At a Glance
- Tasks: Design and optimise automation workflows to enhance SOC services and incident response.
- Company: Join a leading cybersecurity firm focused on innovation and collaboration.
- Benefits: Competitive salary, flexible working options, and opportunities for professional growth.
- Other info: Dynamic team environment with excellent career advancement opportunities.
- Why this job: Make a real impact in cybersecurity by streamlining processes and improving efficiency.
- Qualifications: 2+ years in SOC or automation, strong scripting skills, and experience with SIEM or SOAR platforms.
The predicted salary is between 50000 - 65000 £ per year.
As a SOC Automation Engineer, you will apply hands-on engineering expertise to design, build, and optimise automation workflows that improve the scalability and efficiency of SOC services. Working across SIEM, endpoint, and orchestration platforms (primarily Palo Alto XSOAR), you will reduce analyst workload, accelerate incident response, and enhance decision-making across customer environments.
Key Responsibilities
- Automation Development - Design, build, and maintain scalable automation workflows across detection and response platforms.
- Integration & Orchestration - Deliver cross-platform automation enabling fast, reliable response actions.
- Lifecycle Management - Develop, deploy, and continuously optimise automation for performance, resilience, and coverage.
- Collaboration & Requirements Gathering - Work with SOC and engineering teams to identify automation opportunities.
- Documentation - Produce clear documentation to support delivery, troubleshooting, and continuous improvement.
- Automation Planning - Contribute to automation roadmaps, threat modelling, and use case development.
- Pre-Sales Support - Assist with demos, scoping, and proof-of-value activities where required.
Core Duties
- Automation Design & Development - Build and maintain workflows across SIEM, EDR, and SOAR platforms; develop reusable scripts, templates, and components; ensure solutions support secure, multi-tenant environments.
- Integration & Response Automation - Orchestrate containment, enrichment, and remediation actions; integrate with threat intelligence, cloud, vulnerability, and reporting tools; partner with analysts to map and automate response processes.
- Lifecycle Management & Optimisation - Manage automation from design through to optimisation; troubleshoot failures and refine logic; use post-incident insights to improve workflows.
- Documentation & Standards - Maintain clear documentation of workflows, dependencies, and error handling; ensure consistency and usability for wider teams.
- Strategic Contribution - Support use cases aligned to threat modelling and MITRE ATT&CK; contribute to automation playbooks and response strategies; stay current with tools, frameworks, and emerging threats.
- Collaboration - Embed automation into SOC workflows; share best practices and support team development.
- Pre-Sales - Support workshops, onboarding, and solution design where needed.
Stakeholder Collaboration
- SOC Analysts - Automate repeatable triage and response activities.
- Platform & Detection Engineers - Integrate automation into tooling and detections.
- Sales & Pre-Sales - Provide technical input for customer solutions.
Requirements
- 2+ years' experience in SOC, automation, or cloud security engineering.
- Experience in managed services or multi-tenant environments.
- Strong experience building automations across SIEM, SOAR, or EDR platforms.
- Proficiency in scripting (e.g., Python, PowerShell).
- Experience working with APIs, webhooks, and authentication methods.
- Knowledge of threat frameworks (e.g., MITRE ATT&CK).
- Understanding of cloud security, identity, and event-driven automation.
- Strong communication and analytical skills.
- Security clearance (NPPV and/or SC) may be required.
Technical Knowledge
- Security orchestration and automation principles.
- Scripting and integration patterns (APIs, webhooks).
- SOC detection and response workflows.
- Threat intelligence integration and use case design.
- Cloud and identity security concepts.
- Multi-tenant automation design.
Certifications
- Essential: Hands-on experience with Palo Alto XSOAR.
- Desirable: Palo Alto Networks Certified XSOAR Engineer; Palo Alto Networks Certified Security Automation Engineer (PCSAE); Palo Alto Networks Security Operations Professional.
SOC Automation Engineer in Leeds employer: Adzuna
As a leading employer in the cybersecurity sector, we offer SOC Automation Engineers a dynamic work environment that fosters innovation and collaboration. Our commitment to employee growth is evident through continuous training opportunities and a culture that encourages knowledge sharing and teamwork. Located in a vibrant tech hub, we provide competitive benefits and a supportive atmosphere that empowers our engineers to excel in their roles while making a meaningful impact on our clients' security operations.
StudySmarter Expert Advice🤫
We think this is how you could land SOC Automation Engineer in Leeds
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend meetups, and connect with SOC professionals on LinkedIn. You never know who might have the inside scoop on job openings or can refer you directly.
✨Tip Number 2
Show off your skills! Create a portfolio showcasing your automation projects, scripts, or any relevant work. This gives potential employers a tangible look at what you can do, especially in areas like SIEM and SOAR.
✨Tip Number 3
Prepare for interviews by brushing up on common SOC scenarios and automation challenges. Be ready to discuss how you've tackled similar issues in the past and how you can bring value to their team.
✨Tip Number 4
Don't forget to apply through our website! We love seeing candidates who are genuinely interested in joining us. Plus, it’s a great way to ensure your application gets the attention it deserves.
We think you need these skills to ace SOC Automation Engineer in Leeds
Some tips for your application 🫡
Show Off Your Skills:When you're writing your application, make sure to highlight your hands-on experience with automation workflows and any relevant tools like Palo Alto XSOAR. We want to see how your skills can help us improve our SOC services!
Be Clear and Concise:Keep your application straightforward and to the point. Use clear language to describe your past experiences and how they relate to the role. We appreciate a well-structured application that’s easy for us to read!
Tailor Your Application:Make sure to customise your application for the SOC Automation Engineer role. Mention specific projects or achievements that align with the responsibilities listed in the job description. This shows us you’re genuinely interested in joining our team!
Apply Through Our Website:Don’t forget to submit your application through our website! It’s the best way for us to receive your details and ensures you’re considered for the role. We can’t wait to see what you bring to the table!
How to prepare for a job interview at Adzuna
✨Know Your Automation Tools
Make sure you’re well-versed in the tools mentioned in the job description, especially Palo Alto XSOAR. Familiarise yourself with its features and functionalities, as well as any recent updates or best practices. This will show your genuine interest and expertise during the interview.
✨Showcase Your Scripting Skills
Be prepared to discuss your experience with scripting languages like Python and PowerShell. Bring examples of scripts you've written or automations you've built, and be ready to explain how they improved efficiency or solved specific problems in previous roles.
✨Understand SOC Workflows
Brush up on SOC detection and response workflows, and be ready to discuss how automation can enhance these processes. Think about specific scenarios where you’ve implemented automation to reduce analyst workload or accelerate incident response, and share those experiences.
✨Prepare for Collaboration Questions
Since collaboration is key in this role, think of examples where you’ve worked with cross-functional teams. Be ready to discuss how you identified automation opportunities and how you communicated your ideas effectively to both technical and non-technical stakeholders.