Senior Security Automation Engineer
Adobe · Lehi · Seattle · San Jose
onsitefull-time6-10 years
posted 18 Aug
Sign in to applyThe Opportunity Detection & Automation Engineering operates Adobe's detection and response backbone, closing the gap between detection and containment. As a Senior Security Automation Engineer, you'll design and build production-grade automation, orchestration, and agentic AI systems that reduce mean-time-to-respond and scale Adobe's security operations beyond human-speed triage. You'll partner with Detection Engineering to turn new detection rules into working response, engineer enterprise-scale APIs and orchestration services across the security stack, and deliver containment automation and identity/access response actions used in live incidents. This is a build role for someone who wants to reshape how Adobe automates security response, not simply administer a SOAR platform. WHAT YOU'LL DO Design, develop, and maintain automation and orchestration systems spanning SOAR playbooks, custom services, and agentic AI workflows that automate enrichment, correlation, and containment across the security stack. Partner directly with Detection Engineering on every new detection rule that needs a response action. They define the logic, you engineer and verify the automation, including autonomous/agentic response paths where appropriate. Architect and build enterprise-grade APIs, connectors, and orchestration services that give security operations teams machine-speed enrichment and correlation, reducing analyst triage time and improving signal quality at scale. Own containment and remediation automation for Incident Response, including identity-and access-related response actions used during live incidents. Create and maintain policy-enforcement automation, ensuring upstream access and control decisions execute reliably, without gaps. Integrate automation with ecosystem tooling, including identity providers, endpoint and EDR platforms, and ticketing systems, via REST APIs and custom connectors, and via SOAR platforms where they're the right tool for the job. Design and deploy agentic AI systems, including multi-step autonomous workflows with agent orchestration and context engineering, to extend detection and response beyond scripted playbook logic. Triage production automation issues as an operational priority, and track metrics for automation coverage, reliability, and time-to-remediate. Contribute to Detection-as-Code integration within Detection Engineering's existing standards, and document automation logic for team-wide ownership. Actively find ways to integrate AI into day-to-day work, including playbook development, script writing, enrichment logic, triage, incident summarization, testing, and documentation. WHAT YOU NEED TO SUCCEED Required: 7+ years in security engineering, software engineering, or security automation, with a track record of shipping production-grade code, not just configuring vendor tooling. Proven experience designing, building, and operating enterprise-scale APIs, services, or orchestration systems, demonstrated through real delivered projects. Hands-on experience building and maintaining SOAR playbooks (Splunk SOAR, Tines, XSOAR, etc.), including custom actions, connectors, and playbook logic in Python. Advanced proficiency in Python (or a comparable language) for production automation development. Demonstrated experience building or deploying agentic AI systems, such as agent orchestration, prompt or context engineering, or autonomous multi-step workflows, applied to security or operational automation. Practical understanding of incident response and security investigative workflows. Experience integrating systems with detection/SIEM tooling, identity/access systems, and ticketing/case management systems via REST APIs. Ability to work independently on unstructured problems, making defensible, risk-based decisions on containment/response logic. Strong written and verbal communication. You'll document system and automation logic for engineers and explain the same tradeoffs to non-technical collaborators