About Novanta

Build a career powered by innovations that matter! At Novanta, our innovations power technology products that are transforming healthcare and advanced manufacturing—improving productivity, enhancing people’s lives and redefining what’s possible. We create for our global customers engineered components and sub-systems that deliver extreme precision and performance for a range of mission-critical applications—from minimally invasive surgery to robotics to 3D metal printing.

Novanta is one global team with over 26 offices located in The Americas, Europe and Asia-Pacific. Looking for a great place to work? You have found it with a culture that embraces teamwork, collaboration and empowerment.

Role Overview

As a Security Automation & AI Engineer, you will be responsible for designing, building, and maintaining automated workflows and AI-driven solutions that enhance the efficiency and effectiveness of Novanta's global security operations. Working closely with the Security Operations team, you will develop SOAR playbooks, detection-as-code pipelines, and intelligent automation that accelerate threat detection, incident response, and vulnerability management across the enterprise.

You will also serve as a key liaison between Security and R&D Engineering, gaining deep understanding of CI/CD pipelines and software development workflows to embed security automation into the development lifecycle. Your goal is to reduce manual operational burden, improve detection coverage, and enable the security team to scale its capabilities in line with Novanta's growth.

Primary Responsibilities

  • Design, develop, and maintain security automation workflows and SOAR playbooks to streamline alert triage, enrichment, containment, and remediation processes.
  • Build and maintain detection-as-code pipelines, enabling programmatic creation, testing, version control, and deployment of detection rules across SIEM and EDR platforms.
  • Develop AI-assisted investigation tools and scripts that auto-correlate signals across security platforms (SIEM, EDR, DLP, IAM) to accelerate incident response.
  • Automate vulnerability management workflows, including scan orchestration, prioritisation scoring, remediation tracking, and reporting to support the vulnerability management function.
  • Serve as the security team's subject matter expert on R&D CI/CD pipelines (GitHub, Azure DevOps, build/release workflows).
  • Identify and implement opportunities to embed automated security checks and controls into CI/CD pipelines, shifting security left in the development lifecycle.
  • Build and maintain API-level integrations between security tools and platforms.
  • Collaborate cross-functionally with IT, R&D Engineering, Cloud, and DevOps teams.
  • Provide security automation expertise and communicate complex technical solutions to management.
  • Contribute to the creation and continuous improvement of security automation documentation, runbooks, and operational procedures.
  • Evaluate emerging AI and automation technologies for applicability to security operations, and lead proof-of-concept initiatives.
  • Support the broader security operations team during incident response and threat hunting activities as needed.

Novanta offers a culture that embraces teamwork, collaboration and empowerment.

Required Education, Experience & Knowledge

  • Education: Bachelor's degree in Computer Science, Cybersecurity, Software Engineering, or a related field (or equivalent practical experience).
  • Experience: 3–5 years of experience in security operations, security engineering, or DevSecOps, with a demonstrated focus on automation and tooling development.
  • Programming: Strong proficiency in Python; experience with PowerShell, Bash, or other scripting languages. Ability to write production-quality, maintainable code.
  • CI/CD & DevOps: Hands-on experience with CI/CD platforms (e.g., GitHub Actions, Azure DevOps Pipelines, Jenkins) and version control systems (Git). Understanding of software development lifecycle and DevOps practices.
  • Security Tooling: Experience with SIEM platforms, EDR solutions, and/or SOAR platforms. Familiarity with DLP and IAM tools is a plus.
  • Cloud & Infrastructure: Working knowledge of cloud platforms (AWS, Azure, or GCP) and infrastructure-as-code concepts.
  • APIs & Integration: Strong experience building and consuming RESTful APIs for tool integration and data orchestration.
  • AI/ML Awareness: Familiarity with AI/ML concepts and their practical application in cybersecurity (e.g., anomaly detection, automated classification, LLM-based workflows). Experience with AI frameworks or platforms is a plus.
  • Frameworks: Understanding of security frameworks such as NIST, MITRE ATT&CK, and CIS. Knowledge of GDPR and its impact on security across a global company.
  • Certifications (preferred): Relevant certifications such as GIAC (GCSA, GMON), PCSAE (Palo Alto Certified Security Automation Engineer), AWS Security Specialty, or equivalent.

Skills

  • Dealing with Ambiguity: Can effectively cope with change; can shift gears comfortably; can decide and act without having the total picture.
  • Analytical & Problem-Solving Mindset: Approaches problems systematically; breaks down complex workflows into automatable components.
  • Champions Customer Value Creation: Delivers innovative automation solutions that improve security outcomes for internal stakeholders.
  • Functional/Technical Skills: Has the functional and technical knowledge and skills to design, build, and maintain production-grade security automation.
  • Collaboration & Communication: Works effectively across global, cross-functional teams. Can translate complex automation concepts into clear language.
  • Written Communications: Produces high-quality technical documentation and runbooks.
  • Continuous Learning: Demonstrates curiosity and a commitment to staying current with emerging security automation, AI, and DevSecOps trends.