SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Port is an Agentic SDLC Platform that helps engineering teams build, govern, and operate the software development lifecycle using AI agents. Following a $100M Series C funding round, the company is in a growth and global expansion phase.
As Security Operations & Automation Engineer, you will architect Port's AI-driven detection and response stack. You'll own incident response across corporate systems, workstations, and identity infrastructure, unifying alerts from all sources into a single SOAR/XDR fabric powered by AI agents for first-line investigation and response.
Key responsibilities include:
- Architect and own Port's detection and response stack, integrating SIEM, XDR, SOAR, EDR, and IAM into one automated fabric rather than siloed tools
- Deploy and tune AI agents to handle alert triage, enrichment, and investigation, with humans engaged only for edge cases
- Build SOAR playbooks and integrations across the security and IT toolchain (endpoint, identity, ticketing, chat) for end-to-end automated detection, enrichment, and remediation
- Own the alert pipeline: unify signals from EDR, IAM, cloud, and SaaS sources into one triage and response workflow
- Evaluate and integrate best-of-breed AI-native security tools, wiring each into the unified detection and response fabric
- Drive vulnerability and patch management across corporate systems, automating prioritization and remediation workflows
- Build and tune detection rules specific to Port's environment, treating detection as code
- Maintain security dashboards tracking MTTD/MTTR, automation rate, and alerts resolved without human touch
Success means building an autonomous, AI-driven security operation where automation and AI agents are the default and manual work is the exception. Within the first months, you'll take ownership of the security alert workflow, stand up integrations connecting Port's security tooling stack, eliminate manual legacy triage processes, build relationships with IT and Cloud Security teams, and demonstrably reduce MTTD/MTTR while proving the AI-vs-AI defense approach.