Security Automation Engineer
Chubb Global Information Security is looking for a hands-on Security Automation Engineer to build, own, and maintain the security automation platform that powers day-to-day detection-to-response workflows for our SOC. This role is responsible for our SOAR platform, including Python-based automation, custom API integrations, and the case and incident management tooling analysts rely on every day. The ideal candidate can turn a manual, repetitive analyst task into a reliable, documented automation, and is comfortable using modern AI tooling (Claude/Claude Code or similar) as part of daily engineering work to build and extend that automation faster.
Responsibilities:
- Design, build, and maintain SOAR playbooks and Python-based automations that integrate with EDR, SIEM, ticketing, identity, network, and threat intel tools
- Own and evolve our case and incident management application, including analyst-facing workflows and JavaScript-based UI widgets
- Build and maintain custom API integrations, including non-standard auth schemes (e.g., HMAC request signing), pagination, and high-volume or rate-limited data sources
- Partner with SOC analysts and incident responders to identify manual, repetitive tasks and automate them end-to-end, from alert ingestion through case closure
- Build and extend AI-assisted automation (Claude/Claude Code or similar) to accelerate triage, enrichment, and response
- Troubleshoot, monitor, and maintain existing automations and integrations, ensuring reliability as underlying tools and APIs change
- Document automation logic, connector configurations, and playbook behavior to support team continuity and knowledge transfer
- Translate manual security runbooks into automated, auditable workflows
Evaluate new security tools and data sources for integration feasibility and automation potential
- 3-5 years of IT/security engineering experience, including hands-on scripting or automation work
- Strong Python scripting ability, with experience building and debugging integrations against third-party REST APIs
- Working knowledge of JavaScript for building or maintaining web-based UI components
- Experience integrating disparate security tools (SIEM, EDR, ticketing/ITSM, email security, threat intel, or similar) via API
- Comfortable using AI coding/analysis tools (Claude Code or similar) to build and maintain automation
- Strong troubleshooting and debugging skills across multi-system workflows
- Excellent communication skills - able to translate analyst and IR pain points into automated solutions
- Solid documentation habits for technical automation logic and integration configurations
- Strong time management and organizational skills
Preferred Qualifications:
- Hands-on experience with a SOAR platform (Splunk SOAR/Phantom, Palo Alto XSOAR, Tines, or similar)
- Experience with case or incident management application design and configuration
- Exposure to agentic AI frameworks (e.g., LangGraph) for building AI-assisted security workflows
- Familiarity with Microsoft Sentinel/KQL or another SIEM
Security certifications such as Security+, GCIH, or similar
Experience with enterprise security/infrastructure APIs (e.g., Microsoft Graph, Akamai EdgeGrid)