Information Security Engineer
Gulf Coast Automation Group · Chicago, IL
$105,000–$110,000from the description
Jul 12, 2026
Chicago, IL
Jul 20, 2026
What this job asks for AI summary
A fully remote security engineering role focused on building and maintaining SOAR playbooks to automate alert triage, threat investigation, and incident response, while also advancing AI-driven workflows within a SOC. The position involves malware and intrusion analysis, log and network capture review, SIEM work, and participation in Purple Team exercises and on-call rotations. It suits candidates with hands-on SOAR and scripting experience and a background in incident response.
Mid level · 5+ years · Remote · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 7,000 people nationally plausibly meet what this posting asks for (information security analysts). range 2,900–10,400
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (6)
The JD's 'What You Bring' section is framed as 'Ideal Experience' rather than a strict requirements block, but several items are stated with firm language ('Required scripting or programming skills', 'Hands-on experience with SOAR playbook development', '5+ years of security experience') and are treated as hard gates. The degree requirement is explicitly softened by 'or equivalent education, training, or work experience', so no minimum degree is set.
Scripting/programming is listed as required; Python is named first and PowerShell and Go are offered as alternatives via 'etc.' framing — all captured under one skill entry.
SIEM platforms and associated query languages (Yara-L, CQL, SPL) appear only in the 'What You'll Do' responsibilities narrative, not in a requirements block, so they are treated as preferred. Yara-L is listed as the primary with CQL and SPL as alternatives since the JD presents them as a group.
Security certifications (GIAC, CISSP) are explicitly marked 'preferred' in the JD.
Seniority is assessed as Mid: 5+ years is the stated minimum, the role is an individual-contributor security engineer with no indication of cross-team technical leadership or org-wide scope that would elevate it to Senior. The title carries no level modifier, so the title states no level.
Caller marked this a fully-remote role — scored against the national candidate pool.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.