SOC Automation Engineer

Ontinue

Northern (KY)

Hybrid

USD 90,000 - 120,000

Full time

8 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Ontinue is seeking a SOC Automation Engineer to design, develop and maintain Python-based automation workflows that enhance security investigations and incident response. You will work at the intersection of cybersecurity, software engineering and automation to scale a 24/7 Security Operations Centre.

Join a team building end-to-end automation, with a focus on reliability, observability and measurable impact on analyst workload.

Qualifications

  • At least three years of professional experience in software engineering, cybersecurity, security operations or automation engineering.
  • Hands-on software development experience, including coding, API integrations, data processing, error handling and asynchronous programming.
  • A solid understanding of SOC operations, including alert triage, incident investigation, enrichment, threat intelligence and response.
  • Experience with the Microsoft Security ecosystem, preferably including Microsoft Sentinel and Microsoft Defender.
  • Strong KQL skills and the ability to develop queries supporting security investigations and automation.

Responsibilities

  • Design, develop and maintain Python-based automation workflows supporting security investigation, alert triage, enrichment, incident handling and response.
  • Translate operational requirements and SOC analyst pain points into clearly defined, scalable automation use cases.
  • Develop complex workflows using Temporal.io, following engineering best practices for reliability, scalability, maintainability and observability.
  • Build integrations with security products, REST APIs, databases and other internal and external systems.
  • Create automation capabilities across alert triage, threat intelligence, investigation, enrichment and incident response.
  • Work with Microsoft Security technologies, including Microsoft Sentinel, Microsoft Defender and Defender XDR, along with their associated telemetry and APIs.
  • Develop and optimise Kusto Query Language, or KQL, queries for investigation, enrichment, detection and automation use cases.
  • Design robust business logic capable of handling complex investigation scenarios and operational edge cases.
  • Partner closely with Cyber Defenders to validate requirements and ensure automation delivers meaningful operational value.
  • Contribute throughout requirements analysis, technical design, implementation, testing and continuous improvement.
  • Monitor and improve automation performance, reliability, coverage and its impact on analyst workload.
  • Help shape the evolution of Ontinue’s SOC automation architecture and engineering standards.

Skills

Software engineering
Automation engineering
Cybersecurity
API integrations
Asynchronous programming
KQL queries

Tools

Temporal.io
Microsoft Sentinel
Microsoft Defender
Git

Job description

As a leading provider of AI-powered extended managed detection and response (MXDR) services, Ontinue is on a mission to be the most trusted, 24/7, always-on security partner that empowers customers to embrace the future by using AI to operate more strategically, at scale, and with less risk. We believe that the combination of AI and human expertise is essential for delivering effective managed security that is tailored to a customer’s unique environment, operational constraints, and risks.

Continuous protection. AI-powered Nonstop SecOps. That’s Ontinue.

Role Overview

As a SOC Automation Engineer, you will help transform how our Cyber Defenders investigate and respond to security incidents.

Working at the intersection of cybersecurity, software engineering and automation, you will design, develop and maintain Python-based solutions that reduce manual effort, improve investigation quality and enable our global, 24/7 Security Operations Centre to operate effectively at scale.

