Security Automation Engineer
1 week ago
Job Description
The Cyber Defense AI & Automation team are seeking Security Automation Engineer to design and deliver enterprise-scale automation that reduces manual workload, suppresses noise, and accelerates cyber defense outcomes. This role is responsible for building secure, auditable, and guardrail-enforced automation workflows that operate across the full spectrum of enterprise control-plane platforms (identity, endpoint, cloud, network, and data) with Microsoft Defender, Sentinel, ADX, and Logic Apps as the core orchestration fabric, and extensions into ServiceNow Flow Designer where enterprise workflow integration is required.
As part of the Cyber Defense AI & Automation team, you will work alongside AI Security Engineers, data scientists, and platform engineers to transform detections and telemetry into structured workflows that take safe automated action. Your work will directly enable faster containment, measurable noise reduction, and reusable automation frameworks that scale across domains.
Responsibilities
- Design and build automation workflows using Microsoft Logic Apps, Python services, and REST APIs.
- Integrate with enterprise platforms (IAM, endpoint, cloud, network, data) via APIs to execute secure, guardrail-enforced actions.
- Extend automation into ServiceNow Flow Designer where ticketing or enterprise workflow integration is needed.
- Operationalize AI outputs consume AI-generated case packages (JSON) and translate them into safe enforcement workflows.
- Implement safety controls kill switches, dry-run/test modes, time-limited actions, and staged rollouts (dev → UAT → prod).
- Deliver automation outputs into enterprise workflow and communication channels (Teams, ServiceNow, email, dashboards).
- Automate enrichment pull asset ownership, user identity, threat intel, and prevalence context into workflows.
- Ensure observability log all automated actions into ADX with correlation IDs for audit, dashboards, and feedback loops.
- Partner with domain owners to align automated actions with policies while maintaining independence of the automation fabric.
- Continuously improve frameworks by creating reusable templates, connectors, and patterns that scale across multiple platforms.
Qualifications (Required)
- Bachelor's degree in Computer Science, Cybersecurity, Engineering, or related technical field.
- 3+ years in security engineering with demonstrated experience delivering production automation.
- Hands-on experience with Microsoft Defender XDR, Sentinel, ADX, and Logic Apps.
- Strong programming or scripting in Python or PowerShell, applied to security engineering use cases.
- Strong knowledge of cyber defense workflows (alerting, enrichment, suppression, containment).
- Ability to design automation that is safe, explainable, and auditable.
- Ready to contribute on day one with minimal ramp-up.
Preferred
- Experience integrating automation across IAM, endpoint, cloud, network, and data platforms via APIs.
- Familiarity with KQL for Sentinel/ADX-driven triggers.
- Experience using ServiceNow Flow Designer to extend automation into enterprise workflows.
- Knowledge of automation safety models (rollback, TTL, staged enforcement).
- Exposure to AI-assisted workflows where automation consumes reasoning outputs.
- Strong written and verbal communication to document workflows and explain outcomes.
What Success Looks Like
- Deployment of scalable, production-grade automations that measurably reduce analyst workload and ticket volume.
- Trusted integration of AI outputs into workflows that analysts and leadership can rely on.
- Delivery of auditable, guardrail-enforced automations that are transparent, explainable, and reversible.
- Establishment of reusable automation frameworks that extend across identity, endpoint, cloud, network, and data.
- Increased enterprise confidence in automation through clear logging, dashboards, and observability.
Required Skills
Application Security, Automation, Cybersecurity Analytics, Cybersecurity Operations, Delivery of Security Applications, Information Security
Preferred Skills
Current Employees apply HERE
Current Contingent Workers apply HERE
Search Firm Representatives Please Read Carefully
Merck & Co., Inc., Rahway, NJ, USA, also known as Merck Sharp & Dohme LLC, Rahway, NJ, USA, does not accept unsolicited assistance from search firms for employment opportunities. All CVs / resumes submitted by search firms to any employee at our company without a valid written search agreement in place for this position will be deemed the sole property of our company. No fee will be paid in the event a candidate is hired by our company as a result of an agency referral where no pre-existing agreement is in place. Where agency agreements are in place, introductions are position specific. Please, no phone calls or emails.
Employee Status
Regular
Relocation
No relocation
VISA Sponsorship
No
Travel Requirements
No Travel Required
Flexible Work Arrangements
Hybrid
Shift
Not Indicated
Valid Driving License
No
Hazardous Material(s)
n/a
Job Posting End Date
11/1/2025
- A job posting is effective until PM on the day BEFORE the listed job posting end date. Please ensure you apply to a job posting no later than the day BEFORE the job posting end date.
