Design, develop, and maintain automated security workflows that ingest, enrich, deduplicate, prioritize, and respond to alerts generated by SIEM platforms and related detection technologies.
Engineer automated triage and response logic that reduces manual analyst effort, improves alert quality, and accelerates incident response across Security Operations.
Build integrations between security platforms and ticketing / case management systems to enable consistent case creation, enrichment, evidence capture, escalation, documentation, and stakeholder communication.
Integrate threat intelligence, asset context, identity signals, vulnerability data, and other enrichment sources into automated detection and response pipelines to support risk-based decision-making.
Lead automation for detection and rule lifecycle management, including tuning, validation, deployment, rollback planning, measurement, and continuous improvement of security use cases.
Partner with Security Services subject matter experts to translate operational pain points, incident response requirements, and detection engineering needs into scalable automation.
Develop and maintain reusable scripts, API integrations, workflow components, libraries, and runbook patterns that improve automation consistency and reduce duplicate engineering effort.
Define and apply automation standards for code quality, peer review, version control, testing, documentation, change management, and operational supportability.
Monitor production automation health, investigate failed or degraded workflows, and improve resiliency, observability, exception handling, and alerting for mission-critical automation services.
Evaluate emerging cyber threats and operational trends, then implement or improve automated coverage through new detections, enrichments, response actions, or reporting capabilities.
Lead smaller automation projects or defined phases of broader Security Operations initiatives, coordinating tasks, dependencies, testing, implementation, and handoff with cross-functional partners.
Mentor junior engineers or analysts on automation patterns, troubleshooting, secure coding practices, workflow design, and platform best practices.
Maintain accurate runbooks, workflow documentation, architecture notes, operational handoff materials, and evidence required for audits, change reviews, or leadership reporting.
Participate in on-call or critical incident support for high-impact automation services as required by the Security Operations support model.
Strong programming and scripting capability in Python, PowerShell, JavaScript, or similar languages, with experience building reliable automation for security operations use cases.
Hands-on experience with SIEM and SOAR platforms, detection logic, alert enrichment, automated playbooks, workflow orchestration, and downstream response integrations.
Strong understanding of SOC operations, incident response workflows, detection engineering, security telemetry, alert lifecycle, triage patterns, and case handling processes.
Experience designing and consuming REST APIs, webhooks, event-driven integrations, and data exchange patterns across security tools, cloud services, and internal platforms.
Working knowledge of threat frameworks such as MITRE ATT&CK, Cyber Kill Chain, or similar models, with the ability to operationalize them through automation and detection use cases.
Understanding of network protocols, endpoint telemetry, identity signals, cloud security controls, vulnerability data, and other security context used for enrichment and response.
Familiarity with CI/CD pipelines, version control, code review, test automation, release documentation, and configuration management practices for production automation.
Ability to independently analyze complex technical problems, evaluate trade-offs, and choose practical methods for reliable, supportable security automation.
Strong written and verbal communication skills with the ability to explain technical automation design, operational impact, limitations, and risk-based recommendations to security and IT stakeholders.
10–12 years of experience in cybersecurity, security operations, security engineering, detection engineering, incident response, or security automation roles.
At least 10 years of experience operating within a SOC or enterprise security environment, with direct exposure to detection engineering, incident response workflows, and security tooling automation.
Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field, or equivalent work experience.
Demonstrated experience creating or significantly improving automation workflows, security integrations, rule lifecycle processes, response playbooks, or operational tools in a production environment.
Demonstrated ability to work independently with minimal guidance on complex assignments and act as a technical resource for less experienced engineers or analysts.
Experience collaborating across security, engineering, IT, cloud, platform, and vendor teams in a global or distributed enterprise environment.
Proficient in written and spoken English.
Hands-on experience with SOAR platforms and workflow orchestration tools, including development of automated playbooks, integrations, enrichment workflows, and response actions.
Experience automating security controls and response actions across AWS, Azure, GCP, or hybrid cloud environments.
Exposure to infrastructure as code or configuration management tools such as Terraform, Ansible, or similar technologies for repeatable security automation.
Knowledge of modern detection engineering practices, including use case development, false positive reduction, enrichment strategies, coverage mapping, and telemetry quality improvement.
Experience with security automation reliability practices, including monitoring, retry logic, queue handling, error handling, performance tuning, and failure analysis.
Advanced industry certifications such as CISSP, GIAC, cloud security certifications, or security automation-related credentials are a plus.
KPIs are intended to guide measurable performance expectations and may be refined based on platform ownership, automation maturity, Security Operations priorities, and business-critical use cases.
Onboarding and environment fluency: Complete onboarding to Yum!’s Security Operations platforms, priority workflows, critical integrations, change processes, and stakeholder map within 90 days.
Automation baseline: Establish or update an inventory of assigned automations, dependencies, owners, health status, runbooks, and known gaps within the first 90 days.
Workflow delivery: Deliver at least 2–3 approved automation enhancements, playbooks, integrations, or workflow improvements in the first 3–6 months, with documented acceptance criteria and operational handoff.
Change quality: Ensure at least 95% of assigned automation changes include version control, peer review, testing evidence, rollback guidance, and runbook updates.
Operational responsiveness: Triage high-priority automation failures, degraded workflows, or production support requests within agreed SLAs and communicate impact, workaround, and remediation status clearly.
Efficiency improvement: Reduce manual steps or average enrichment time by 10–15% for at least one prioritized alert, triage, or response workflow.
MTTA / MTTR improvement: Improve mean time to acknowledge, enrich, or respond for targeted security use cases by at least 20% through validated automation.
Manual effort reduction: Reduce repeatable manual Security Operations effort by 25–30% across prioritized workflows through automation, enrichment, auto-ticketing, or response orchestration.
Detection and response quality: Improve false positive handling, enrichment quality, or alert disposition accuracy by 15–20% for selected high-volume or high-risk use cases.
Automation reliability: Maintain at least 99% availability or successful execution for business-critical automation workflows, excluding approved maintenance windows or dependent-platform outages.
Lifecycle maturity: Implement or materially improve rule lifecycle, playbook lifecycle, code review, deployment, monitoring, and rollback practices for assigned automation services.
Knowledge transfer: Mentor junior analysts or engineers through documented patterns, code reviews, troubleshooting sessions, and reusable automation templates.