Key Responsibilities
  • Design, develop and maintain Python-based automation workflows supporting security investigation, alert triage, enrichment, incident handling and response
  • Translate operational requirements and SOC analyst pain points into clearly defined, scalable automation use cases
  • Develop complex workflows using Temporal.io, following engineering best practices for reliability, scalability, maintainability and observability
  • Build integrations with security products, REST APIs, databases and other internal and external systems.
  • Create automation capabilities across alert triage, threat intelligence, investigation, enrichment and incident response
  • Work with Microsoft Security technologies, including Microsoft Sentinel, Microsoft Defender and Defender XDR, along with their associated telemetry and APIs
  • Develop and optimise Kusto Query Language, or KQL, queries for investigation, enrichment, detection and automation use cases
  • Design robust business logic capable of handling complex investigation scenarios and operational edge cases.
  • Partner closely with Cyber Defenders to validate requirements and ensure automation delivers meaningful operational value
  • Contribute throughout requirements analysis, technical design, implementation, testing and continuous improvement
  • Monitor and improve automation performance, reliability, coverage and its impact on analyst workload.
  • Help shape the evolution of Ontinue’s SOC automation architecture and engineering standards
What Success Looks Like
  • Identify high-value automation opportunities arising from genuine SOC operational challenges.
  • Translate cybersecurity requirements into clear, actionable technical designs
  • Deliver reliable automation quickly and iteratively, improving solutions through feedback from SOC users
  • Build workflows that are scalable, resilient, maintainable and observable
  • Understand the security context behind each automation use case rather than simply implementing technical requirements to increase automation coverage, improve investigation quality and measurably reduce manual analyst workload.
  • Collaborate effectively across SOC, Engineering, Product, AI and Platform teams
Required Experience & Skills
  • At least three years of professional experience in software engineering, cybersecurity, security operations or automation engineering
  • Hands-on software development experience, including coding, API integrations, data processing, error handling and asynchronous programming
  • A solid understanding of SOC operations, including alert triage, incident investigation, enrichment, threat intelligence and response
  • Experience with the Microsoft Security ecosystem, preferably including Microsoft Sentinel and Microsoft Defender
  • Strong KQL skills and the ability to develop queries supporting security investigations and automation
  • Experience with Git and modern software development practices, including testing, debugging, code reviews and CI/CD
  • An understanding of distributed systems, asynchronous processing, workflow orchestration and scalable automation architectures
Preferred
  • Experience developing automation for Microsoft Sentinel, Microsoft Defender for Endpoint, Defender XDR or associated Microsoft Security products
  • Experience developing production automation workflows, ideally using Temporal.io or a comparable workflow orchestration frameworks
  • Experience integrating REST APIs and working with authentication, JSON, webhooks and external services and cybersecurity APIs or threat intelligence platforms
  • Knowledge of common attack techniques and frameworks, including MITRE ATT&CK

Learn more: www.ontinue.com

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Automation Engineer — AI-Powered SecOps
SOC Automation Engineer — AI-Powered SecOps

Ontinue • Northern (KY)

Hybrid
USD 90,000 - 120,000
Sr. Automation & Cybersecurity Engineer
Sr. Automation & Cybersecurity Engineer

Actus Consulting Group • Plano (TX)

On-site
USD 120,000 - 180,000
SOC Automation Engineer
SOC Automation Engineer

Bitdefender • United States

On-site
USD 70,000 - 100,000
Senior Automation & Cybersecurity Engineer
Senior Automation & Cybersecurity Engineer

Cinter Career Services, LLC • Plano (TX)

On-site
USD 130,000 - 180,000
Sr. Automation & Cybersecurity Engineer
Sr. Automation & Cybersecurity Engineer

Toyota Tsusho Systems • Plano (TX)

On-site
USD 130,000 - 170,000
Sr. Automation & Cybersecurity Engineer
Sr. Automation & Cybersecurity Engineer

Toyota Tsusho Systems US, Inc. • Plano (TX)

On-site
USD 120,000 - 180,000
Senior Automation & Cybersecurity Engineer
Senior Automation & Cybersecurity Engineer

Cinter Career • Plano (TX)

On-site
USD 140,000 - 190,000
SOC Engineer
SOC Engineer

TENEX.AI • Sarasota (FL)

On-site
USD 90,000 - 120,000
SOC Engineer
SOC Engineer

TENEX.AI • Overland Park (KS)

On-site
USD 100,000 - 130,000
Sr. Automation & Cybersecurity Engineer
Sr. Automation & Cybersecurity Engineer

Toyota Tsusho Systems Corporation • Plano (TX)

On-site
USD 120,000 - 180,000