Center for Internet Security, Inc.

Principal Security Operations Center Automation Engineer - Remote

Job Locations US
Operations and Security Services
Regular Full-Time


The Principal Security Operations Center (SOC) Automation Engineer will be a senior technical individual contributor position within CIS’s Operations & Security Services (OSS) Department. The Principal SOC Automation Engineer will provide the orchestration strategy, and playbook lifecycle management and lead the development of Security Orchestration, Automation, and Response (SOAR) playbooks that improve the efficiency and effectiveness of security operations provided by the Multi-State Information Sharing & Analysis Center (MS-ISAC) and Elections Infrastructure Information Sharing & Analysis Center (EI-ISAC) to State, Local, Tribal, and Territorial (SLTT) organizations.


The Center for Internet Security (CIS) makes the connected world a safer place for people, businesses, and governments through our core competencies of collaboration and innovation. We are a community-driven nonprofit responsible for industry leading best practices for securing IT systems and data. We lead a global community of IT professionals to continuously evolve these standards and provide products and services to proactively safeguard against emerging threats.


Salary Range: $108,100 - $163,600
We offer a competitive total rewards package at the Center for Internet Security:
  • Base salary is determined on a number of factors including, but not limited to, education, experience and skills.
  • Health (PPO, EPO, HSA), Dental & Vision Insurance eligibility starting from the first day of hire
  • $500 wellness card for Health Coverage Participants
  • 401(k) with 4% Company Match, vested from the first day of hire
  • Flexible Spending Account (FSA) & Dependent Care Account (DCA)
  • Life Insurance
  • Bonding Leave
  • Paid Volunteering Program
  • Bonus eligibility
  • Paid Time Off (PTO) inclusive of vacation, personal and sick time
  • Paid Holidays
  • Wellness Program
  • Employee Engagement Activities
  • Professional Development Opportunities
  • Tuition Reimbursement
  • Student Loan PayDown Program
  • Employee Referral program
  • Employee Assistance Program

What You'll Do

  • Design, build, test, deploy, maintain, and document new SOAR playbooks to extend the existing security capabilities of the MS- and EI-ISAC. Develop creative new approaches to accelerate threat detection, responses, and proactive defenses. Orchestrate information between SOC, Cyber Threat Intelligence (CTI), and Cyber Incident Response Team (CIRT) analysts, improving the relevance and actionability of products
  • Lead playbook development and deployment with multi-functional team members. Collaborate with and provide feedback to the analysts, engineers, and product managers as you operationalize innovative security automation and orchestration into security operations
  • Communicate and document the efficiency and effectiveness of SOAR playbooks to management and stakeholders. Make recommendations to OSS executive leadership on capabilities, direction, investments, and divestments of technologies, products, and services
  • Actively research emerging security practices and workflows and operationalize findings to better enhance our offerings
  • Develop and manage the playbook development lifecycle, including change control process and quality assurance standards for automation and orchestration, to ensure changes are tested, rollback plans created, and that playbooks do not negatively impact integrated business systems or operations
  • Assist internal support teams with troubleshooting highly technical issues that cannot be resolved by lower-tiered support levels
  • Provide briefings and training to SLTT members, MS-ISAC and EI-ISAC executive committees, and internal stakeholders on cyber defensive technologies. This position will closely align with the sales, marketing, and communications teams to assist with pre- and post-sales support and provide input to develop materials for members
  • Other tasks and responsibilities as assigned

What You'll Need

  • Bachelor’s degree in information technology, cybersecurity, or a related field*
  • 8+ years’ experience in network and security operations. Minimum 3 years’ experience in SOC analysis and threat hunting
  • 5+ years’ experience in SOAR and information automation
  • Minimum 2 years’ experience building/integrating security operations processes in large environments
  • Expert-level knowledge of Application Programming Interface (API) technologies and integrating security tools such as firewalls, intrusion detection and prevention systems, endpoint security tools, and other data sources into automated workflows
  • Expert-level proficiency in Python development
  • Significant experience with orchestrating processes, development of custom integrations, and designing advanced decision-making logic
  • Significant experience with designing and implementing automation and orchestration best practices, including playbook lifecycle management and development of Key Performance Indicators (KPIs)
  • Experience with cyber defense technologies, asset management technologies, Security Event and Incident Management (SIEM) platforms, Threat Intelligence Platforms (TIPs), information and enrichment services, and the MITRE ATT&CK framework
  • Excellent client-facing and internal communication skills
  • Solid organizational skills, including attention to detail and multi-tasking skills
  • Candidate must be eligible to obtain National Security Clearance
  • The position is open to U.S. citizens and requires a favorably adjudicated DHS Fitness Review for Public Trust Positions**
  • Must be authorized to work in the United States

It's A Plus If You Have:

  • Advanced degree in Computer Science, Business, or related field
  • Strong presentation capabilities
  • Experience with Cyware’s Orchestrate SaaS platform
  • Relevant industry certifications such as CISSP, GCIH, GCIA, GMON
  • Experience in vendor management and relationships
  • Familiarity with Agile DevOps and project management

*Additional years of relevant experience or a combination of an Associate’s degree or equivalent and relevant experience may be substituted for the Bachelor’s degree.


**Factors that may cause a negative Fitness Review decision include:

  • Criminal Conduct
  • Dishonest Conduct
  • Employment Misconduct
  • Alcohol Abuse
  • Drug Use (illegal drug use or use of a legal drug in a manner that deviates from approved medical direction) Additionally, illegal drug use includes the use of drugs that are illegal for federal purposes despite being legal in select states and countries, such as marijuana.
  • False Statements
  • Financial Issues
  • Have not resided in the US for three (3) of the past five (5) years

At CIS, we are committed to providing an inclusive environment in which the diverse backgrounds, experiences, and views of our employees, members, and customers are valued and respected. It is through this commitment that we are able to work together towards our common mission: to make the connected world a safer place.


Sorry the Share function is not working properly at this moment. Please refresh the page and try again later.
Share on your newsfeed