CSOC Engineer - Security Automation
Job description
About the role
Fastly is seeking a CSOC Engineer to focus on security automation within our global operations team. You will help maintain the integrity of our edge cloud platform by developing tools and workflows to improve our incident response capabilities. In this capacity, you will own the design and implementation of automated security processes that enhance the efficiency and reliability of our Security Operations Center. The role requires a proactive approach to identifying repetitive manual tasks and replacing them with resilient, scalable scripts and integrations. You will work closely with distributed engineering and operations teams to ensure security automation aligns with broader platform objectives. This position is critical in bridging the gap between detection logic and rapid, consistent incident remediation. The successful candidate will be responsible for owning the lifecycle of automation, from initial requirements gathering through deployment and ongoing optimization. You will serve as a subject matter expert for security tooling and automation best practices within the Pune operations hub.
Location: India
Engagement: Full-time
What you'll do
- Architect and deploy automation scripts that streamline security operations and accelerate incident handling workflows.
- Conduct in-depth monitoring and analysis of security logs to detect potential threats or anomalies across the network infrastructure.
- Partner with engineering teams to embed security controls directly into existing infrastructure components and deployment pipelines.
- Drive the continuous improvement of detection logic and the maintenance of comprehensive response playbooks.
- Lead the investigation and remediation of security incidents, ensuring timely and effective resolution.
- Author and sustain detailed runbooks that standardize automated responses to recurring security events and edge cases.
- Leverage command-line tools and APIs to interact with security platforms and orchestration frameworks programmatically.
- Convert high-level security requirements into detailed technical specifications that guide automation project execution.
- Perform systematic reviews of automated workflows to verify ongoing effectiveness and alignment with shifting threat landscapes.
- Support the creation of dashboards and reporting mechanisms that provide operational visibility into automated security processes.
- Aid in the deployment of security tooling updates with an emphasis on stability, performance, and operational resilience.
- Act as a central technical resource for colleagues looking to integrate automation into their daily security activities and workflows.
Requirements
- Bring proven experience from a Security Operations Center or a closely related technical security role.
- Demonstrate strong proficiency in scripting languages used for automation tasks and operational tooling.
- Show familiarity with web application security principles, API protection mechanisms, and DDoS mitigation strategies.
- Exhibit the ability to analyze complex data sets and translate them into actionable security insights and recommendations.
- Maintain strong communication skills to effectively coordinate with globally distributed engineering and operations teams.
- Prove capability to perform reliably in a 24x7 on-call environment and respond to incidents at any hour.
- Demonstrate understanding of security frameworks and the ability to apply them in practical operational scenarios.
- Commit to adhering strictly to established security policies and procedures without exception or compromise.
- Provide a proven track record of driving process improvements within security operations functions.
- Show willingness to contribute to the development, documentation, and refinement of standard operating procedures.
- Display capacity to manage multiple priorities simultaneously in a fast-paced, dynamic operational setting.
Skills & tools
- Demonstrate proficiency in automation and orchestration tools that enable scalable security operations.
- Bring experience with log management platforms and modern observability tooling for security monitoring.
- Show knowledge of modern web protocols and network security architectures that underpin edge cloud services.
- Possess hands-on experience with at least one scripting language such as Python or Bash for automation tasks.
- Show familiarity with Security Information and Event Management (SIEM) systems and their practical application.
- Understand RESTful APIs and demonstrate the ability to interact with them programmatically for integration purposes.
- Have experience with version control practices as they apply to infrastructure and automation code repositories.
- Show knowledge of containerized environments and the specific security considerations within those contexts.
- Bring exposure to security orchestration, automation, and response (SOAR) platforms and their operational use.
- Demonstrate familiarity with cloud-native security tooling and associated configuration best practices.
Practical notes
This position is based in Pune. Please ensure your application reflects your current work authorization status for India.