Automation Engineer Ii, Falcon Complete (remote)

CrowdStrike CrowdStrike · Enterprise · Ireland, United Kingdom · Remote

The Automation Engineer II on the Falcon Complete MDR team will develop expertise in scaling security operations through automation and AI. This role involves building SOAR playbooks, AI-powered workflows, and scripted solutions to maximize analyst efficiency in detection triage, investigation, and response. Responsibilities include developing automation workflows, integrating LLM APIs and AI services, and conducting testing of AI-powered workflows.

What you'd actually do

  1. Assist in building and maintaining security automation workflows and playbooks in SOAR platforms to streamline investigation, triage, and response actions
  2. Develop PowerShell and Python scripts for security enrichment, remediation, and basic forensic functions
  3. Assist with integrating LLM APIs and AI services into automated workflow pipelines to enhance detection and response capabilities
  4. Conduct end-to-end testing and validation of automated and AI-powered workflows prior to production deployment
  5. Build and maintain complex API integrations connecting security platforms, data sources, and AI services within automated workflow pipelines

Skills

Required

  • 2+ years of experience in automation, scripting, or cybersecurity
  • Proficiency with PowerShell for security investigation and response tasks
  • Working knowledge of Python for automation and API integration
  • Experience with low-code/no-code or SOAR workflow automation platforms to build, maintain, and scale security workflows
  • Hands-on experience with REST API integration, including authentication methods, request handling, and response parsing within automation workflows
  • Familiarity with event-driven and webhook-triggered automation design patterns
  • Working knowledge of JavaScript or expression-based scripting logic within automation or workflow platforms
  • Design and execute workflow validation and quality assurance testing strategies to ensure automation reliability and detection integrity
  • Basic understanding of SIEM query languages and security analytics
  • Familiarity with data formats (JSON) and Regular Expressions for data parsing
  • Understanding of incident detection and response workflows in SOC/MDR environments
  • Experience with version control systems (Git, GitHub, GitLab, Bitbucket)
  • Proven experience utilizing AI technologies to enhance decision-making, streamline workflows and processes, improve efficiency and drive business outcomes.

Nice to have

  • Falcon SOAR platform experience
  • LogScale (formerly Humio) experience
  • Experience with self-hosted automation platform deployment (e.g., Docker or containerized environments)
  • Experience managing secure credential and secrets management within automation pipelines
  • Familiarity with AI workflow frameworks, LLM integration, and basic prompt engineering concepts

What the JD emphasized

  • AI-native platform
  • AI-powered workflows
  • integrating LLM APIs and AI services
  • AI technologies to enhance decision-making

Other signals

  • AI-powered workflows
  • integrating LLM APIs and AI services
  • automation and AI