Senior Response Automation Engineer - Information Security
ElasticUnited StatesPosted 24 February 2026
Job Description
<div class="content-intro"><p>Elastic, the Search AI Company, enables everyone to find the answers they need in real time, using all their data, at scale — unleashing the potential of businesses and people. The Elastic Search AI Platform, used by more than 50% of the Fortune 500, brings together the precision of search and the intelligence of AI to enable everyone to accelerate the results that matter. By taking advantage of all structured and unstructured data — securing and protecting private information more effectively — Elastic’s complete, cloud-based solutions for search, security, and observability help organizations deliver on the promise of AI.</p></div><h3><strong>What Is The Role : </strong></h3>
<p style="text-align: justify;">As a <strong>Senior Response Automation Engineer</strong> at Elastic you will work to enhance and maintain the workflows supporting Elastic front-line defenders, assisting the team delivering safe and secure products and services to our customers, users, and fellow Elasticians. Currently, the Threat Detection and Response Team heavily relies on automation - we have developed many integrations and intelligent workflows to provide alert context, take action automatically, and more. This has resulted in significant time savings and efficiencies.</p>
<p style="text-align: justify;">Our ability to continue to enhance existing workflows and develop new ones to take us to the next level in our SOC-less journey. In this role, you will be responsible for understanding, maintaining, and improving threat detection and response processes, working on automations that support alert triage through management of response cases. If doing all of this with the Elastic Stack excites you, then we’d love to meet you!</p>
<h3><strong>What You Will Be Doing : </strong></h3>
<ul>
<li style="text-align: justify;">Drive the full lifecycle of automation development, from design to maintenance, to significantly advance our threat detection and response capabilities.</li>
<li style="text-align: justify;">Optimize and automate core SOC/IR analyst workflows, focusing on delivering rich alert context and efficient triage processes across all detection sources, including the Elastic Detection Engine.</li>
<li style="text-align: justify;">Establish automated feedback mechanisms that empower the Threat Detection team to continuously refine detections, identify false positives, and uncover new enrichment and automation opportunities.</li>
<li style="text-align: justify;">Build and manage integrations across security tools and platforms to create seamless workflows and enhance data correlation for comprehensive threat detection and response.</li>
<li style="text-align: justify;">Architect and implement automated incident response playbooks for effective containment, eradication, and recovery in various threat scenarios.</li>
<li style="text-align: justify;">Serve as a key automation expert, partnering with security analysts and incident responders to transform manual security operations into highly efficient, automated processes.</li>
<li style="text-align: justify;">Innovate and document best practices for detecting, responding to, and eradicating advanced threats, focusing on reducing overall time to response.</li>
<li style="text-align: justify;">Ensure the integrity and effectiveness of all workflows through rigorous testing and validation.</li>
<li style="text-align: justify;">Collaborate strategically with Threat Detection and Response leadership to identify critical areas for enhancement and execute impactful improvement initiatives.</li>
</ul>
<h3><strong>What You Bring : </strong></h3>
<ul>
<li style="text-align: justify;">At least 3 years of experience related to automation engineering in a complex, global environment. Automation experience focused on security operations / incident response is a plus.</li>
<li style="text-align: justify;">Experience with automating with Security Operations and Response (SOAR) tools or a ... (truncated, view full listing at source)
Apply Now
Direct link to company career page
More jobs at Elastic
See all →More AWS jobs
See all →Associate Manager, New Verticals - Consumer Financials Strategy & Operations
DoorDash · New York, NY; San Francisco, CA; Chicago, IL; Seattle, WA; Los Angeles, CA; Washington DC
Associate, Quality Strategy & Operations
DoorDash · United States - Remote
Creative Project Manager
DoorDash · Los Angeles,CA; San Francisco, CA; New York, NY
Manager, New Verticals - Gift Card Strategy & Operations
DoorDash · New York, NY; San Francisco, CA; Los Angeles, CA; Seattle, WA; Washington, DC