About this role
As a leading provider of AI-powered extended managed detection and response (MXDR) services, Ontinue is on a mission to be the most trusted, 24/7, always-on security partner that empowers customers to embrace the future by using AI to operate more strategically, at scale, and with less risk. We believe that the combination of AI and human expertise is essential for delivering effective managed security that is tailored to a customer’s unique environment, operational constraints, and risks.
Continuous protection. AI-powered Nonstop SecOps. That’s Ontinue.
Role Overview
As a SOC Automation Engineer, you will help transform how our Cyber Defenders investigate and respond to security incidents.
Working at the intersection of cybersecurity, software engineering and automation, you will design, develop and maintain Python-based solutions that reduce manual effort, improve investigation quality and enable our global, 24/7 Security Operations Centre to operate effectively at scale.
Key Responsibilities
• Design, develop and maintain Python-based automation workflows supporting security investigation, alert triage, enrichment, incident handling and response
• Translate operational requirements and SOC analyst pain points into clearly defined, scalable automation use cases
• Develop complex workflows using Temporal.io, following engineering best practices for reliability, scalability, maintainability and observability
• Build integrations with security products, REST APIs, databases and other internal and external systems.
• Create automation capabilities across alert triage, threat intelligence, investigation, enrichment and incident response
• Work with Microsoft Security technologies, including Microsoft Sentinel, Microsoft Defender and Defender XDR, along with their associated telemetry and APIs
• Develop and optimise Kusto Query Language, or KQL, queries for investigation, enrichment, detection and automation use cases
• Design robust business logic capable of handling complex investigation scenarios and operational edge cases.
• Partner closely with Cyber Defenders to validate requirements and ensure automation delivers meaningful operational value
• Contribute throughout requirements analysis, technical design, implementation, testing and continuous improvement
• Monitor and improve automation performance, reliability, coverage and its impact on analyst workload.
• Help shape the evolution of Ontinue’s SOC automation architecture and engineering standards
What Success Looks Like
• Identify high-value automation opportunities arising from genuine SOC operational challenges.
• Translate cybersecurity requirements into clear, actionable technical designs
• Deliver reliable automation quickly and iteratively, improving solutions through feedback from SOC users
• Build workflows that are scalable, resilient, maintainable and observable
• Understand the security context behind each automation use case rather than simply implementing technical requirements to increase automation coverage, improve investigation quality and measurably reduce manual analyst workload.
• Collaborate effectively across SOC, Engineering, Product, AI and Platform teams
Required Experience & Skills
• At least three years of professional experience in software engineering, cybersecurity, security operations or automation engineering
• Hands-on software development experience, including coding, API integrations, data processing, error handling and asynchronous programming
• A solid understanding of SOC operations, including alert triage, incident investigation, enrichment, threat intelligence and response
• Experience with the Microsoft Security ecosystem, preferably including Microsoft Sentinel and Microsoft Defender
• Strong KQL skills and the ability to develop queries supporting security investigations and automation
• Experience with Git and modern software development practices, including testing, debugging, code reviews and CI/CD
• An understanding of distributed systems, asynchronous processing, workflow orchestration and scalable automation architectures
Preferred
• Experience developing automation for Microsoft Sentinel, Microsoft Defender for Endpoint, Defender XDR or associated Microsoft Security products
• Experience developing production automation workflows, ideally using Temporal.io or a comparable workflow orchestration frameworks
• Experience integrating REST APIs and working with authentication, JSON, webhooks and external services and cybersecurity APIs or threat intelligence platforms
• Knowledge of common attack techniques and frameworks, including MITRE ATT&CK
Next Steps
If you have the skills and experience required and feel that Ontinue is a place you can belong, we would love to get to know you better! Please drop an application to this role and our talent acquisition manager will be in touch to discuss further.
Learn more: www.ontinue.com