AI Security Automation Engineer
Software Engineering, Data Science
Vietnam
Protecting the World’s Critical Infrastructure
OPSWAT, a global leader in IT, OT, and ICS critical infrastructure cybersecurity, delivers an end-to-end platform that gives public and private sector organizations and enterprises the critical advantage needed to protect their complex networks, secure their devices, and ensure compliance. Over the last 20 years our commitment to innovative technology has earned the trust of more than 1,700 organizations, governments, and institutions globally, solidifying our role in protecting the world’s critical infrastructure and securing our way of life.
The Position
The AI Security Automation Engineer designs, builds, and operates AI-enabled automation across Cybersecurity Operations. The role converts manual, repetitive, and data-heavy security processes into governed workflows and agentic systems with clear controls, auditability, metrics, and human approval where required.
This role remains security-first: automation must strengthen control effectiveness, reduce cycle time, improve evidence quality, and support faster detection and response without weakening governance, privacy, or accountability.
What You Will be Doing
- Build agentic security workflows. Design and implement AI agents that gather context, analyze security data, use approved tools, generate evidence, route work, and escalate decisions within defined guardrails.
- Develop and maintain SOAR and security automation playbooks for alert enrichment, triage, correlation, evidence capture, case creation, notifications, response recommendations, and remediation tracking.
- Automate security controls, KCI calculations, evidence collection, validation, testing support, exception handling, and management reporting across the security control framework.
- Streamline selected GRC workflows, including ISQ, TPSR, evidence collection, control mapping, risk flagging, exception routing, SLA tracking, and audit trails.
- Integrate SIEM, SOAR, EDR, identity, vulnerability, cloud security, ticketing system, data platforms, APIs, and collaboration tools into end-to-end security workflows.
- Performing other tasks as assigned by Direct Supervisor.
What We Need from You
- 3+ years of experience in cybersecurity, SecOps engineering, security automation, platform engineering, GRC engineering, or a related role.
- Demonstrated experience building production-grade security workflows, integrations, or automation.
- Hands-on programming experience with Python or a similar language, REST APIs, webhooks, JSON, SQL, authentication, data transformation, and error handling.
- Experience with SIEM, SOAR, EDR, case-management, ticketing, GRC, or comparable security platforms.
- Practical understanding of alert triage, security investigations, incident response, remediation, and operational security metrics.
- Experience developing LLM-enabled workflows or agents that use tools, retrieve enterprise context, maintain traceability, and incorporate human review.
#LI-onsite
OPSWAT is an equal opportunity employer. We celebrate diversity and are committed to providing an environment where equal employment opportunities are extended to all employees and applicants, free of discrimination and harassment of any type. All employment decisions are based on individual qualifications, job requirements, and business needs without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other category protected by federal, state, or local laws.
Recruiting Agencies: we do not accept unsolicited resumes from third party agencies for any of our open positions. To submit resumes for our jobs, there must be a recruiting contract approved by our legal team and endorsed by both parties. We are currently not accepting additional 3rd party agencies at this time.