Job Description We are looking for an experienced Torq HyperAutomation Platform Engineer to own, operate, and continuously improve the hyperautomation platform supporting our security operations. This role is ideal for a hands-on security automation professional who can design, build, test, and maintain workflows for alert enrichment, triage, containment, notifications, case management, and incident response across multiple client environments. The Torq HyperAutomation Platform Engineer will work closely with SOC analysts, incident responders, security engineers, and client technical teams to identify repetitive manual processes and convert them into reliable, secure, and well-documented automations. This person will serve as the primary engineer responsible for the Torq platform, its integrations, platform health, and automation roadmap. Responsibilities - Serve as the primary owner of the Torq hyperautomation platform, including administration, workflow development, access management, integration management, versioning, troubleshooting, and platform health. - Design, build, test, deploy, and maintain automated security workflows for alert enrichment, triage, containment, escalation, notification, case management, and incident response. - Build and maintain integrations with security platforms, including CrowdStrike Falcon, email security tools, identity providers, SIEM platforms, cloud services, threat intelligence sources, and ticketing systems. - Automate CrowdStrike Falcon activities involving detections, host information, Real Time Response, host containment, event streaming, and CrowdStrike Next-Gen SIEM. - Integrate ticketing, case management, and IT service management platforms such as ConnectWise, Jira Service Management, or ServiceNow into automated security workflows. - Automate ticket creation, enrichment, assignment, routing, escalation, status updates, and closure. - Develop custom integrations using REST APIs, webhooks, JSON, and scripting when native connectors are unavailable or do not meet operational requirements. - Implement and troubleshoot API authentication methods, including OAuth 2.0, API keys, bearer tokens, and service accounts. - Automate email security operations such as phishing alert intake, message tracing, email search and purge actions, user-reported phishing workflows, threat enrichment, and analyst notifications. - Partner with SOC analysts and incident responders to identify high-volume, repetitive, and low-value manual tasks that can be converted into automations. - Support the onboarding of new clients, security tools, credentials, integrations, and data sources into the automation platform. - Establish standards for workflow naming, documentation, reusable components, secrets management, logging, testing, error handling, deployment, and change control. - Build automations with appropriate failure handling, retry logic, logging, monitoring, and analyst notifications. - Maintain workflow documentation, technical procedures, integration references, runbooks, and knowledge base articles. - Monitor workflow performance, platform availability, integration health, errors, and automation success rates. - Measure and report on automation impact, including alerts automatically enriched or triaged, analyst hours saved, workflow success rates, and reductions in response times. - Continuously review and improve existing workflows to increase reliability, security, maintainability, and operational value. Requirements - 3+ years of experience in security operations, security engineering, integration engineering, automation engineering, or a related technical role. - Hands-on experience working with a SOAR or security hyperautomation platform such as Torq, Palo Alto Cortex XSOAR, Splunk SOAR, Swimlane, Tines, or a comparable platform. - Strong understanding of SOC processes, including alert intake, enrichment, triage, escalation, containment, investigation, and incident response. - Strong working knowledge of REST APIs, including authentication, HTTP methods, status codes, request and response handling, pagination, rate limits, and error handling. - Experience testing and troubleshooting API integrations using Postman, curl, or similar tools. - Experience integrating with CrowdStrike Falcon APIs or a comparable endpoint detection and response platform. - Experience automating EDR activities such as detection enrichment, endpoint queries, host actions, containment, or response actions. - Experience working with email security platforms such as Microsoft Defender for Office 365, Proofpoint, Abnormal Security, Avanan, Barracuda, IRONSCALES, or similar tools. - Experience building or supporting automated phishing investigation and response workflows. - Experience integrating ticketing, case management, PSA, or ITSM systems such as ConnectWise, Jira Service Management, or ServiceNow. - Scripting proficiency in Python, JavaScript, or a similar programming language. - Strong experience working with JSON, webhooks, structured data, conditional logic, and data transformation. - Ability to troubleshoot workflow failures involving authentication, permissions, API behavior, data formatting, platform configuration, and automation logic. - Solid understanding of secrets management, secure credential handling, role-based access control, and change management practices. - Strong analytical, troubleshooting, and problem-solving skills. - Strong written and verbal communication skills in English. - Ability to communicate technical concepts clearly to SOC analysts, engineers, leadership, and client stakeholders. - Highly organized, detail-oriented, and able to manage multiple workflows, integrations, and priorities independently. - Strong documentation skills and the ability to create clear technical procedures, runbooks, and workflow documentation. Preferred Qualifications - Direct experience administering and building production workflows in Torq. - Experience working in an MSSP, MDR provider, SOC, or multi-tenant security environment. - Experience managing automations across multiple client environments, credentials, security platforms, and technology stacks. - Familiarity with Microsoft 365, Microsoft Entra ID, and Microsoft Graph API for identity and email automation. - Experience with SIEM platforms such as CrowdStrike Next-Gen SIEM, CrowdStrike LogScale, Microsoft Sentinel, Splunk, or similar platforms. - Experience working with SIEM query languages and security event data. - Familiarity with threat intelligence and enrichment platforms such as VirusTotal, AbuseIPDB, URLScan, AlienVault OTX, or similar services. - Familiarity with Git, workflow versioning, testing, peer review, and controlled production deployment practices. - Experience creating reusable automation components, templates, and standardized integration patterns. - Experience measuring automation performance and presenting operational metrics to technical or business stakeholders. - Relevant certifications such as CrowdStrike CCFA, CrowdStrike CCFR, CompTIA Security+, GIAC certifications, or comparable security certifications. Benefits Why Join Black Birch Technology Group • Work on cutting edge AI and automation initiatives • Build enterprise grade solutions with real business impact • Collaborate with innovative teams and clients across industries • Opportunity for growth within a rapidly evolving AI and automation practice • Flexible hybrid and remote work environment - Competitive salary package. - Paid sick days. - Continuous training and professional growth opportunities. - Performance-based incentives. - Private health insurance. - Christmas bonus. - Supportive culture that values employee well-being.
Data Platform Engineer
Lumenalta
Senior Data & Platform Engineer – Veterinary Technology | DR
Truelogic
System Administrator - Remote
Corporacion Sidif Del Caribe
Staffing Solution Architect - Remote Work
BairesDev
Ruby on Rails Developer - Remote Work
BairesDev
Forward Deployed Engineer (CloudFlare) - Technology Industry
Truelogic Software