SOC Automation Engineer

Company: Claranet
Apply for the SOC Automation Engineer
Location: Leeds
Job Description:

Overview

As a SOC Automation Engineer, you will apply hands‑on engineering expertise to design, build, and optimise automation workflows that improve the scalability and efficiency of SOC services. Working across SIEM, endpoint, and orchestration platforms (primarily Palo Alto XSOAR), you will reduce analyst workload, accelerate incident response, and enhance decision‑making across customer environments.

Key Responsibilities

  • Design, build, and maintain scalable automation workflows across detection and response platforms.
  • Develop, deploy, and continuously optimise automation for performance, resilience, and coverage.
  • Work with SOC and engineering teams to identify automation opportunities.
  • Produce clear documentation to support delivery, troubleshooting, and continuous improvement.

Additional Responsibilities

  • Build and maintain workflows across SIEM, EDR, and SOAR platforms.
  • Develop reusable scripts, templates, and components.
  • Embed automation into SOC workflows.
  • Share best practices and support team development.
  • Support workshops, onboarding, and solution design where needed.
  • Automate repeatable triage and response activities.
  • Integrate automation into tooling and detection workflows.
  • Provide technical input for customer solutions.

Required Experience and Skills

  • 2+ years’ experience in SOC, automation, or cloud security engineering.
  • Experience in managed services or multi‑tenant environments.
  • Strong experience building automations across SIEM, SOAR, or EDR platforms.
  • Proficiency in scripting (Python, PowerShell).
  • Experience working with APIs, webhooks, and authentication methods.
  • Knowledge of threat frameworks (MITRE ATT&CK).
  • Understanding of cloud security, identity, and event‑driven automation.
  • Strong communication and analytical skills.
  • Security clearance (NPPV and/or SC) may be required.

Technical Knowledge

  • Security orchestration and automation principles.
  • Scripting and integration patterns (APIs, webhooks).
  • SOC detection and response workflows.
  • Threat intelligence integration and use case development.

Certifications

  • Palo Alto Networks Certified Security Automation Engineer (PCSAE).
  • Palo Alto Networks Security Operations Professional (SAOP).

#J-18808-Ljbffr…

Posted: May 23rd, 2026