Cybersecurity Systems Automation Engineer (Sr. Scientist) - Remote
USA - Texas - Austin (Lavaca WeWork), United States
MSD
At MSD, we're following the science to tackle some of the world's greatest health threats. Get a glimpse of how we work to improve lives.Job Description
Position Summary:
We are seeking a senior-level Cybersecurity Systems Automation Engineer to join the Cybersecurity Automation & AI team. This role will lead the design and delivery of scalable automation solutions across enterprise platforms such as ServiceNow, Microsoft Defender, Azure, and identity systems. You will engineer cross-domain workflows that reduce manual effort, optimize security processes, and drive CIO-level outcomes across the enterprise.
Job Description:
This position sits within a fast-moving cybersecurity engineering function focused on high-impact automation. The Cybersecurity Systems Automation Engineer will architect and build automation pipelines that span beyond traditional SOAR, integrating systems like ServiceNow Flow Designer, Defender XDR, UIPath, and API-driven components from identity, endpoint, and cloud security platforms. You will partner with domain owners in IAM, Endpoint Security, Application Security, and others to streamline and secure workflows before incidents reach the SOC.
You’ll be responsible for building reusable automations that reduce ticket volume, eliminate manual handoffs, and improve response time across critical business processes. This role is ideal for a hands-on systems engineer who thrives on delivering automation at scale within a complex, highly regulated enterprise.
Key Responsibilities:
Design and deliver automation pipelines across ServiceNow, Defender, UIPath, and additional security platforms.
Engineer workflows that eliminate redundant tickets, reduce toil, and surface risk insights in real time.
Collaborate with domain teams (IAM, Endpoint, AppSec, etc.) to identify automation opportunities and codify best practices.
Optimize and modernize legacy playbooks (e.g., ServiceNow runbooks) into engineered, scalable workflows.
Leverage scripting (Python/PowerShell) and integration methods (REST APIs, webhooks, ServiceNow spokes) to drive end-to-end automation.
Build kills switches, telemetry validation, and governance controls into automation for production safety.
Mentor R1/R2 engineers and contribute to team knowledge base and automation standards.
Minimum education required:
Bachelor’s degree in Computer Science, Engineering, or a related field.
Required Qualifications:
5+ years of experience in enterprise IT or cybersecurity automation roles
Proficient in scripting languages (Python, PowerShell) and automation frameworks
Strong hands-on experience with ServiceNow (Flow Designer, IntegrationHub, or scripted APIs)
Familiarity with Microsoft Defender (XDR, MDE) and Azure security services
Experience designing and deploying secure, scalable automations in a regulated enterprise environment
Ability to translate business process and security use cases into technical automation design
Strong understanding of RESTful APIs, data pipelines, and platform integrations
Preferred Qualifications:
Experience with UIPath, Power Automate, or similar orchestration platforms
Prior experience automating workflows in identity platforms (e.g., SailPoint, Entra ID)
Familiarity with SIEM/SOAR platforms (e.g., Sentinel, Splunk) from an automation standpoint
Exposure to large-scale automation in regulated industries (pharma, finance, healthcare)
Experience contributing to or leading cross-functional automation initiatives with measurable business impact
Current Employees apply HERE
Current Contingent Workers apply HERE
US and Puerto Rico Residents Only:
Our company is committed to inclusion, ensuring that candidates can engage in a hiring process that exhibits their true capabilities. Please click here if you need an accommodation during the application or hiring process.
As an Equal Employment Opportunity Employer, we provide equal opportunities to all employees and applicants for employment and prohibit discrimination on the basis of race, color, age, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability status, or other applicable legally protected characteristics. As a federal contractor, we comply with all affirmative action requirements for protected veterans and individuals with disabilities. For more information about personal rights under the U.S. Equal Opportunity Employment laws, visit:
We are proud to be a company that embraces the value of bringing together, talented, and committed people with diverse experiences, perspectives, skills and backgrounds. The fastest way to breakthrough innovation is when people with diverse ideas, broad experiences, backgrounds, and skills come together in an inclusive environment. We encourage our colleagues to respectfully challenge one another’s thinking and approach problems collectively.
Learn more about your rights, including under California, Colorado and other US State Acts
U.S. Hybrid Work Model
Effective September 5, 2023, employees in office-based positions in the U.S. will be working a Hybrid work consisting of three total days on-site per week, Monday - Thursday, although the specific days may vary by site or organization, with Friday designated as a remote-working day, unless business critical tasks require an on-site presence.This Hybrid work model does not apply to, and daily in-person attendance is required for, field-based positions; facility-based, manufacturing-based, or research-based positions where the work to be performed is located at a Company site; positions covered by a collective-bargaining agreement (unless the agreement provides for hybrid work); or any other position for which the Company has determined the job requirements cannot be reasonably met working remotely. Please note, this Hybrid work model guidance also does not apply to roles that have been designated as “remote”.
San Francisco Residents Only: We will consider qualified applicants with arrest and conviction records for employment in compliance with the San Francisco Fair Chance Ordinance
Los Angeles Residents Only: We will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws, including the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance
Search Firm Representatives Please Read Carefully
Merck & Co., Inc., Rahway, NJ, USA, also known as Merck Sharp & Dohme LLC, Rahway, NJ, USA, does not accept unsolicited assistance from search firms for employment opportunities. All CVs / resumes submitted by search firms to any employee at our company without a valid written search agreement in place for this position will be deemed the sole property of our company. No fee will be paid in the event a candidate is hired by our company as a result of an agency referral where no pre-existing agreement is in place. Where agency agreements are in place, introductions are position specific. Please, no phone calls or emails.
Employee Status:
RegularRelocation:
VISA Sponsorship:
Travel Requirements:
Flexible Work Arrangements:
RemoteShift:
Valid Driving License:
Hazardous Material(s):
Job Posting End Date:
05/13/2025*A job posting is effective until 11:59:59PM on the day BEFORE the listed job posting end date. Please ensure you apply to a job posting no later than the day BEFORE the job posting end date.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: APIs Application security Automation Azure Cloud Compliance Computer Science Endpoint security Finance Governance IAM PowerShell Python SailPoint Scripting Sentinel SIEM SOAR SOC Splunk XDR
Perks/benefits: Flex hours Relocation support
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.