SOC Automation Engineer (Python / SOAR / LLM Integrations)

Egypt - Remote

⚠️ We'll shut down after Aug 1st - try foo🦍 for all jobs in tech ⚠️

DeepSource

DeepSource is a premier provider of IT services, including talent acquisition, managed services, professional IT consulting, and remote or on-site deployment.

View all jobs at DeepSource

Apply now Apply later

Key Responsibilities

  • Design, build, and maintain SOC automation workflows for L1 triage, alert enrichment, and response using SOAR tools (Cortex XSOAR, Splunk SOAR, n8n, etc.)
  • Develop modular, agent-based pipelines using Python or TypeScript (ideally event-driven or orchestrated via n8n, Apache Airflow, etc.)
  • Integrate threat intelligence APIs (VirusTotal, AbuseIPDB, Shodan, MISP, OpenCTI)
  • Collaborate with AI team to interface LLMs into enrichment/summarization steps (e.g., GPT, Claude, mistral, etc.)
  • Contribute to architectural design and data flow models (timeline graphs, observables)
  • Write clean, testable code and deploy in cloud-based environments (AWS/GCP)

Requirements

Qualifications

  • 5–10+ years of experience in cybersecurity, DevSecOps, or SOC automation
  • Proficiency in Python, JavaScript/TypeScript, or Golang
  • Hands-on with at least one SOAR or workflow automation platform (e.g., Cortex XSOAR, Phantom, TheHive, Shuffle, StackStorm, n8n)
  • Strong understanding of SIEM tools (e.g., Splunk, Sentinel, QRadar, Wazuh)
  • Experience with threat intelligence feeds, EDR/XDR tools, and incident response logic
  • Familiarity with RESTful APIs, webhook/event-driven architectures
  • (Bonus) Experience with AI/ML models (especially LLMs or agent frameworks)
Apply now Apply later

* Salary range is an estimate based on our AI, ML, Data Science Salary Index 💰

Job stats:  0  0  0
Category: Engineering Jobs

Tags: Airflow APIs Architecture AWS Claude GCP Golang GPT JavaScript LLMs Machine Learning ML models Pipelines Python Splunk TypeScript

Regions: Remote/Anywhere Middle East
Country: Egypt

More jobs like this