Ontinue

SOC Automation Engineer

Ontinue
Apply
6 days ago
Remote, WorldwideMid Level

Responsibilities

  • Design, develop, and maintain Python-based automation workflows for security investigation, alert triage, enrichment, incident handling, and response.
  • Develop complex, reliable, scalable, maintainable, and observable workflows using Temporal.io.
  • Integrate security products, APIs, databases, and internal and external systems.
  • Work with Microsoft Sentinel, Microsoft Defender, Defender XDR, and associated telemetry and APIs.
  • Develop and optimize Kusto Query Language queries for investigations, enrichment, detection, and automation.
  • Translate SOC analyst pain points and cybersecurity requirements into actionable automation designs.
  • Partner with Cyber Defenders and cross-functional SOC, Engineering, Product, AI, and Platform teams.
  • Contribute to requirements analysis, technical design, implementation, testing, monitoring, and continuous improvement.
  • Improve automation performance, reliability, coverage, and impact on analyst workload.

Requirements

  • At least three years of professional experience in software engineering, cybersecurity, security operations, or automation engineering.
  • Hands-on software development experience with coding, API integrations, data processing, error handling, and asynchronous programming.
  • Solid understanding of SOC operations, including alert triage, incident investigation, enrichment, threat intelligence, and response.
  • Experience with the Microsoft Security ecosystem, preferably including Microsoft Sentinel and Microsoft Defender.
  • Strong Kusto Query Language skills for security investigation and automation queries.
  • Experience with Git and modern development practices including testing, debugging, code reviews, and CI/CD.
  • Understanding of distributed systems, asynchronous processing, workflow orchestration, and scalable automation architectures.
  • Preferred experience developing automation for Microsoft Sentinel, Microsoft Defender for Endpoint, Defender XDR, or related Microsoft Security products.
  • Preferred experience developing production workflows with Temporal.io or a comparable workflow orchestration framework.
  • Preferred experience integrating APIs and working with authentication, JSON, webhooks, external services, cybersecurity APIs, or threat intelligence platforms.
  • Knowledge of common attack techniques and frameworks, including MITRE ATT&CK.

Tech Stack

Categories

Ontinue

About Ontinue

201-500 employees
Contact me