Get more replies from employers
Send a job-specific resume in minutes.
NETS is seeking a seasoned SOC automation specialist to design and implement scalable automation across SIEM, SOAR, and EDR/XDR ecosystems. You will lead data-driven initiatives, build reusable frameworks, and drive governance and documentation to streamline SOC operations.
You will collaborate with Cyber Defence, IT, Cloud, and Data teams to translate security telemetry into actionable insights and dashboards for leadership.
Design and implement automation solutions to eliminate manual, repetitive SOC tasks (alert triage, enrichment, reporting, investigations).
Develop and maintain integrations across SIEM, SOAR, EDR/XDR, ticketing, and threat intelligence platforms.
Build reusable automation frameworks using Python, PowerShell, APIs, and workflow orchestration tools.
Drive use-case automation (auto-enrichment, auto-response, playbooks) to improve SOC efficiency and response time.
Establish automation standards, governance, and documentation.
Design and maintain SOC data pipelines, ensuring reliable ingestion, transformation, and normalization of security telemetry.
Perform data analysis to uncover trends, anomalies, and operational insights.
Ensure data quality, integrity, and consistency across multiple security platforms.
Support advanced analytics, including statistical analysis and basic machine learning use cases (where applicable).
Develop and maintain executive dashboards and visualizations (KPIs, KRIs, SLAs) for SOC performance.
Translate complex security data into clear, actionable insights for senior management.
Automate generation of weekly/monthly SOC reports.
Track metrics such as MTTD, MTTR, alert volumes, false positive rates, and threat trends.
SOC Operations Enablement
Work closely with SOC analysts to identify process inefficiencies and automation opportunities.
Improve triage workflows with automation, enrichment, and contextual data.
Support incident response through data correlation and investigative tooling.
Tooling & Platform Integration
Integrate and optimize tools including:
SIEM (e.g., Elastic, LogRhythm, Solarwinds)
SOAR platforms
EDR/XDR solutions
Leverage APIs and event-driven architectures to enable real-time data flow and orchestration.
Serve as a technical lead and subject matter expert in SOC automation and data analytics.
Mentor SOC engineers and analysts in automation and data literacy.
Collaborate with Cyber Defence, IR, IT, Cloud, and Data teams to align data and automation strategies.
Act as a key contributor in SOC transformation initiatives.
Required Qualifications & Experience
7+ years of experience in logic automation, cybersecurity, data engineering, or SOC Automation roles
At least:
5+ years in SOC automation / security engineering / data analytics
3+ years in a senior or lead technical role
Strong hands-on experience with:
Programming/Scripting: Python (mandatory), PowerShell, Bash, PowerApps, RPA, PowerBI
Experience with:
SIEM platforms (Splunk, Elastic, LogRhythm, Solarwinds)
SOAR platforms and playbook development
Data visualization tools (Power BI, Tableau, Grafana, Kibana)
Understanding of: (Good to have)
SOC operations and workflows
Incident response lifecycle
Security telemetry and log sources
Experience with:
Cloud platforms (AWS, Azure, GCP) and associated logging/monitoring
Automation in cloud-native environments is a plus
Preferred Qualifications
Experience in financial services, banking, or payment systems
Knowledge of:
MITRE ATT&CK framework
Exposure to:
Process Automation,
Data Visualizations for Reports
Machine learning for anomaly detection
Big data platforms (e.g., Spark, Hadoop)
Preferred Certifications
Relevant certifications such as:
GIAC (GCDA, GCIH, GMON) (Good to have)
CISSP / CISM (Good to have)
Microsoft Security / Azure certifications
Splunk or SIEM-related certifications (Good to have)
Automations, Data/analytics certifications (optional but advantageous)
Focus on automation, scalability, and continuous improvement
Problem-solving and analytical thinking
Ability to translate data into business insights
Strong stakeholder communication (technical + management)
Leadership and mentoring capability
What Success Looks Like
Significant reduction in manual SOC workload through automation
Improved MTTD/MTTR and analyst productivity
High-quality, reliable SOC dashboards and reporting for leadership
Strong data-driven decision-making culture within SOC
Scalable and maintainable automation frameworks and pipelines