Jobs
My ads
My job alerts
Sign in
Find a job Career Tips Companies
Find

Cyber defence automation engineer

West Drayton
IAG Transform
Automation engineer
Posted: 11 July
Offer description

Job Description


Purpose of the role

The purpose of the role is to design, implement, and manage automation solutions within the Security Operations Centre (SOC) to improve the efficiency and effectiveness of security operations.

This role focuses on automating repetitive tasks, optimizing workflows, and integrating tools and systems to enhance threat detection, incident response, and overall SOC performance. The goal is to streamline security operations, reduce manual effort, and accelerate the identification and mitigation of security threats, enabling the SOC team to focus on more complex and critical tasks.



The SOC Automation Engineer is accountable for the following:

- Automation of SOC Processes

Design and implement automation solutions to streamline repetitive tasks such as alert triaging, incident response, and reporting

- Tool Integration

Integrate various security tools (SIEM, SOAR, firewalls, etc.) to improve data flow and response coordination.

- Optimization of Workflows

Enhance and optimize SOC workflows for improved efficiency and reduced manual effort.

- Development of Playbooks

Create automated response playbooks for common security incidents, enabling faster and more consistent incident handling.

- Collaboration with Security Teams

Work closely with SOC analysts and engineers to identify areas for automation and provide technical solutions.

- Monitoring and Maintenance

Ensure the continuous operation and performance of automation tools, resolving issues as they arise.

- Continuous Improvement

Regularly review and update automation scripts and processes to adapt to evolving threats and technologies.

- Documentation

Maintain detailed documentation of automation workflows, playbooks, and configurations.



Key Relationships/Interfaces

External:

* Third-party partners and key solution suppliers

Internal:

* Other areas of IAG Cybersecurity, particularly the cyber programme
* Group Security Team(s)
* Senior managers/customers from across the Group and relevant business areas
* Senior managers/customers/colleagues from operating companies
*

Qualifications


Qualifications

* Bachelor’s degree in, Cybersecurity, Computer Science, Information Technology, or Artificial Intelligence.
* Industry certifications such as:
* Certified Information Systems Security Professional (CISSP)
* Certified Incident Handler (GCIH)
* GIAC Security Automation Expert (GCSA)
* Splunk Certified Automation Consultant, or relevant SOAR certifications.
* Experience with automation tools (e.g., SOAR platforms, Ansible, Phantom or similar).
* Proficiency in scripting languages (e.g., Python, PowerShell, Bash).
* Strong understanding of SOC processes, including incident response and threat detection.
* Experience with SIEM platforms (e.g., Splunk).
* Knowledge of security frameworks (e.g., NIST, MITRE ATT&CK).

Skills

* Proficiency in automation tools (e.g., SOAR platforms, Ansible, Phantom).
* Expertise in scripting languages (e.g., Python, PowerShell, Bash).
* Strong knowledge of SOC processes (incident response, threat detection).
* Experience with SIEM platforms (e.g., Splunk).
* Ability to integrate and automate security tools with AI / ML capabilities.
* Strong problem-solving and analytical skills.
* Experience in developing automated workflows and playbooks.
* Knowledge of security frameworks (e.g., MITRE ATT&CK, NIST).
* Strong collaboration and communication skills.
* Experience with log management and event correlation automation.

Experience

* 3-5 years of experience in SOC or cybersecurity roles.
* Hands-on experience with automation tools (e.g., SOAR, Ansible, Phantom, Demisto).
* Experience with scripting languages (e.g., Python, PowerShell, Bash) for automation.
* Experience integrating and automating security tools and processes.
* Strong background in SOC operations, incident response, and threat detection.
* Experience with SIEM platforms (e.g., Splunk, QRadar, ArcSight).
* Experience developing and managing automated response workflows.
* Familiarity with security frameworks like MITRE ATT&CK or NIST.
* Experience working with security log management and event correlation tools.

Apply
Create E-mail Alert
Job alert activated
Saved
Save
Similar job
Electrical and automation engineer
London
American Bureau of Shipping
Automation engineer
Similar job
Qa automation engineer
London
CW Talent Solutions
Automation engineer
Similar job
Senior qa automation engineer
London
SPD Technology
Automation engineer
See more jobs
Similar jobs
Engineering jobs in West Drayton
jobs West Drayton
jobs Greater London
jobs England
Home > Jobs > Engineering jobs > Automation engineer jobs > Automation engineer jobs in West Drayton > Cyber Defence Automation Engineer

About Jobijoba

  • Career Advice
  • Company Reviews

Search for jobs

  • Jobs by Job Title
  • Jobs by Industry
  • Jobs by Company
  • Jobs by Location
  • Jobs by Keywords

Contact / Partnership

  • Contact
  • Publish your job offers on Jobijoba

Legal notice - Terms of Service - Privacy Policy - Manage my cookies - Accessibility: Not compliant

© 2025 Jobijoba - All Rights Reserved

Apply
Create E-mail Alert
Job alert activated
Saved
Save