Requisition ID
R364497
-
Security Engineer, Observability
1 week ago
Bucharest, Bucureşti, Romania CrowdStrike Full time 40,000 - 80,000 per yearAs a global leader in cybersecurity, CrowdStrike protects the people, processes and technologies that drive modern organizations. Since 2011, our mission hasn't changed — we're here to stop breaches, and we've redefined modern security with the world's most advanced AI-native platform. Our customers span all industries, and they count on CrowdStrike to...
-
IT Security Engineer
2 weeks ago
Bucharest, Bucureşti, Romania Rompetrol (KMG International) Full time €40,000 - €80,000 per yearJob DescriptionWe are seeking a technically skilled and detail-orientedSecurity Engineer in Bucharestto lead the implementation and ongoing management of our Mobile Device Management (MDM) platform, while gradually expanding into Data Loss Prevention (DLP) initiatives.Rompetrol,part ofKMG International,is the place where thousands of minds and over 200...
-
Information Security Engineer
2 weeks ago
Bucharest, Bucureşti, Romania Ahold Delhaize Full time 90,000 - 120,000 per yearYour new role and environment.We are looking for an experiencedInformation Security Engineerto strengthen our security posture and play a key role in both the first and second lines of defense. In this role, you will work closely with engineering, operations, and compliance teams to ensure our digital assets and data remain protected, while enabling the...
-
Reporting Automation Engineer
2 weeks ago
Bucharest, Bucureşti, Romania Decillion Digital Limited Full time 20,000 - 60,000 per yearJob Title: Reporting Automation EngineerLocation: BulgariaPosition Summary:We are seeking a skilled Reporting Automation Engineer to design and implement a web-based reporting dashboard with automated data collection and visualization capabilities. This short-term project role requires a hands-on professional experienced in frontend and backend development,...
-
Junior Automation Engineer
1 week ago
Bucharest, Bucureşti, Romania Bitdefender Full time 15,000 - 30,000 per yearBitdefenderBitdefender is a cybersecurity leader delivering best-in-class threat prevention, detection, and response solutions worldwide. Guardian over millions of consumer, enterprise, and government environments, Bitdefender is one of the industry's most trusted experts for eliminating threats, protecting privacy, digital identity and data, and enabling...
-
Sr. Security Engineer, AppSec
1 week ago
Bucharest, Bucureşti, Romania 6Sense Full time 40,000 - 100,000 per yearOur Mission:6sense is on a mission to revolutionize how B2B organizations create revenue by predicting customers most likely to buy and recommending the best course of action to engage anonymous buying teams. 6sense Revenue AI is the only sales and marketing platform to unlock the ability to create, manage and convert high-quality pipeline to revenue.Our...
-
Senior Application Security Engineer
2 weeks ago
Bucharest, Bucureşti, Romania Arrise Full time €40,000 - €80,000 per yearDescription Position at ARRISE ABOUT US ARRISE sets the benchmark for service delivery and excellence in the iGaming industry. Playing a key role in the success of its clients, which include Pragmatic Play, a brand relied upon by the world's biggest online casinos for its cutting-edge products, ARRISE helps to deliver exceptional gaming experiences to...
-
Product Security Engineer
2 weeks ago
Bucharest, Bucureşti, Romania Edenred Digital Center Bucharest Full time €60,000 - €120,000 per yearTake a step forward and let Edenred surprise you.Every day, we deliver innovative solutions to improve the life of millions of people, connecting employees, companies, and merchants all around the world.We know there are hundred ways for you to grow. With us, you will expand your skills in a multicultural, challenging, and dynamic environment.Dare to join...
-
Senior Quality Assurance Automation Engineer
2 weeks ago
Bucharest, Bucureşti, Romania Hays Full time €40,000 - €80,000 per yearYour new company:Our client is dedicated to accelerating the path to more reliable, affordable, and sustainable energy. They assist their customers in powering economies and delivering the electricity that is vital to health, safety, security, and an improved quality of life. Addressing the urgent need to build a more sustainable electric power system while...
-
Automation Engineer
1 week ago
Bucharest, Bucureşti, Romania Quipu GmbH Full time €60,000 - €80,000 per yearWe are looking for Automation Engineer to join our team.Key responsibilities:Plan, implement, operate, and optimize automation for banking services, release orchestration, and delivery pipelines across environments (Dev QA UAT Prod).Design, document, and continuously improve automation processes, workflows, and structures for CI/CD, IaC, and release...