×
Register Here to Apply for Jobs or Post Jobs. X

Security Automation Engineer

Job in Ridley Park, Delaware County, Pennsylvania, 19078, USA
Listing for: TransUnion
Full Time position
Listed on 2026-09-03
Job specializations:
  • Software Development
    AI Engineer (Applied/Software), Backend Developer, DevOps
Job Description & How to Apply Below

Advisor, Cybersecurity

The SOAR Development team designs and delivers automation capabilities that strengthen Security Operations Center response and reduce manual effort for security analysts. The team works across security operations, detection engineering, and supporting technology teams to build scalable, AI-driven security solutions within a global and distributed environment. This role reports to Information Security Engineering Manager. This is a hybrid position and involves regular performance of job responsibilities virtually as well as in-person at an assigned TU office location for a minimum of two days a week.

Role Overview and Core Responsibilities

  • Lead the design, development, and maintenance of security response automations on the agentic AI SOC platform, including the migration of existing Splunk SOAR playbooks.
  • Build agentic workflows from end to end, including prompt and agent design, tool integration, guardrails, output evaluation, and human-in-the-loop review for AI-driven triage and response.
  • Develop and maintain integrations across SIEM, EDR, threat intelligence, case management, and ITSM platforms using REST APIs, webhooks, and event-driven patterns.
  • Build internal tools, services, and APIs primarily in Python to expand platform capabilities and reduce repetitive work for security analysts.
  • Administer and improve the case management platform and its supporting workflows.
  • Partner with detection engineering teams to convert new security detections into automated response workflows.
  • Contribute to shared engineering standards through Git-based development, code reviews, automated testing, and CI/CD practices.
  • Measure the effectiveness of automation through throughput, mean time to respond or remediate, false-positive burden, and analyst time saved.
  • Create clear technical documentation and runbooks while collaborating across a global, distributed team.

Required Knowledge and Experiences

  • 10+ years of experience in security engineering, security automation, or software engineering with a strong cybersecurity focus.
  • Hands-on experience with SOAR or security automation platforms such as Splunk SOAR, Cortex XSOAR, Tines, Torq, or similar technologies.
  • Experience building solutions with modern Large Language Model platforms such as Anthropic Claude, OpenAI, Amazon Bedrock, or similar platforms, including agent design, prompt design, tool-use patterns, and model-output evaluation.
  • Working knowledge of Security Operations Center operations, incident response workflows, and the MITRE ATT&CK framework.
  • Strong software engineering fundamentals, documentation practices, written communication skills, and experience working effectively within a distributed global team.

Required Technical Skills

  • Strong production-level Python development experience.
  • Experience developing and integrating REST APIs, JSON-based services, webhooks, and event-driven solutions.
  • Knowledge of authentication and secure integration patterns, including OAuth, API keys, and secrets management.
  • Experience with Git-based development, code review, automated testing, and Continuous Integration and Continuous Delivery practices.
  • Hands-on experience using APIs, Software Development Kits, and tool-use patterns to build LLM-powered tools, integrations, workflows, or agents.

We're also looking for the preferred skills below. Whether you are proficient or could use some brushing up, we're happy to support your career development and growth in:

  • Experience building autonomous or semi-autonomous agent systems or working with agentic AI security platforms in production.
  • Experience with LLM fine-tuning, systematic evaluations, safety testing, or red-teaming.
  • Exposure to Splunk Enterprise Security, Search Processing Language, detection logic, or detection-as-code practices.
  • Experience with Service Now or similar case management and ITSM platforms, along with web-service frameworks such as FastAPI or Flask.
  • Knowledge of AWS, Docker, Kubernetes, Terraform, Dev Ops practices, front-end development, or experience mentoring engineers and leading technical work streams.

Benefits that support every part of your life:

At Trans Union, we design benefits to help you feel…

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary