SOC Automation Engineer

Phoenix Software

Pocklington

On-site

GBP 65,000 - 90,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid working
SC clearance support

Job summary

Phoenix Software in the United Kingdom is hiring a SOC Automation Engineer to join our Security Operations Centre and advance our managed security services. This hands-on role designs, develops and maintains security automation workflows, builds integrations with SIEM, SOAR, EDR and cloud platforms, and collaborates with SOC Analysts and service owners to automate investigations and improve customer outcomes.

Hybrid working is supported.

Qualifications

  • Experience designing and implementing security automation solutions.
  • Strong software development or automation engineering background.
  • Experience with Python, JavaScript or similar scripting and development languages.
  • Good understanding of REST APIs and systems integration.
  • Experience in Security Operations, Incident Response, Threat Engineering or Security Engineering.
  • Knowledge of SIEM, SOAR, EDR, IAM and vulnerability management.
  • Cloud security knowledge and cloud-based platforms.
  • Awareness of AI technologies in security operations.
  • Excellent communication and documentation abilities.

Responsibilities

  • Design, develop and maintain security automation workflows to support SOC operations.
  • Create and optimise automated playbooks for detection, triage, enrichment and response.
  • Collaborate with SOC, engineering and service delivery teams to deliver automation solutions.
  • Build and maintain integrations with security technologies including SIEM, SOAR, EDR and cloud platforms.
  • Leverage APIs and external data sources to enhance security workflows.
  • Explore and implement AI-enhanced automation capabilities where appropriate.
  • Develop reusable automation components deployable across customer environments.
  • Produce and maintain technical documentation and runbooks.
  • Monitor performance and reliability of automation solutions; drive improvements.
  • Support knowledge sharing and training within the SOC team.
  • Contribute to automation standards and best practices.

Skills

Security automation
Automation engineering
Python/JavaScript
REST APIs
Troubleshooting
Communication

Tools

Swimlane
Cortex XSOAR
Tines
SOAR integrations

Job description

Phoenix enables digital transformation across the UK public sector, empowering organisations to innovate with cloud and hybrid infrastructures, data, AI, security and collaboration technologies.

We are now hiring a SOC Automation Engineer to join our Security Operations Centre team and support the continued development of our managed security services.

This is a hands-on technical role focused on designing, developing and enhancing security automation solutions that improve the effectiveness, efficiency and scalability of SOC operations. Working closely with SOC Analysts, Incident Responders and Service Owners, you will help automate security processes, streamline investigations and improve customer outcomes through intelligent automation and orchestration.

What will you be doing?
  • Design, develop and maintain security automation workflows to support SOC operations.
  • Create and optimise automated playbooks that improve detection, triage, enrichment and response activities.
  • Work closely with SOC, engineering and service delivery teams to understand operational requirements and deliver automation solutions.
  • Build and maintain integrations with security technologies including SIEM, SOAR, EDR, threat intelligence and cloud platforms.
  • Leverage APIs and external data sources to enhance security workflows and processes.
  • Explore and implement AI-enhanced automation capabilities where appropriate.
  • Develop reusable automation components and assets that can be deployed across multiple customer environments.
  • Produce and maintain technical documentation, workflow diagrams, implementation guides and operational runbooks.
  • Monitor the performance and reliability of automation solutions and implement continuous improvements.
  • Support knowledge sharing and training activities across the SOC team.
  • Contribute to the ongoing development of automation standards and best practices.
What are we looking for?
  • Experience designing and implementing security automation solutions.
  • Strong software development or automation engineering background.
  • Experience with Python, JavaScript or similar scripting and development languages.
  • Good understanding of REST APIs and systems integration.
  • Experience working within a Security Operations, Incident Response, Threat Engineering or Security Engineering environment.
  • Understanding of modern security technologies including SIEM, SOAR, EDR, IAM, threat intelligence and vulnerability management solutions.
  • Knowledge of cloud security and cloud-based platforms.
  • Awareness of AI technologies and their practical application within security operations.
  • Strong troubleshooting and problem-solving skills.
  • Excellent communication and technical documentation abilities.
  • Ability to work independently while collaborating effectively across multiple teams.
Experience & Qualifications
  • Minimum of 3 years' experience within a SOC, Security Engineering, Incident Response or related environment.
  • Minimum of 2 years' experience developing or maintaining security automations.
  • Experience working with SOAR technologies such as Swimlane, Cortex XSOAR, Tines or similar platforms.
  • Experience integrating enterprise security technologies into automated workflows.
  • Experience working within Managed Security Services (MSSP) environments desirable.
  • Experience delivering automation projects from design through to implementation and support.

Certifications (desirable):

  • Swimlane Certified SOAR Administrator (SCSA) or Swimlane Certified SOAR Developer (SCSD).
  • Azure, AWS or GCP cloud certifications.
  • Kubernetes certifications such as CKA or CKAD.
  • Python, DevOps or API development certifications.
Practical stuff

Where is the role based? Primary location is our HQ in Pocklington (YO42).

What about hybrid/remote working? Hybrid working is supported, with flexibility depending on business and customer requirements.

How many interviews? Following a screen with the Recruitment Team, you can expect a two-stage interview process — one online and one in-person.

Important Security Clearance

Due to the nature of our customers and the work delivered by our Security Operations Centre, candidates must either hold current SC (Security Check) clearance or be eligible and willing to obtain and maintain it.

Candidates who already hold active SC clearance will be highly advantageous.

Important BPSS Check

As part of our recruitment process and due to the nature of the work we do, all employees are required to undertake a BPSS check. While some employees may require further security clearance, the BPSS check is mandatory and all offers of employment are conditional upon successful completion.

Have you made it this far?

If you're still reading, we think there's a strong chance you might be our kind of person.

Here's the thing, research suggests many women and underrepresented groups don't apply unless they meet every requirement. Even if you don't tick every box above, we encourage you to introduce yourself.

We believe a diversity of perspectives and experiences makes a team stronger, and the stronger our team, the more successful we will be.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Analyst (Shift Based)
SOC Analyst (Shift Based)

Phoenix Software • Pocklington

Hybrid
GBP 25,000 - 35,000
Security Automation & AI SOC Engineer
Security Automation & AI SOC Engineer

Pontoon • Greater London

Hybrid
GBP 83,000 - 138,000
Senior SOC Analyst - Manchester
Senior SOC Analyst - Manchester

BAE Systems Digital Intelligence • Manchester

Hybrid
GBP 60,000 - 90,000
£5,000 referral bonus
Hybrid working
Senior SOC Analyst - Manchester
Senior SOC Analyst - Manchester

Cyber Security training courses • Manchester

Hybrid
GBP 60,000 - 95,000
Referral bonus £5,000
SecOps Engineer
SecOps Engineer

Manchester Arndale • Greater London

Hybrid
GBP 60,000 - 90,000
SOC Engineer
SOC Engineer

SPECTRUM IT • Milton Keynes

On-site
GBP 27,000 - 45,000
Senior Security Engineer
Senior Security Engineer

Made Tech Limited • Bristol

On-site
GBP 55,000 - 75,000
30 days Holiday
Flexible Working Hours
Flexible Parental Leave
+2
Lead Security Analyst
Lead Security Analyst

Made Tech Limited • Bristol

On-site
GBP 65,000 - 80,000
30 days Holiday
Flexible Working Hours
Remote Working – part-time
+5
SOC Engineer
SOC Engineer

Proactive.IT Appointments Ltd. • Milton Keynes

On-site
GBP 55,000 - 85,000
Security clearance sponsorship
Exposure to diverse customer envs
Lead Security Operations Center Analyst (f/m/d)
Lead Security Operations Center Analyst (f/m/d)

Thinkproject • Reading

Hybrid
GBP 65,000 - 85,000
Lunch & Learn Sessions
Hybrid working
Unlimited learning