SOAR and AI Engineer
Job description
About the role
Thinkahead, operating under the AHEAD brand, builds platforms that power digital business. The company brings together advances in cloud infrastructure, automation, analytics, and software delivery to help enterprises keep the promises they make about digital transformation. As a SOAR and AI Engineer, you will work at the intersection of security operations and intelligent automation. Your mission is to help organizations stop fighting the same alerts over and over by building automation that handles routine security work, and by weaving AI capabilities into the response process where they genuinely help. This is an engineering role in the truest sense: you design, build, and maintain orchestration logic, integrate security tools, and deliver automation that reduces noise and speeds up response times. You will also help enterprises adopt AI responsibly in their security programs, which is a fast-moving and exciting space. The work is delivered in partnership with clients, so you will combine deep technical skill with clear communication and a practical mindset. AHEAD prizes a culture of belonging where every perspective is valued, and the company is an equal opportunity employer that welcomes candidates from all backgrounds.
Key facts
What you'll do
You will translate messy, real-world security operations into clear, maintainable workflows that make life easier for analysts. You will configure and customize SOAR playbooks so that repetitive tasks are handled automatically and incidents flow through a logical, auditable path. You will integrate security tools and data sources so that events from different platforms can be correlated, enriched, and routed through a single, coherent response process. You will implement AI-assisted steps in those workflows, such as summarizing alerts, suggesting ticket updates, or prioritizing cases based on predicted risk. You will write clean, tested automation logic, templates, and integrations that can be reused across many customers and security environments. You will collaborate with security practitioners to understand their needs, challenge assumptions, and turn vague requirements into precise, operational behavior. You will review, document, and refine automation designs so that other engineers and customers can understand, modify, and trust the system. You will ensure that automation respects security policies, handles errors gracefully, and provides clear feedback to both humans and systems. You will contribute to reference architectures and implementation patterns that show clients how to scale automation and AI responsibly across their organizations. You will mentor analysts and technical staff on effective automation practices, helping them build confidence in the tools and improve their day-to-day operations.
Requirements
You must have a strong background in security operations concepts and hands-on experience with at least one major SOAR platform. You must understand how common security tools such as firewalls, EDR, identity providers, and ticketing systems expose data and accept actions, and you must have connected them through APIs or integrations. You must be comfortable writing automation logic using code, scripts, or visual designers, and you must care deeply about readability, maintainability, and testing of your work. You must have experience integrating multiple systems so that events, alerts, and cases can move smoothly between tools without manual intervention. You must understand data formats commonly used in security, such as JSON, key-value pairs, logs, and indicators of compromise, and you must be able to map and transform them reliably. You must have a practical understanding of security operations workflows, including incident triage, investigation steps, and reporting, and you must be able to translate those practices into automated behavior. You must be comfortable working in cloud environments and using infrastructure-as-code or configuration-as-code techniques to define and deploy automation resources. You must be comfortable learning and applying new APIs, protocols, and SDKs quickly, and you must be able to explain technical tradeoffs to non-technical stakeholders. You must be a collaborative team member who communicates clearly, shares knowledge, and seeks feedback regularly with both customers and colleagues.
Nice to have
Experience with modern AI technologies such as large language models, embeddings, or tool-use patterns is preferred, along with a track record of applying them to real problems. Experience contributing to open source projects or publishing reusable components is also preferred. Experience in regulated industries or with compliance frameworks is preferred, as is a background in threat detection, incident response, or security engineering. Experience with CI/CD pipelines, monitoring, and observability for automation platforms is preferred, along with a demonstrated ability to optimize workflows for performance and reliability.
Practical notes
This role is based in the United States and requires eligibility to work in the country without sponsorship at this time. The position is full time, and hours are aligned with business needs, including collaboration with clients in different time zones. Travel is not required, though occasional in-person meetings may be arranged when practical and mutually agreed upon. Visa sponsorship is not available for this role. The posting will remain open until the position is filled, and the company encourages candidates who meet the core requirements to apply as soon as they are ready.