The Role
Own and operate the Torq hyperautomation platform to design, build, test, and maintain automated security workflows and integrations (EDR, SIEM, email security, ITSM). Partner with SOC analysts and responders to convert manual tasks into reliable automations, ensure platform health, document runbooks, and measure automation impact.
Summary Generated by Built In
We are looking for an experienced Torq HyperAutomation Platform Engineer to own, operate, and continuously improve the hyperautomation platform supporting our security operations.
This role is ideal for a hands-on security automation professional who can design, build, test, and maintain workflows for alert enrichment, triage, containment, notifications, case management, and incident response across multiple client environments.
The Torq HyperAutomation Platform Engineer will work closely with SOC analysts, incident responders, security engineers, and client technical teams to identify repetitive manual processes and convert them into reliable, secure, and well-documented automations. This person will serve as the primary engineer responsible for the Torq platform, its integrations, platform health, and automation roadmap.
Responsibilities
- Serve as the primary owner of the Torq hyperautomation platform, including administration, workflow development, access management, integration management, versioning, troubleshooting, and platform health.
- Design, build, test, deploy, and maintain automated security workflows for alert enrichment, triage, containment, escalation, notification, case management, and incident response.
- Build and maintain integrations with security platforms, including CrowdStrike Falcon, email security tools, identity providers, SIEM platforms, cloud services, threat intelligence sources, and ticketing systems.
- Automate CrowdStrike Falcon activities involving detections, host information, Real Time Response, host containment, event streaming, and CrowdStrike Next-Gen SIEM.
- Integrate ticketing, case management, and IT service management platforms such as ConnectWise, Jira Service Management, or ServiceNow into automated security workflows.
- Automate ticket creation, enrichment, assignment, routing, escalation, status updates, and closure.
- Develop custom integrations using REST APIs, webhooks, JSON, and scripting when native connectors are unavailable or do not meet operational requirements.
- Implement and troubleshoot API authentication methods, including OAuth 2.0, API keys, bearer tokens, and service accounts.
- Automate email security operations such as phishing alert intake, message tracing, email search and purge actions, user-reported phishing workflows, threat enrichment, and analyst notifications.
- Partner with SOC analysts and incident responders to identify high-volume, repetitive, and low-value manual tasks that can be converted into automations.
- Support the onboarding of new clients, security tools, credentials, integrations, and data sources into the automation platform.
- Establish standards for workflow naming, documentation, reusable components, secrets management, logging, testing, error handling, deployment, and change control.
- Build automations with appropriate failure handling, retry logic, logging, monitoring, and analyst notifications.
- Maintain workflow documentation, technical procedures, integration references, runbooks, and knowledge base articles.
- Monitor workflow performance, platform availability, integration health, errors, and automation success rates.
- Measure and report on automation impact, including alerts automatically enriched or triaged, analyst hours saved, workflow success rates, and reductions in response times.
- Continuously review and improve existing workflows to increase reliability, security, maintainability, and operational value.
Requirements
- 3+ years of experience in security operations, security engineering, integration engineering, automation engineering, or a related technical role.
- Hands-on experience working with a SOAR or security hyperautomation platform such as Torq, Palo Alto Cortex XSOAR, Splunk SOAR, Swimlane, Tines, or a comparable platform.
- Strong understanding of SOC processes, including alert intake, enrichment, triage, escalation, containment, investigation, and incident response.
- Strong working knowledge of REST APIs, including authentication, HTTP methods, status codes, request and response handling, pagination, rate limits, and error handling.
- Experience testing and troubleshooting API integrations using Postman, curl, or similar tools.
- Experience integrating with CrowdStrike Falcon APIs or a comparable endpoint detection and response platform.
- Experience automating EDR activities such as detection enrichment, endpoint queries, host actions, containment, or response actions.
- Experience working with email security platforms such as Microsoft Defender for Office 365, Proofpoint, Abnormal Security, Avanan, Barracuda, IRONSCALES, or similar tools.
- Experience building or supporting automated phishing investigation and response workflows.
- Experience integrating ticketing, case management, PSA, or ITSM systems such as ConnectWise, Jira Service Management, or ServiceNow.
- Scripting proficiency in Python, JavaScript, or a similar programming language.
- Strong experience working with JSON, webhooks, structured data, conditional logic, and data transformation.
- Ability to troubleshoot workflow failures involving authentication, permissions, API behavior, data formatting, platform configuration, and automation logic.
- Solid understanding of secrets management, secure credential handling, role-based access control, and change management practices.
- Strong analytical, troubleshooting, and problem-solving skills.
