Summary
Ontinue is a provider of AI-powered extended managed detection and response services. The SOC Automation Engineer will design, develop, and maintain Python-based automation solutions that support security investigations, alert triage, enrichment, incident handling, and response for a global, 24/7 Security Operations Centre. The role partners with Cyber Defenders and cross-functional teams to improve automation reliability, scalability, and operational impact.
Responsibilities
- Design, develop and maintain Python-based automation workflows supporting security investigation, alert triage, enrichment, incident handling and response
- Translate operational requirements and SOC analyst pain points into clearly defined, scalable automation use cases
- Develop complex workflows using Temporal.io, following engineering best practices for reliability, scalability, maintainability and observability
- Build integrations with security products, REST APIs, databases and other internal and external systems
- Create automation capabilities across alert triage, threat intelligence, investigation, enrichment and incident response
- Work with Microsoft Security technologies, including Microsoft Sentinel, Microsoft Defender and Defender XDR, along with their associated telemetry and APIs
- Develop and optimise Kusto Query Language, or KQL, queries for investigation, enrichment, detection and automation use cases
- Design robust business logic capable of handling complex investigation scenarios and operational edge cases
- Partner closely with Cyber Defenders to validate requirements and ensure automation delivers meaningful operational value
- Contribute throughout requirements analysis, technical design, implementation, testing and continuous improvement
- Monitor and improve automation performance, reliability, coverage and its impact on analyst workload
- Help shape the evolution of Ontinue’s SOC automation architecture and engineering standards
- Identify high-value automation opportunities arising from genuine SOC operational challenges
- Translate cybersecurity requirements into clear, actionable technical designs
- Deliver reliable automation quickly and iteratively, improving solutions through feedback from SOC users
- Build workflows that are scalable, resilient, maintainable and observable
- Understand the security context behind each automation use case rather than simply implementing technical requirements to increase automation coverage, improve investigation quality and measurably reduce manual analyst workload
- Collaborate effectively across SOC, Engineering, Product, AI and Platform teams
Skills
- At least three years of professional experience in software engineering, cybersecurity, security operations or automation engineering
- Hands-on software development experience, including coding, API integrations, data processing, error handling and asynchronous programming
- A solid understanding of SOC operations, including alert triage, incident investigation, enrichment, threat intelligence and response
- Experience with the Microsoft Security ecosystem, preferably including Microsoft Sentinel and Microsoft Defender
- Strong KQL skills and the ability to develop queries supporting security investigations and automation
- Experience with Git and modern software development practices, including testing, debugging, code reviews and CI/CD
- An understanding of distributed systems, asynchronous processing, workflow orchestration and scalable automation architectures
- Experience developing automation for Microsoft Sentinel, Microsoft Defender for Endpoint, Defender XDR or associated Microsoft Security products
- Experience developing production automation workflows, ideally using Temporal.io or a comparable workflow orchestration frameworks
- Experience integrating REST APIs and working with authentication, JSON, webhooks and external services and cybersecurity APIs or threat intelligence platforms
- Knowledge of common attack techniques and frameworks, including MITRE ATT&CK
Qualifications
Must Haves
- At least three years of professional experience in software engineering, cybersecurity, security operations or automation engineering
- Hands-on software development experience, including coding, API integrations, data processing, error handling and asynchronous programming
- A solid understanding of SOC operations, including alert triage, incident investigation, enrichment, threat intelligence and response
- Experience with the Microsoft Security ecosystem, preferably including Microsoft Sentinel and Microsoft Defender
- Strong KQL skills and the ability to develop queries supporting security investigations and automation
- Experience with Git and modern software development practices, including testing, debugging, code reviews and CI/CD
- An understanding of distributed systems, asynchronous processing, workflow orchestration and scalable automation architectures
Nice to Haves
- Experience developing automation for Microsoft Sentinel, Microsoft Defender for Endpoint, Defender XDR or associated Microsoft Security products
- Experience developing production automation workflows, ideally using Temporal.io or a comparable workflow orchestration frameworks
- Experience integrating REST APIs and working with authentication, JSON, webhooks and external services and cybersecurity APIs or threat intelligence platforms
- Knowledge of common attack techniques and frameworks, including MITRE ATT&CK