Security Automation Engineer

Philadelphia, PAFull-timePosted Aug 5, 2026

Chubb Global Information Security is looking for a hands-on Security Automation Engineer to build, own, and maintain the security automation platform that powers day-to-day detection-to-response workflows for our SOC. This role is responsible for our SOAR platform, including Python-based automation, custom API integrations, and the case and incident management tooling analysts rely on every day. The ideal candidate can turn a manual, repetitive analyst task into a reliable, documented automation, and is comfortable using modern AI tooling (Claude/Claude Code or similar) as part of daily engineering work to build and extend that automation faster.

Responsibilities:

  • Design, build, and maintain SOAR playbooks and Python-based automations that integrate with EDR, SIEM, ticketing, identity, network, and threat intel tools
  • Own and evolve our case and incident management application, including analyst-facing workflows and JavaScript-based UI widgets
  • Build and maintain custom API integrations, including non-standard auth schemes (e.g., HMAC request signing), pagination, and high-volume or rate-limited data sources
  • Partner with SOC analysts and incident responders to identify manual, repetitive tasks and automate them end-to-end, from alert ingestion through case closure
  • Build and extend AI-assisted automation (Claude/Claude Code or similar) to accelerate triage, enrichment, and response
  • Troubleshoot, monitor, and maintain existing automations and integrations, ensuring reliability as underlying tools and APIs change
  • Document automation logic, connector configurations, and playbook behavior to support team continuity and knowledge transfer
  • Translate manual security runbooks into automated, auditable workflows
  • Evaluate new security tools and data sources for integration feasibility and automation potential

  • 3-5 years of IT/security engineering experience, including hands-on scripting or automation work
  • Strong Python scripting ability, with experience building and debugging integrations against third-party REST APIs
  • Working knowledge of JavaScript for building or maintaining web-based UI components
  • Experience integrating disparate security tools (SIEM, EDR, ticketing/ITSM, email security, threat intel, or similar) via API
  • Comfortable using AI coding/analysis tools (Claude Code or similar) to build and maintain automation
  • Strong troubleshooting and debugging skills across multi-system workflows
  • Excellent communication skills - able to translate analyst and IR pain points into automated solutions
  • Solid documentation habits for technical automation logic and integration configurations
  • Strong time management and organizational skills

Preferred Qualifications:

  • Hands-on experience with a SOAR platform (Splunk SOAR/Phantom, Palo Alto XSOAR, Tines, or similar)
  • Experience with case or incident management application design and configuration
  • Exposure to agentic AI frameworks (e.g., LangGraph) for building AI-assisted security workflows
  • Familiarity with Microsoft Sentinel/KQL or another SIEM
  • Security certifications such as Security+, GCIH, or similar

  • Experience with enterprise security/infrastructure APIs (e.g., Microsoft Graph, Akamai EdgeGrid)

Want jobs like this matched to you?

SimpleCareer scores fresh postings against your résumé so you only see the matches that matter.

Get started free