- Strong written and verbal communication skills in English.
- Ability to communicate technical concepts clearly to SOC analysts, engineers, leadership, and client stakeholders.
- Highly organized, detail-oriented, and able to manage multiple workflows, integrations, and priorities independently.
- Strong documentation skills and the ability to create clear technical procedures, runbooks, and workflow documentation.
Preferred Qualifications
- Direct experience administering and building production workflows in Torq.
- Experience working in an MSSP, MDR provider, SOC, or multi-tenant security environment.
- Experience managing automations across multiple client environments, credentials, security platforms, and technology stacks.
- Familiarity with Microsoft 365, Microsoft Entra ID, and Microsoft Graph API for identity and email automation.
- Experience with SIEM platforms such as CrowdStrike Next-Gen SIEM, CrowdStrike LogScale, Microsoft Sentinel, Splunk, or similar platforms.
- Experience working with SIEM query languages and security event data.
- Familiarity with threat intelligence and enrichment platforms such as VirusTotal, AbuseIPDB, URLScan, AlienVault OTX, or similar services.
- Familiarity with Git, workflow versioning, testing, peer review, and controlled production deployment practices.
- Experience creating reusable automation components, templates, and standardized integration patterns.
- Experience measuring automation performance and presenting operational metrics to technical or business stakeholders.
- Relevant certifications such as CrowdStrike CCFA, CrowdStrike CCFR, CompTIA Security+, GIAC certifications, or comparable security certifications.
Benefits
Why Join Black Birch Technology Group
• Work on cutting edge AI and automation initiatives
• Build enterprise grade solutions with real business impact
• Collaborate with innovative teams and clients across industries
• Opportunity for growth within a rapidly evolving AI and
automation practice
• Flexible hybrid and remote work environment
- Competitive salary package.
- Paid sick days.
- Continuous training and professional growth opportunities.
- Performance-based incentives.
- Private health insurance.
- Christmas bonus.
- Supportive culture that values employee well-being.
Skills Required
- 3+ years of experience in security operations, security engineering, integration engineering, automation engineering, or related technical role
- Hands-on experience with a SOAR or hyperautomation platform (Torq, Cortex XSOAR, Splunk SOAR, Swimlane, Tines or comparable)
- Strong understanding of SOC processes (alert intake, enrichment, triage, escalation, containment, investigation, incident response)
- Working knowledge of REST APIs including authentication, HTTP methods, status codes, pagination, rate limits, and error handling
- Experience testing and troubleshooting API integrations using Postman, curl, or similar tools
- Experience integrating with CrowdStrike Falcon APIs or comparable endpoint detection and response (EDR) platform
- Experience automating EDR activities (detection enrichment, endpoint queries, host actions, containment, response actions)
- Experience with email security platforms (Microsoft Defender for Office 365, Proofpoint, Abnormal Security, Avanan, Barracuda, IRONSCALES or similar)
- Experience building or supporting automated phishing investigation and response workflows
- Experience integrating ticketing, case management, PSA, or ITSM systems (ConnectWise, Jira Service Management, ServiceNow)
- Scripting proficiency in Python, JavaScript, or a similar programming language
- Strong experience with JSON, webhooks, structured data, conditional logic, and data transformation
- Ability to troubleshoot workflow failures involving authentication, permissions, API behavior, data formatting, configuration, and logic
- Solid understanding of secrets management, secure credential handling, role-based access control, and change management practices
- Strong analytical, troubleshooting, problem-solving, written and verbal communication, organization, and documentation skills
- Direct experience administering and building production workflows in Torq
- Experience working in an MSSP, MDR provider, SOC, or multi-tenant security environment
- Experience managing automations across multiple client environments, credentials, security platforms, and technology stacks
- Familiarity with Microsoft 365, Microsoft Entra ID, and Microsoft Graph API
- Experience with SIEM platforms (CrowdStrike Next-Gen SIEM, CrowdStrike LogScale, Microsoft Sentinel, Splunk) and SIEM query languages
- Familiarity with threat intelligence/enrichment platforms (VirusTotal, AbuseIPDB, URLScan, AlienVault OTX)
- Familiarity with Git, workflow versioning, testing, peer review, and controlled production deployment practices
- Relevant certifications such as CrowdStrike CCFA/CCFR, CompTIA Security+, GIAC or comparable security certifications
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
Black Birch Group is a premier IT concierge and service provider that offers white-glove IT, Governance-Risk-Compliance (GRC), and Business Process Outsourcing (BPO) services. They aim to help MSPs and growing businesses scale by unifying various functions into a single operating model.








