
SOC Automation Engineer
Posted 16 hours ago

Posted 16 hours ago
This is a fully remote position, open to applicants in United States.
• Design, develop, and maintain Python-based automation workflows that support security investigations, alert triage, enrichment, incident handling, and response.
• Convert operational requirements and SOC analyst challenges into scalable automation use cases.
• Create intricate workflows utilizing Temporal.io.
• Establish integrations with security products, REST APIs, databases, and both internal and external systems.
• Implement automation capabilities across alert triage, threat intelligence, investigation, enrichment, and incident response.
• Collaborate with Microsoft Sentinel, Microsoft Defender, and Defender XDR, including their associated telemetry and APIs.
• Develop and optimize Kusto Query Language (KQL) queries for investigation, enrichment, detection, and automation.
• Design resilient business logic for complex investigation scenarios and operational edge cases.
• Work alongside Cyber Defenders to validate requirements and ensure that automation provides operational value.
• Contribute to requirements analysis, technical design, implementation, testing, and continuous improvement efforts.
• Monitor and enhance automation performance, reliability, coverage, and its effect on analyst workload.
• Assist in shaping Ontinue’s SOC automation architecture and engineering standards.
• Collaborate with SOC, Engineering, Product, AI, and Platform teams.
• A minimum of three years of professional experience in software engineering, cybersecurity, security operations, or automation engineering.
• Practical software development experience, including coding, API integrations, data processing, error handling, and asynchronous programming.
• Strong understanding of SOC operations, encompassing alert triage, incident investigation, enrichment, threat intelligence, and response.
• Familiarity with the Microsoft Security ecosystem, preferably including Microsoft Sentinel and Microsoft Defender.
• Proficient in KQL with the capability to develop queries that support security investigations and automation.
• Experience with Git and contemporary software development practices, including testing, debugging, code reviews, and CI/CD.
• Knowledge of distributed systems, asynchronous processing, workflow orchestration, and scalable automation architectures.
• Proven experience in developing automation for Microsoft Sentinel, Microsoft Defender for Endpoint, Defender XDR, or related Microsoft Security products.
• Background in creating production automation workflows, ideally using Temporal.io or similar workflow orchestration frameworks.
• Experience in integrating REST APIs and working with authentication, JSON, webhooks, external services, cybersecurity APIs, or threat intelligence platforms.
• Understanding of common attack techniques and frameworks, including MITRE ATT&CK.
• Remote work arrangement.
• Full-time employment.
nesto
Wabtec Corporation
Wabtec Corporation
Wabtec Corporation
Get handpicked remote jobs straight to your inbox weekly.