SOC Automation Engineer

OntinueOn-siteFull-timeMid level, 2–5 yearsListed 2 weeks ago

Apply now

About this role

As a leading provider of AI-powered extended managed detection and response (MXDR) services,  Ontinue  is on a mission to be the most trusted, 24/7, always-on security partner that empowers customers to embrace the future by using AI to operate more strategically, at scale, and with less risk. We believe that the combination of AI and human  expertise  is essential for delivering effective managed security that is tailored to a customer’s unique environment, operational constraints, and risks.

Continuous protection. AI-powered  Nonstop SecOps .  That’s  Ontinue .

Role Overview

As a SOC Automation Engineer, you will help transform how our Cyber Defenders investigate and respond to security incidents.

Working at the intersection of cybersecurity, software  engineering  and automation, you will design,  develop  and  maintain  Python-based solutions that reduce manual effort, improve investigation  quality  and enable our global, 24/7 Security Operations Centre to  operate  effectively at scale.

Key Responsibilities

- Design, develop and  maintain  Python-based automation workflows supporting security investigation, alert triage, enrichment, incident  handling and response

- Translate operational requirements and SOC analyst pain points into clearly defined, scalable automation use cases

- Develop complex workflows using Temporal.io, following engineering best practices for reliability, scalability,  maintainability and observability

- Build integrations with security products, REST APIs,  databases  and other internal and external systems.

- Create automation capabilities across alert triage, threat intelligence, investigation,  enrichment and incident response

- Work with Microsoft Security technologies, including Microsoft Sentinel, Microsoft  Defender and Defender XDR, along with their associated telemetry and APIs

- Develop and  optimise  Kusto Query Language, or KQL, queries for investigation, enrichment,  detection and automation use cases

- Design robust business logic capable of handling complex investigation scenarios and operational edge cases.

- Partner closely with Cyber Defenders to  validate requirements and ensure automation delivers meaningful operational value

- Contribute throughout requirements analysis, technical design, implementation,  testing and continuous improvement

- Monitor and improve automation performance, reliability,  coverage  and its impact on analyst workload.

- Help shape the evolution of  Ontinue’s SOC automation architecture and engineering standards

What Success Looks Like

- Identify  high-value automation opportunities arising from genuine SOC operational challenges.

- Translate cybersecurity requirements into clear, actionable technical designs

- Deliver reliable automation quickly and iteratively, improving solutions through feedback from SOC users

- Build workflows that are scalable, resilient,  maintainable and observable

- Understand the security context behind each automation use case rather than simply implementing technical requirements to i ncrease automation coverage, improve investigation  quality   and measurably  reduce manual analyst workload.

- Collaborate effectively across SOC, Engineering, Product,  AI and Platform teams

Required Experience & Skills

- At least three years of professional experience in software engineering, cybersecurity, security  operations or automation engineering

- H ands-on  software development  experience, including  coding , API integrations, data processing, error  handling and asynchronous programming

- A solid understanding of SOC operations, including alert triage, incident investigation, enrichment, threat  intelligence and response

- Experience with the Microsoft Security ecosystem, preferably including Microsoft Sentinel and Microsoft Defender

- Strong KQL skills and the ability to develop queries supporting security investigations and automation

- Experience with Git and modern software development practices, including testing, debugging, code  reviews and CI/CD

- An understanding of distributed systems, asynchronous processing, workflow  orchestration and scalable automation architectures

Preferred

- Experience developing automation for Microsoft Sentinel, Microsoft Defender for Endpoint, Defender  XDR or associated Microsoft Security products

- Experience developing production automation workflows, ideally using Temporal.io or a comparable workflow orchestration frameworks

- Experience integrating REST APIs and working with authentication, JSON, webhooks and external services and cybersecurity APIs or threat intelligence platforms

- Knowledge of common attack techniques and frameworks, including MITRE ATT&CK

Next Steps

If you have the skills and experience  required  and feel that  Ontinue  is a place you can  belong , we would love to get to know you better!  Please drop an application to  this role and our talent acquisition manager will be in touch to discuss further.

Learn more:  www.ontinue.com