Skip to content
← Back to job listings

Security Automation Architect (AI & SOC Transformation)

Plain Concepts · Spain

External listingfull-time26 days ago

About The Role

Join our team as a Security Automation Architect, where you will play a key role in transforming traditional Security Operations Centers into AI-native, automated, and scalable security operations. You will analyze current SOC processes, identify opportunities for automation, and design workflows that integrate AI agents to assist analysts in triage, investigation, and response. This is a hands-on architecture role that requires a strong background in cybersecurity, security automation, and incident response. Enjoy a competitive salary, flexible work hours, remote work options, and a comprehensive benefits package.

  • Analyzing current SOC processes and identifying opportunities for automation and improvement.
  • Converting manual playbooks into structured, automated workflows and designing how AI agents assist analysts.
  • Establishing clear boundaries between automation, AI, and human decisions, and ensuring all automation is secure, explainable, and auditable.
  • The ideal candidate will help organizations move from manual, ticket-driven security operations toward a new operating model where analysts, automation and AI agents work together to increase speed, consistency and resilience
  • 6+ years of experience in cybersecurity (SOC, SecOps, Detection & Response, etc.)
  • Practical mindset: ability to design solutions that work in real environments
  • Fluent in Spanish and English
  • Hands-on experience working with SOC environments (L1, L2, L3)
  • Experience designing or improving detection use cases and incident response workflows
  • Strong background in security automation, SIEM or SOAR
  • Ability to translate analyst knowledge into automation and workflows
  • Understanding of incident lifecycle, enrichment and escalation processes
  • Experience working with technical teams and business stakeholders
  • Experience with Microsoft Sentinel, Defender XDR or Security Copilot
  • Experience in SOC automation / SOAR implementations
  • Knowledge of detection engineering and MITRE ATT&CK
  • Experience with KQL, SPL or similar query languages
  • Exposure to AI-driven workflows or automation
  • Experience in SOC transformation programs or MSSP environments

This is an external listing. JobSpring does not represent or verify the employer. Report this listing