Jobs and Careers
FI
Principal Security Engineer (SOAR)
First AmericanSanta Ana, United Statesfull_timeVerifiedPosted 15 May 2025
💰 $222,300/yr($166,800/yr – $222,300/yr)
About the role
Who We Are
Join a team that puts its People First! Since 1889, First American (NYSE: FAF) has held an unwavering belief in its people. They are passionate about what they do, and we are equally passionate about fostering an environment where all feel welcome, supported, and empowered to be innovative and reach their full potential. Our inclusive, people-first culture has earned our company numerous accolades, including being named to the Fortune 100 Best Companies to Work For® list for ten consecutive years. We have also earned awards as a best place to work for women, diversity and LGBTQ+ employees, and have been included on more than 50 regional best places to work lists. First American will always strive to be a great place to work, for all. For more information, please visit www.careers.firstam.com.What We Do
The Principal Security Engineer is responsible for leading the development and application of security orchestration, automation, and response (SOAR) solutions that enable the success of Security Operations Center (SOC) initiatives. This position requires deep, expert-level technical experience automating SOC workflows. The Principal Security Engineer primarily interfaces with the SOC as well as other teams within Information Security. The Principal Security Engineer designs, implements, and maintains SOAR workflows to improve the efficiency and effectiveness of the Security Operations Center (SOC). This role involves creating playbooks, integrating security tools, and automating repetitive tasks while collaborating with SOC analysts and IT teams to optimize incident response. The Principal Security Engineer is also responsible for leading the SOC’s security automation architecture and strategic roadmap while developing metrics to measure program maturity and value. The overall objective of the Principal Security Engineer will be to build and optimize automation for security operations, enhance our incident response processes, and grow our threat management capabilities.Responsible for supporting the Information Security Incident Response program initiatives, including protecting information and information systems from unauthorized access, use, disclosure, disruption, modification, perusal, inspection, recording or destruction.
This role will be hybrid three days a week onsite in Santa Ana, CA.
What You'll Do:
- Lead design, develop, and implement SOAR playbooks and workflows.
- Investigates, recommends, evaluates, deploys, and integrates security tools and systems with the SOAR platform to improve our ability to protect corporate assets and infrastructure.
- Automate repetitive SOC processes to improve efficiency and reduce response times.
- Collaborate with SOC analysts to understand operational requirements and tailor automation solutions.
- Monitor and maintain the SOAR platform to ensure optimal performance and uptime.
- Develops test plans and conducts rigorous testing and validation of playbooks to ensure reliability and effectiveness.
- Provide technical expertise and troubleshooting for SOAR-related issues.
- Document playbooks, workflows, and integrations thoroughly for SOC reference.
- Stay updated on advancements in SOAR platforms, cybersecurity threats, and best practices.
- Monitors, reports and resolves security related problems and discrepancies.
- Participates as a member of the Information Security Incident Response Team.
- Participates in Cyber Security Incident investigations.
- Required to perform duties outside of normal work hours based on business needs.
What You'll Bring:
- Must have minimum 7+ years information security experience working in a Security Operations Center (SOC)
- Must have 5+ years hands on experience with SOAR technologies and SOC tools
- License or Certification: CISSP, GCIH, GIAC, or SOAR-specific credentials
- Generally requires a BS Degree in Computer Science, Information Technology, Cybersecurity, or equivalent work experience
- Must have hands-on working knowledge of SOAR platform(s)
- Must have hands-on working knowledge of integrating security tools and technologies
- Strong understanding of incident response processes, security tools, and cybersecurity frameworks
- Proficiency in scripting languages (e.g., Python, JavaScript) for automation and integration
- Experience with APIs and system integrations for security tools
- Experience with SIEM solutions and threat intelligence platforms
- Knowledge of IT infrastructure and network security
- Experience in implementing Information Security technologies and/or processes required
- Experience in product evaluation and managing vendor relationships required
- Experience in defining Information Securi
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s