Security Automation Engineer
ForesiteSecurity Automation Engineer Foresite is seeking a highly motivated and passionate Security Automation Engineer with a strong foundation in cybersecurity and foundational Python skills to join our growing Professional Services team. In this client-facing role, you will be instrumental in helping Foresite's customers deploy and adopt their SOAR-powered ecosystem, working directly with them throughout each engagement. This is a client-facing role. Your primary customers will be Foresite's external clients, not our internal Security Operations Center (SOC). Your work will center on building automation workflows, playbooks, and blocks tailored to each customer's environment, and delivering hands-on enablement training so their teams can confidently operate and extend what you've built. If you are an exceptional problem solver who enjoys translating security operations needs into practical automation, and who thrives on teaching and building strong customer relationships, we encourage you to apply! Note: While experience with Google SecOps SOAR is highly valued, we are fully prepared to train a strong Cybersecurity and Python specialist who has a passion and willingness to master the platform and enjoys working directly with customers. What You'll Do: As a Security Automation Engineer, you will act as a technical partner and enabler for our customers throughout each engagement. Your responsibilities will include: Custom Scripting & Integration: Write and adapt Python scripts to build API integrations and configure automated actions within customer SOAR environments, applying foundational scripting skills rather than advanced software development. Customer Discovery & Solution Design: Partner with customer stakeholders to understand their tools, processes, and pain points, then translate those requirements into tailored automation workflows, playbooks, and blocks. Version Control & Asset Management: Leverage Git and GitHub best practices to manage playbook and script repositories, maintaining clean, well-documented, and reusable automation assets across customer engagements. SOAR Playbook, Workflow & Block Delivery: Design, build, and troubleshoot automation playbooks, workflows, and blocks within Google SecOps SOAR to meet each customer's specific use cases and operational goals. Customer Enablement & Training: Serve as the primary technical point of contact during customer engagements, delivering hands-on enablement training so customer teams can confidently operate, maintain, and extend the automation you build. Continuous Improvement: Collaborate with customer stakeholders to identify bottlenecks in their security operations and implement automated solutions that measurably decrease mean-time-to-detection (MTTD) and response (MTTR). Documentation: Create clear, customer-facing documentation for playbooks, workflows, and integrations delivered during each engagement, so customer teams can maintain and extend their automation long after the engagement ends. Who You Are: The Ultimate Problem-Solver: You are a natural self-starter with excellent analytical skills and meticulous attention to detail. You love troubleshooting automation workflows and finding practical solutions during live customer engagements. Cybersecurity & Coding Hybrid: You possess 3-5 years of experience in security engineering or security operations, combined with foundational Python scripting skills. API & Integration Specialist: Comfortable working with RESTful APIs, parsing JSON structures, and integrating data across diverse platforms. GitHub Literate: Demonstrated experience with GitHub (branching, merging, pull requests) for managing and version-controlling automation assets. Willingness to Learn SOAR: If you don't already have experience with Google SecOps SOAR (formerly Siemplify) or other major SOAR platforms, you have an active eagerness and aptitude to learn and master it quickly. Client-Facing Communicator: Strong interpersonal, presentation, and communication skills to work directly with customer teams, understand their pain points, and translate operational needs into automation and training that sticks. Why Join the Foresite Team? At Foresite, we aren’t just another security provider—we are a mission-driven partner helping organizations navigate an increasingly complex threat landscape. Founded by passionate security practitioners, we’ve grown into a global leader in SecOps and MDR by staying true to our core value: radical transparency. When you join Foresite, you are part of a "humans-first" culture where your expertise is valued, and your well-being is a priority. We leverage our Google Cloud Premier SecOps Partnership to stay at the cutting edge, but we know that our greatest asset is our people. What We Offer: Comprehensive Health & Wellness: Robust medical insurance options to keep you and your family healthy. Employer-Covered Insurance: We fully provide employer paid Dental coverage, as well as Short-Term (STD) and Long-Term Disability (LTD) to ensure you are protected financially if life takes an unexpected turn. Generous Time Off: We believe in a true work-life balance. You’ll start with 3 weeks of paid vacation, plus additional sick leave and paid company holidays to ensure you have time to recharge. Growth & Mentorship: Access to world-class training and mentorship. We support your career trajectory, whether you’re looking to deepen your technical skills or move into leadership. Impactful Work: Help protect global clients using the latest AI-enhanced security tools and GCP native technologies. Department Security Engineering Locations US Remote Remote status Fully Remote About Foresite Foresite was founded in 2013 when our group of passionate security professionals saw what a nightmare organizations were facing to stay secure. We founded Foresite Cybersecurity with a mission: empower organizations of all sizes to navigate this ever-changing threat landscape. Founded in 2013 Applicant tracking system by Teamtailor