SOC Automation Engineer

Claranet
Ls11Az, LS1 1AZ, United Kingdom
2 weeks ago
Job Type
Permanent
Work Pattern
Full-time
Work Location
On-site
Seniority
Mid
Education
Degree
Security Clearance
Required
Posted
19 May 2026 (2 weeks ago)

Benefits

Security clearance

SOC Automation Engineer

As a SOC Automation Engineer, you will apply hands-on engineering expertise to design, build, and optimise automation workflows that improve the scalability and efficiency of SOC services. Working across SIEM, endpoint, and orchestration platforms (primarily Palo Alto XSOAR), you will reduce analyst workload, accelerate incident response, and enhance decision-making across customer environments.

Key Responsibilities
  • Automation Development – Design, build, and maintain scalable automation workflows across detection and response platforms.
  • Integration & Orchestration – Deliver cross-platform automation enabling fast, reliable response actions.
  • Lifecycle Management – Develop, deploy, and continuously optimise automation for performance, resilience, and coverage.
  • Collaboration & Requirements Gathering – Work with SOC and engineering teams to identify automation opportunities.
  • Documentation – Produce clear documentation to support delivery, troubleshooting, and continuous improvement.
  • Automation Planning – Contribute to automation roadmaps, threat modelling, and use case development.
  • Pre-Sales Support – Assist with demos, scoping, and proof-of-value activities where required.
Core Duties

Automation Design & Development

  • Build and maintain workflows across SIEM, EDR, and SOAR platforms
  • Develop reusable scripts, templates, and components
  • Ensure solutions support secure, multi-tenant environments

Integration & Response Automation

  • Orchestrate containment, enrichment, and remediation actions
  • Integrate with threat intelligence, cloud, vulnerability, and reporting tools
  • Partner with analysts to map and automate response processes

Lifecycle Management & Optimisation

  • Manage automation from design through to optimisation
  • Troubleshoot failures and refine logic
  • Use post-incident insights to improve workflows

Documentation & Standards

  • Maintain clear documentation of workflows, dependencies, and error handling
  • Ensure consistency and usability for wider teams

Strategic Contribution

  • Support use cases aligned to threat modelling and MITRE ATT&CK
  • Contribute to automation playbooks and response strategies
  • Stay current with tools, frameworks, and emerging threats

Collaboration

  • Embed automation into SOC workflows
  • Share best practices and support team development

Pre-Sales

  • Support workshops, onboarding, and solution design where needed
Stakeholder Collaboration
  • SOC Analysts – Automate repeatable triage and response activities
  • Platform & Detection Engineers – Integrate automation into tooling and detections
  • Sales & Pre-Sales – Provide technical input for customer solutions
Requirements
  • 2+ years’ experience in SOC, automation, or cloud security engineering
  • Experience in managed services or multi-tenant environments
  • Strong experience building automations across SIEM, SOAR, or EDR platforms
  • Proficiency in scripting (e.g., Python, PowerShell)
  • Experience working with APIs, webhooks, and authentication methods
  • Knowledge of threat frameworks (e.g., MITRE ATT&CK)
  • Understanding of cloud security, identity, and event-driven automation
  • Strong communication and analytical skills

Security clearance (NPPV and/or SC) may be required.

Technical Knowledge
  • Security orchestration and automation principles
  • Scripting and integration patterns (APIs, webhooks)
  • SOC detection and response workflows
  • Threat intelligence integration and use case design
  • Cloud and identity security concepts
  • Multi-tenant automation design
Certifications

Essential:

  • Hands-on experience with Palo Alto XSOAR

Desirable:

  • Palo Alto Networks Certified XSOAR Engineer
  • Palo Alto Networks Certified Security Automation Engineer (PCSAE)
  • Palo Alto Networks Security Operations Professional

Related Jobs

View all jobs

Automation Engineer II, Falcon Complete

CrowdStrike United Kingdom
Remote

Threat Detection Engineer

Additional Resources London, United Kingdom
£60,000 – £80,000 pa Hybrid

Threat Detection Engineer

Additional Resources Wc1A2Sl, WC1A 2SL, United Kingdom
£60,000 – £80,000 pa Hybrid

SOC Engineer - DV cleared

CBSbutler Holdings Limited trading as CBSbutler Hemel Hempstead, Hertfordshire, HP1 1EW, United Kingdom
£500 – £700 pd On-site Clearance Required

SOC Engineering Lead

FlexIT Talent Solutions Ltd United Kingdom
£70,000 – £75,000 pa Remote Clearance Required

SOC Engineer - Cyber

Proprec B112Aa, B11 2AA, United Kingdom
£45,000 – £50,000 pa Hybrid

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Where to Advertise Cloud Computing Jobs in the UK (2026 Guide)

Where to advertise cloud computing jobs UK in 2026: the specialist boards and channels that reach AWS, Azure, GCP and cloud-native engineering talent. The candidate pool is large relative to other deep tech disciplines but highly segmented — cloud architects, DevOps engineers, platform engineers, FinOps specialists and cloud security professionals each occupy distinct communities with different job search behaviours, certification profiles and salary expectations. General job boards reach a broad audience but struggle to differentiate between these disciplines, producing high application volumes but low candidate quality for specialist cloud roles. This guide, published by CloudComputingJobs.co.uk, covers where to advertise cloud computing roles in the UK in 2026, how the main platforms compare, what employers should expect to pay, and what the data says about hiring across different role types.

Cloud Computing Jobs UK 2026: What to Expect Over the Next 3 Years

Cloud Computing Jobs UK 2026: salaries, hiring trends and the AWS, Azure and GCP skills shaping UK cloud careers over the next three years. Cloud computing is the infrastructure layer on which the modern digital economy runs — and the jobs market that has grown around it is one of the largest, most sustained, and most structurally resilient in the entire technology sector. But the cloud computing jobs market of 2026 looks quite different from the one that existed three years ago, and the next three years will bring further change at a pace that rewards those who understand the direction of travel. The migration phase that defined cloud hiring for much of the previous decade is largely complete for enterprise organisations. The question for most UK businesses is no longer whether to move to the cloud but how to operate, optimise, and secure what they have already built there — and how to integrate the wave of AI capability that is now being delivered primarily through cloud infrastructure. That shift has profound implications for which cloud skills are in demand, which roles are growing, and which are beginning to plateau. At the same time, new architectural patterns — multi-cloud, cloud-native, serverless, and the growing integration of edge computing with centralised cloud infrastructure — are creating entirely new categories of specialist expertise that employers are actively competing to hire. The cloud computing jobs market of 2026 is not contracting. It is evolving, and evolving in ways that create significant opportunity for job seekers who are building the right skills. This article breaks down what the UK cloud computing jobs market is likely to look like through to 2028 — covering the titles emerging right now, the technologies driving employer demand, the skills that will matter most, and how to position your career ahead of the curve.