broader technology strategies.

Required Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, Software Engineering, or a related field (or equivalent practical experience)
  • 3–5 years of experience in security operations, security engineering, or DevSecOps, with a demonstrated focus on automation and tooling development
  • Strong proficiency in Python
  • experience with PowerShell, Bash, or other scripting languages
  • Ability to write production-quality, maintainable code
  • Hands-on experience with CI/CD platforms (e.g., GitHub Actions, Azure DevOps Pipelines, Jenkins) and version control systems (Git)
  • Understanding of software development lifecycle and DevOps practices
  • Experience with SIEM platforms, EDR solutions, and/or SOAR platforms
  • Working knowledge of cloud platforms (AWS, Azure, or GCP) and infrastructure-as-code concepts
  • Strong experience building and consuming RESTful APIs for tool integration and data orchestration
  • Familiarity with AI/ML concepts and their practical application in cybersecurity (e.g., anomaly detection, automated classification, LLM-based workflows)
  • Understanding of security frameworks such as NIST, MITRE ATT&CK, and CIS
  • Knowledge of GDPR and its impact on security across a global company

Desired Qualifications

  • Relevant certifications such as GIAC (GCSA, GMON), PCSAE (Palo Alto Certified Security Automation Engineer), AWS Security Specialty, or equivalent
  • Familiarity with DLP and IAM tools
  • Experience with AI frameworks or platforms
  • Can effectively cope with change; can shift gears comfortably; can decide and act without having the total picture; comfortable handling risk and uncertainty in fast-paced security environments
  • Approaches problems systematically; breaks down complex workflows into automatable components; uses data to drive decisions and measure the effectiveness of automation
  • Delivers innovative automation solutions that improve security outcomes for internal stakeholders
  • Seeks feedback from SOC analysts, threat hunters, and engineers to optimise workflows
  • Has the functional and technical knowledge and skills to design, build, and maintain production-grade security automation at a high level of accomplishment
  • Works effectively across global, cross-functional teams
  • Can translate complex automation concepts into clear language for technical and non-technical audiences alike
  • Can write clearly and succinctly in a variety of communication settings and styles; produces high-quality technical documentation and runbooks
  • Demonstrates curiosity and a commitment to staying current with emerging security automation, AI, and DevSecOps trends and technologies

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce