
Security Automation Engineer
3 days ago
Job Description
The Cyber Defense AI & Automation team are seeking Security Automation Engineer to design and deliver enterprise-scale automation that reduces manual workload, suppresses noise, and accelerates cyber defense outcomes. This role is responsible for building secure, auditable, and guardrail-enforced automation workflows that operate across the full spectrum of enterprise control-plane platforms (identity, endpoint, cloud, network, and data) with Microsoft Defender, Sentinel, ADX, and Logic Apps as the core orchestration fabric, and extensions into ServiceNow Flow Designer where enterprise workflow integration is required.
As part of the Cyber Defense AI & Automation team, you will work alongside AI Security Engineers, data scientists, and platform engineers to transform detections and telemetry into structured workflows that take safe automated action. Your work will directly enable faster containment, measurable noise reduction, and reusable automation frameworks that scale across domains.
Responsibilities
- Design and build automation workflows using Microsoft Logic Apps, Python services, and REST APIs.
- Integrate with enterprise platforms (IAM, endpoint, cloud, network, data) via APIs to execute secure, guardrail-enforced actions.
- Extend automation into ServiceNow Flow Designer where ticketing or enterprise workflow integration is needed.
- Operationalize AI outputs: consume AI-generated case packages (JSON) and translate them into safe enforcement workflows.
- Implement safety controls: kill switches, dry-run/test modes, time-limited actions, and staged rollouts (dev → UAT → prod).
- Deliver automation outputs into enterprise workflow and communication channels (Teams, ServiceNow, email, dashboards).
- Automate enrichment: pull asset ownership, user identity, threat intel, and prevalence context into workflows.
- Ensure observability: log all automated actions into ADX with correlation IDs for audit, dashboards, and feedback loops.
- Partner with domain owners to align automated actions with policies while maintaining independence of the automation fabric.
- Continuously improve frameworks by creating reusable templates, connectors, and patterns that scale across multiple platforms.
Qualifications (Required)
- Bachelor's degree in Computer Science, Cybersecurity, Engineering, or related technical field.
- 3+ years in security engineering with demonstrated experience delivering production automation.
- Hands-on experience with Microsoft Defender XDR, Sentinel, ADX, and Logic Apps.
- Strong programming or scripting in Python or PowerShell, applied to security engineering use cases.
- Strong knowledge of cyber defense workflows (alerting, enrichment, suppression, containment).
- Ability to design automation that is safe, explainable, and auditable.
- Ready to contribute on day one with minimal ramp-up.
Preferred
- Experience integrating automation across IAM, endpoint, cloud, network, and data platforms via APIs.
- Familiarity with KQL for Sentinel/ADX-driven triggers.
- Experience using ServiceNow Flow Designer to extend automation into enterprise workflows.
- Knowledge of automation safety models (rollback, TTL, staged enforcement).
- Exposure to AI-assisted workflows where automation consumes reasoning outputs.
- Strong written and verbal communication to document workflows and explain outcomes.
What Success Looks Like
- Deployment of scalable, production-grade automations that measurably reduce analyst workload and ticket volume.
- Trusted integration of AI outputs into workflows that analysts and leadership can rely on.
- Delivery of auditable, guardrail-enforced automations that are transparent, explainable, and reversible.
- Establishment of reusable automation frameworks that extend across identity, endpoint, cloud, network, and data.
- Increased enterprise confidence in automation through clear logging, dashboards, and observability.
Current Employees apply HERE
Current Contingent Workers apply HERE
Search Firm Representatives Please Read Carefully
Merck & Co., Inc., Rahway, NJ, USA, also known as Merck Sharp & Dohme LLC, Rahway, NJ, USA, does not accept unsolicited assistance from search firms for employment opportunities. All CVs / resumes submitted by search firms to any employee at our company without a valid written search agreement in place for this position will be deemed the sole property of our company. No fee will be paid in the event a candidate is hired by our company as a result of an agency referral where no pre-existing agreement is in place. Where agency agreements are in place, introductions are position specific. Please, no phone calls or emails.
Employee Status:
RegularRelocation:
No relocationVISA Sponsorship:
NoTravel Requirements:
No Travel RequiredFlexible Work Arrangements:
HybridShift:
Not IndicatedValid Driving License:
NoHazardous Material(s):
n/aRequired Skills:
Application Security, Automation, Cybersecurity Analytics, Cybersecurity Operations, Delivery of Security Applications, Information SecurityPreferred Skills:
Job Posting End Date:
10/17/2025*A job posting is effective until 11:59:59PM on the day BEFORE the listed job posting end date. Please ensure you apply to a job posting no later than the day BEFORE the job posting end date.
Requisition ID:R364497
-
Application Security Engineer
2 weeks ago
Bucharest, Bucureşti, Romania Nord Security Full time €80,000 - €120,000 per yearThe world's most advanced VPN, and a whole lot more. If you're a curious problem-solver who carves their own path, join the team behind Threat Protection Pro, the NordLynx protocol, and the fastest VPN on the planet—tools that put privacy, security, and control back in people's hands.Your impact? Helping millions take back control of their online...
-
Security Automation Engineer
1 day ago
Bucharest, Bucureşti, Romania MSD Romania Full time €40,000 - €80,000 per yearJob DescriptionThe Cyber Defense AI & Automation team are seeking Security Automation Engineer to design and deliver enterprise-scale automation that reduces manual workload, suppresses noise, and accelerates cyber defense outcomes. This role is responsible for building secure, auditable, and guardrail-enforced automation workflows that operate across the...
-
Security Automation Engineer
1 day ago
Bucharest, Bucureşti, Romania MSD Full time 40,000 - 80,000 per yearJob DescriptionThe Cyber Defense AI & Automation team are seeking Security Automation Engineer to design and deliver enterprise-scale automation that reduces manual workload, suppresses noise, and accelerates cyber defense outcomes. This role is responsible for building secure, auditable, and guardrail-enforced automation workflows that operate across the...
-
Network & Security Automation Engineer
1 week ago
Bucharest, Bucureşti, Romania ENGIE Full time €45,000 - €55,000 per yearNetwork & Security Automation ENGINEERBUCHARESTENGIE GBSOne of the world's leading energy companies, ENGIE is present across the entire energy chain, in electricity and natural gas, from upstream to downstream. By placing responsible growth at the heart of its businesses (energy, energy services and the environment), its mission is to meet major challenges:...
-
Network & Security Automation Engineer
1 week ago
Bucharest, Bucureşti, Romania ENGIE Digital & IT Full time €70,000 - €120,000 per yearNetwork & Security Automation ENGINEERBUCHARESTENGIE GBSOne of the world's leading energy companies, ENGIE is present across the entire energy chain, in electricity and natural gas, from upstream to downstream. By placing responsible growth at the heart of its businesses (energy, energy services and the environment), its mission is to meet major challenges:...
-
Security Operations Engineer
2 weeks ago
Bucharest, Bucureşti, Romania Aera Technology Full time €60,000 - €100,000 per yearAera Technology is a pioneer in the growing category of Decision Intelligence – the technology to digitize, augment, and automate decision-making processes with AI and machine learning. Through our AI decision automation platform, Aera Decision Cloud, we are helping the best-known brands in the world make smarter, faster decisions.Privately-held and...
-
Automation Engineer
2 weeks ago
Bucharest, Bucureşti, Romania CrowdStrike Full time €90,000 - €120,000 per yearAs a global leader in cybersecurity, CrowdStrike protects the people, processes and technologies that drive modern organizations. Since 2011, our mission hasn't changed — we're here to stop breaches, and we've redefined modern security with the world's most advanced AI-native platform. We work on large scale distributed systems, processing almost 3...
-
Security Software Engineer
2 weeks ago
Bucharest, Bucureşti, Romania Electronic Arts (EA) Full time €60,000 - €80,000 per yearDescription & RequirementsElectronic Arts creates next-level entertainment experiences that inspire players and fans around the world. Here, everyone is part of the story. Part of a community that connects across the globe. A place where creativity thrives, new perspectives are invited, and ideas matter. A team where everyone makes play happen.We're looking...
-
Technical Account Manager II
2 weeks ago
Bucharest, Bucureşti, Romania Flow Automation Full time €60,000 - €80,000 per yearContract-based role via Flow Automations – Remote or HybridHow would you like to help the world's largest companies transform the way they work via automation, allowing their team members to achieve their full potential? As part of our collaboration with UiPath and its enterprise clients, Flow Automations is hiring Technical Account Managers to support...
-
Security Engineer, Observability
7 days ago
Bucharest, Bucureşti, Romania CrowdStrike Full time €104,000 - €130,878 per yearAs a global leader in cybersecurity, CrowdStrike protects the people, processes and technologies that drive modern organizations. Since 2011, our mission hasn't changed — we're here to stop breaches, and we've redefined modern security with the world's most advanced AI-native platform. Our customers span all industries, and they count on CrowdStrike to...