SOC Automation Engineer

Posted Yesterday
Hiring Remotely in United States
Remote
Mid level
Artificial Intelligence • Software
The Role
Design, develop, and maintain Python-based SOC automation workflows for alert triage, investigation, enrichment, incident handling, and response. Build reliable Temporal.io workflows and integrations with Microsoft Sentinel, Defender, REST APIs, databases, and threat intelligence systems. Develop KQL queries, translate SOC requirements into technical solutions, and improve automation scalability, observability, reliability, and analyst efficiency while collaborating with Cyber Defenders and cross-functional engineering teams.
Summary Generated by Built In

As a leading provider of AI-powered extended managed detection and response (MXDR) services, Ontinue is on a mission to be the most trusted, 24/7, always-on security partner that empowers customers to embrace the future by using AI to operate more strategically, at scale, and with less risk. We believe that the combination of AI and human expertise is essential for delivering effective managed security that is tailored to a customer’s unique environment, operational constraints, and risks.  

Continuous protection. AI-powered Nonstop SecOpsThat’s Ontinue. 

Role Overview 

As a SOC Automation Engineer, you will help transform how our Cyber Defenders investigate and respond to security incidents. 

Working at the intersection of cybersecurity, software engineering and automation, you will design, develop and maintain Python-based solutions that reduce manual effort, improve investigation quality and enable our global, 24/7 Security Operations Centre to operate effectively at scale.  

Key Responsibilities 

  • Design, develop and maintain Python-based automation workflows supporting security investigation, alert triage, enrichment, incident handling and response
  • Translate operational requirements and SOC analyst pain points into clearly defined, scalable automation use cases
  • Develop complex workflows using Temporal.io, following engineering best practices for reliability, scalability, maintainability and observability
  • Build integrations with security products, REST APIs, databases and other internal and external systems.  
  • Create automation capabilities across alert triage, threat intelligence, investigation, enrichment and incident response
  • Work with Microsoft Security technologies, including Microsoft Sentinel, Microsoft Defender and Defender XDR, along with their associated telemetry and APIs
  • Develop and optimise Kusto Query Language, or KQL, queries for investigation, enrichment, detection and automation use cases
  • Design robust business logic capable of handling complex investigation scenarios and operational edge cases.  
  • Partner closely with Cyber Defenders to validate requirements and ensure automation delivers meaningful operational value
  • Contribute throughout requirements analysis, technical design, implementation, testing and continuous improvement
  • Monitor and improve automation performance, reliability, coverage and its impact on analyst workload.  
  • Help shape the evolution of Ontinue’s SOC automation architecture and engineering standards

 

What Success Looks Like 

  • Identify high-value automation opportunities arising from genuine SOC operational challenges. 
  • Translate cybersecurity requirements into clear, actionable technical designs
  • Deliver reliable automation quickly and iteratively, improving solutions through feedback from SOC users
  • Build workflows that are scalable, resilient, maintainable and observable
  • Understand the security context behind each automation use case rather than simply implementing technical requirements to increase automation coverage, improve investigation quality and measurably reduce manual analyst workload. 
  • Collaborate effectively across SOC, Engineering, Product, AI and Platform teams

 

Required Experience & Skills 

  • At least three years of professional experience in software engineering, cybersecurity, security operations or automation engineering
  • Hands-on software development experience, including coding, API integrations, data processing, error handling and asynchronous programming
  • A solid understanding of SOC operations, including alert triage, incident investigation, enrichment, threat intelligence and response
  • Experience with the Microsoft Security ecosystem, preferably including Microsoft Sentinel and Microsoft Defender
  • Strong KQL skills and the ability to develop queries supporting security investigations and automation
  • Experience with Git and modern software development practices, including testing, debugging, code reviews and CI/CD
  • An understanding of distributed systems, asynchronous processing, workflow orchestration and scalable automation architectures

 

Preferred 

  • Experience developing automation for Microsoft Sentinel, Microsoft Defender for Endpoint, Defender XDR or associated Microsoft Security products
  • Experience developing production automation workflows, ideally using Temporal.io or a comparable workflow orchestration frameworks
  • Experience integrating REST APIs and working with authentication, JSON, webhooks and external services and cybersecurity APIs or threat intelligence platforms
  • Knowledge of common attack techniques and frameworks, including MITRE ATT&CK


Next Steps 

If you have the skills and experience required and feel that Ontinue is a place you can belong, we would love to get to know you better! Please drop an application to this role and our talent acquisition manager will be in touch to discuss further.  

Learn more: www.ontinue.com 

Skills Required

  • At least three years of professional experience in software engineering, cybersecurity, security operations, or automation engineering
  • Hands-on software development experience, including coding, API integrations, data processing, error handling, and asynchronous programming
  • Solid understanding of SOC operations, including alert triage, incident investigation, enrichment, threat intelligence, and response
  • Experience with the Microsoft Security ecosystem, preferably including Microsoft Sentinel and Microsoft Defender
  • Strong Kusto Query Language skills for security investigations and automation
  • Experience with Git and modern software development practices, including testing, debugging, code reviews, and CI/CD
  • Understanding of distributed systems, asynchronous processing, workflow orchestration, and scalable automation architectures
  • Experience developing automation for Microsoft Sentinel, Microsoft Defender for Endpoint, Defender XDR, or related Microsoft Security products
  • Experience developing production automation workflows using Temporal.io or comparable workflow orchestration frameworks
  • Experience integrating REST APIs and working with authentication, JSON, webhooks, external services, cybersecurity APIs, or threat intelligence platforms
  • Knowledge of common attack techniques and frameworks, including MITRE ATT&CK
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Zürich
195 Employees

What We Do

As a leading provider of AI-powered managed extended detection and response (MXDR) services, Ontinue is on a mission to be the most trusted security partner that empowers customers to embrace and accelerate digital transformation by using AI to operate more at scale, and with less risk. The combination of AI and human expertise is essential for delivering effective managed security that is tailored to a customer’s unique environment, operational constraints, and risks. Our MXDR service combines powerful proprietary AI with the industry’s first collaboration with Microsoft Teams to continuously build a deep understanding of our customers’ environments, informing how we prevent, detect, and respond to threats. Our Microsoft expertise allows customers to achieve these outcomes with the Microsoft Security tools they already own. The result is highly localized managed protection that empowers security teams to be faster, smarter, and more cost efficient than ever before. Continuous protection. AI-powered Nonstop SecOps. That’s Ontinue.

Similar Jobs

ChowNow Logo ChowNow

Operations Manager

Food • Software
Easy Apply
Remote or Hybrid
USA
208 Employees
130K-168K Annually

General Motors Logo General Motors

Sales Manager

Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Remote or Hybrid
United States
165000 Employees

General Motors Logo General Motors

Sales Manager

Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Remote or Hybrid
United States
165000 Employees

General Motors Logo General Motors

Performance Accountability Specialist

Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Remote or Hybrid
Detroit, MI, USA
165000 Employees
81K-109K Annually

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account