InfoSec - Senior Response Automation Engineer
Listed on 2026-03-01
-
IT/Tech
Cybersecurity, Systems Engineer, AI Engineer
Overview
Elastic, the Search AI Company, enables everyone to find the answers they need in real time, using all their data, at scale - unleashing the potential of businesses and people. The Elastic Search AI Platform, used by more than 50% of the Fortune 500, brings together the precision of search and the intelligence of AI to enable everyone to accelerate the results that matter.
By taking advantage of all structured and unstructured data - securing and protecting private information more effectively - Elastic's complete, cloud-based solutions for search, security, and observability help organizations deliver on the promise of AI.
The Role
As a Senior Response Automation Engineer at Elastic you will work to enhance and maintain the workflows supporting Elastic front-line defenders, assisting the team delivering safe and secure products and services to our customers, users, and fellow Elasticians. Currently, the Threat Detection and Response Team heavily relies on automation - we have developed many integrations and intelligent workflows to provide alert context, take action automatically, and more.
This has resulted in significant time savings and efficiencies.
Our ability to continue to enhance existing workflows and develop new ones to take us to the next level in our SOC-less journey. In this role, you will be responsible for understanding, maintaining, and improving threat detection and response processes, working on automations that support alert triage through management of response cases. If doing all of this with the Elastic Stack excites you, then we'd love to meet you!
WhatYou Will Be Doing
- Drive the full lifecycle of automation development, from design to maintenance, to significantly advance our threat detection and response capabilities.
- Optimize and automate core SOC/IR analyst workflows, focusing on delivering rich alert context and efficient triage processes across all detection sources, including the Elastic Detection Engine.
- Establish automated feedback mechanisms that empower the Threat Detection team to continuously refine detections, identify false positives, and uncover new enrichment and automation opportunities.
- Build and manage integrations across security tools and platforms to create seamless workflows and enhance data correlation for comprehensive threat detection and response.
- Architect and implement automated incident response playbooks for effective containment, eradication, and recovery in various threat scenarios.
- Serve as a key automation expert, partnering with security analysts and incident responders to transform manual security operations into highly efficient, automated processes.
- Innovate and document best practices for detecting, responding to, and eradicating advanced threats, focusing on reducing overall time to response.
- Ensure the integrity and effectiveness of all workflows through rigorous testing and validation.
- Collaborate strategically with Threat Detection and Response leadership to identify critical areas for enhancement and execute impactful improvement initiatives.
- At least 3 years of experience related to automation engineering in a complex, global environment. Automation experience focused on security operations / incident response is a plus.
- Experience with automating with Security Operations and Response (SOAR) tools or alternative tools supporting similar workflows. Tines experience is a plus.
- Demonstrated ability to take complex / manual processes and solve them through automation. If you've done this with the help of the Elastic Stack, even better!
- Demonstrated ability to think innovatively about solving critical security problems.
- Strong communication skills, with the ability to make sound decisions with limited information, and embrace challenging the status quo.
- Are eligible to work in DoD Impact Level 4 or above cloud service environments
As a distributed company, diversity drives our identity. Whether you're looking to launch a new career or grow an existing one, Elastic is the type of company where you can balance great work with great life. Your age is only a number.…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).