Security Automation & AI Engineer

Novanta

Barcelona, ESonsitePosted Aug 3, 2026
Posting intelligenceActively listed

Skills

classificationprogrammaticazure devopsjenkinsgithubpythonazurecicdgooglecloudawsllmml

About the role

Build a career powered by innovations that matter! At Novanta, our innovations power technology products that are transforming healthcare and advanced manufacturing - improving productivity, enhancing people’s lives and redefining what’s possible. We create for our global customers engineered components and sub-systems that deliver extreme precision and performance for a range of mission-critical applications - from minimally invasive surgery to robotics to 3D metal printing.

Novanta is one global team with over 26 offices located in The Americas, Europe and Asia-Pacific. Looking for a great place to work? You have found it with a culture that embraces teamwork, collaboration and empowerment. Come explore Novanta.

Business Unit Overview

This position is part of Novanta's Corporate and Shared Services global teams. Novanta's Corporate and Shared Services teams play an important role in executing the company's strategic mission and operations. Included in Corporate and Shared Services are the business functions including Finance, Accounting, Human Resources, Information Technology, Legal, Compliance, Corporate Development and Corporate Marketing. The Corporate and Shared Services teams work closely with all Novanta business units to support operating initiatives contributing to the organization's financial success.

Job Summary

As a Security Automation & AI Engineer, you will be responsible for designing, building, and maintaining automated workflows and AI-driven solutions that enhance the efficiency and effectiveness of Novanta's global security operations. Working closely with the Security Operations team, you will develop SOAR playbooks, detection-as-code pipelines, and intelligent automation that accelerate threat detection, incident response, and vulnerability management across the enterprise.

You will also serve as a key liaison between Security and R&D Engineering, gaining deep understanding of CI/CD pipelines and software development workflows to embed security automation into the development lifecycle. Your goal is to reduce manual operational burden, improve detection coverage, and enable the security team to scale its capabilities in line with Novanta's growth, while maintaining the confidentiality, integrity, and availability of our data and ensuring compliance with industry standards and regulations.

Primary Responsibilities

Design, develop, and maintain security automation workflows and SOAR playbooks to streamline alert triage, enrichment, containment, and remediation processes.

Build and maintain detection-as-code pipelines, enabling programmatic creation, testing, version control, and deployment of detection rules across SIEM and EDR platforms.

Develop AI-assisted investigation tools and scripts that auto-correlate signals across security platforms (SIEM, EDR, DLP, IAM) to accelerate incident response.

Automate vulnerability management workflows, including scan orchestration, prioritisation scoring, remediation tracking, and reporting to support the vulnerability management function.

Serve as the security team's subject matter expert on R&D CI/CD pipelines (GitHub, Azure DevOps, build/release workflows), understanding how software is developed, tested, and deployed across Novanta's business units.

Identify and implement opportunities to embed automated security checks and controls into CI/CD pipelines, shifting security left in the development lifecycle.

Build and maintain API-level integrations between security tools and platforms, ensuring data flows efficiently without manual intervention.

Collaborate cross-functionally with IT, R&D Engineering, Cloud, and DevOps teams to align security automation initiatives with broader technology strategies.

Provide security automation expertise and communicate complex technical solutions to management and the leadership team.

Contribute to the creation and continuous improvement of security automation documentation, runbooks, and operational procedures.

Evaluate emerging AI and automation technologies for applicability to security operations, and lead proof-of-concept initiatives.

Support the broader security operations team during incident response and threat hunting activities as needed.

Required Education, Experience & Knowledge

Education – Bachelor's degree in Computer Science, Cybersecurity, Software Engineering, or a related field (or equivalent practical experience).

Experience – 3–5 years of experience in security operations, security engineering, or DevSecOps, with a demonstrated focus on automation and tooling development.

Programming – Strong proficiency in Python; experience with PowerShell, Bash, or other scripting languages. Ability to write production-quality, maintainable code.

CI/CD & DevOps – Hands-on experience with CI/CD platforms (e.g., GitHub Actions, Azure DevOps Pipelines, Jenkins) and version control systems (Git). Understanding of software development lifecycle and DevOps practices.

Security Tooling – Experience with SIEM platforms, EDR solutions, and/or SOAR platforms. Familiarity with DLP and IAM tools is a plus.

Cloud & Infrastructure – Working knowledge of cloud platforms (AWS, Azure, or GCP) and infrastructure-as-code concepts.

APIs & Integration – Strong experience building and consuming RESTful APIs for tool integration and data orchestration.

AI/ML Awareness – Familiarity with AI/ML concepts and their practical application in cybersecurity (e.g., anomaly detection, automated classification, LLM-based workflows). Experience with AI frameworks or platforms is a plus.

Frameworks – Understanding of security frameworks such as NIST, MITRE ATT&CK, and CIS. Knowledge of GDPR and its impact on security across a global company.

Certifications (preferred) – Relevant certifications such as GIAC (GCSA, GMON), PCSAE (Palo Alto Certified Security Automation Engineer), AWS Security Specialty, or equivalent.

Skills

Dealing with Ambiguity – Can effectively cope with change; can shift gears comfortably; can decide and act without having the total picture; comfortable handling risk and uncertainty in fast-paced security environments.

Analytical & Problem-Solving Mindset – Approaches problems systematically; breaks down complex workflows into automatable components; uses data to drive decisions and measure the effectiveness of automation.

Champions Customer Value Creation – Delivers innovative automation solutions that improve security outcomes for internal stakeholders. Seeks feedback from SOC analysts, threat hunters, and engineers to optimise workflows.

Functional/Technical Skills – Has the functional and technical knowledge and skills to design, build, and maintain production-grade security automation at a high level of accomplishment.

Collaboration & Communication – Works effectively across global, cross-functional teams. Can translate complex automation concepts into clear language for technical and non-technical audiences alike.

Written Communications – Can write clearly and succinctly in a variety of communication settings and styles; produces high-quality technical documentation and runbooks.

Continuous Learning – Demonstrates curiosity and a commitment to staying current with emerging security automation, AI, and DevSecOps trends and technologies.

Please call +1 781-266-5700 if you need a disability accommodation for any part of the employment process.

Questions about this role

Click "Apply with AI Applyd" above and you are done. Your resume is rewritten for this advert, the screening questions are answered, and it is submitted on Novanta's own hiring system. No retyping your history, no fourteen tabs, no evening lost.

Compensation for Security Engineer roles in Spain varies widely by seniority, employer size, and remote vs onsite arrangement. Check the salary range on this listing when published, or browse our Security Engineer hub for Spain medians across recent openings.

You never touch the form - the application is filled and submitted for you on Novanta's own hiring system. It is not marked sent when we press submit. It is marked sent when a confirmation from their system arrives at the address we apply with, and your dashboard shows which stage each application is at until then.

Twelve applicant tracking systems have a real apply path: Workday, Greenhouse, Lever, Ashby, Workable, iCIMS, Personio, Recruitee, Teamtailor, Rippling, Breezy and SmartRecruiters. Your application goes in on the employer's own hiring system, never into an aggregator queue.

Want AI Applyd to auto-apply to roles like this?

We tailor your resume per posting, fill the forms, and track replies for you.