SOC Automation Engineer
- Status
- Open
- Remote policy
- Remote
- Employment type
- Not stated
- Salary
- Not stated
- Categories
- SOC-Automation-Engineer, Cybersecurity-Engineering, Security-Operations, Automation-Engineering, Security-Engineering, SOC-Engineer, SOC-Automation, Security-Automation-Engineer, Cyber-Security-Automation-Engineer
- Source
- himalayas
- First observed
- 2026-09-04 11:18 UTC
- Last seen
- 2026-09-04 11:18 UTC
- Source claims posted
- 2026-09-04 11:15 UTC
- Consecutive misses
- 0 of 10
What the posting says
As a leading provider of AI-powered extended managed detection and response (MXDR) services, Ontinue is on a mission to be the most trusted, 24/7, always-on security partner that empowers customers to embrace the future by using AI to operate more strategically, at scale, and with less risk. We believe that the combination of AI and human expertise is essential for delivering effective managed security that is tailored to a customer’s unique environment, operational constraints, and risks.
Continuous protection. AI-powered Nonstop SecOps. That’s Ontinue.
Role Overview
As a SOC Automation Engineer, you will help transform how our Cyber Defenders investigate and respond to security incidents.
Working at the intersection of cybersecurity, software engineering and automation, you will design, develop and maintain Python-based solutions that reduce manual effort, improve investigation quality and enable our global, 24/7 Security Operations Centre to operate effectively at scale.
Key Responsibilities
Design, develop and maintain Python-based automation workflows supporting security investigation, alert triage, enrichment, incident handling and response
Translate operational requirements and SOC analyst pain points into clearly defined, scalable automation use cases
Develop complex workflows using Temporal.io, following engineering best practices for reliability, scalability, maintainability and observability
Build integrations with security products, REST APIs, databases and other internal and external systems.
Create automation capabilities across alert triage, threat intelligence, investigation, enrichment and incident response
Work with Microsoft Security technologies, including Microsoft Sentinel, Microsoft Defender and Defender XDR, along with their associated telemetry and APIs
Develop and optimise Kusto Query Language, or KQL, queries for investigation, enrichment, detection and automation use cases
Design robust business logic capable of handling complex investigation scenarios and operational edge cases.
Partner closely with Cyber Defenders to validate requirements and ensure automation delivers meaningful operational value
Contribute throughout requirements analysis, technical design, implementation, testing and continuous improvement
Monitor and improve automation performance, reliability, coverage and its impact on analyst workload.
Help shape the evolution of Ontinue’s SOC automation architecture and engineering standards
What Success Looks Like
Identify high-value automation opportunities arising from genuine SOC operational challenges.
Translate cybersecurity requirements into clear, actionable technical designs
Deliver reliable automation quickly and iteratively, improving solutions through feedback from SOC users
Build workflows that are scalable, resilient, maintainable and observable
Understand the security context behind each automation use case rather than simply implementing technical requirements to increase automation coverage, improve investigation qualityand measurably reduce manual analyst workload.
Collaborate effectively across SOC, Engineering, Product, AI and Platform teams
Required Experience & Skills
At least three years of professional experience in software engineering, cybersecurity, security operations or automation engineering
Hands-on software development experience, including coding, API integrations, data processing, error handling and asynchronous programming
A solid understanding of SOC operations, including alert triage, incident investigation, enrichment, threat intelligence and response
Experience with the Microsoft Security ecosystem, preferably including Microsoft Sentinel and Microsoft Defender
Strong KQL skills and the ability to develop queries supporting security investigations and automation
Experience with Git and modern software development practices, including testing, debugging, code reviews and CI/CD
An understanding of distributed systems, asynchronous processing, workflow orchestration and scalable automation architectures
Preferred
Experience developing automation for Microsoft Sentinel, Microsoft Defender for Endpoint, Defender XDR or associated Microsoft Security products
Experience developing production automation workflows, ideally using Temporal.io or a comparable workflow orchestration frameworks
Experience integrating REST APIs and working with authentication, JSON, webhooks and external services and cybersecurity APIs or threat intelligence platforms
Knowledge of common attack techniques and frameworks, including MITRE ATT&CK
Next Steps
If you have the skills and experience required and feel that Ontinue is a place you can belong, we would love to get to know you better! Please drop an application to this role and our talent acquisition manager will be in touch to discuss further.
Learn more:
Originally posted on Himalayas
Quality
- x Salary range stated weight 35%
- + Remote policy stated weight 20%
- + Location stated weight 15%
- + Organisation stated weight 15%
- + Publication date stated weight 15%
Not enough history yet to judge honesty signals.
Timeline
-
*
#568929 2026-09-04 11:18 UTCPublished