Security Automation and AI SOC Engineer

Adecco
London, UK
5 days ago
Apply on www.adecco.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Part-time (≤ 32 hours)
Compensation
£195,000.0
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Automation of Tests Microsoft Azure Cloud Computing Security Collaborative Software Cyber Security Intrusion Detection and Prevention Python (Programming Language) Automation of Marketing Security Information and Event Management
+8 more
Systems Integration Scripting Large Language Models Microsoft Sentinel Cortex XSOAR Platform Virtual Agents Splunk Security Orchestration, Automation & Response

Job description

We are seeking an experienced Security Automation and AI SOC Engineer to help accelerate the evolution of our Security Operations capability through further automation, orchestration and the pragmatic adoption of AI. This role will focus on identifying, designing and implementing automation that reduces manual effort, improves consistency and quality, and enables analysts to spend more time on high-value security activities. The successful candidate will also help shape and deliver our approach to AI within the SOC, ensuring that automation and AI are implemented safely, effectively and with appropriate governance.

The role requires a blend of technical capability, strategic thinking and practical delivery experience. We are looking for someone who has successfully implemented automation and AI within a Security Operations environment and can articulate both the technical implementation and the operating model required for long-term success.

Key Responsibilities

Security Automation:

  • Design, develop and maintain security automation workflows using hyper-automation platforms such as Torq, Tines, Swimlane or similar technologies.
  • Working with the SOC to identify manual, repetitive and time-consuming operational activities suitable for automation.
  • Develop automated triage, enrichment, investigation and response workflows.
  • Improve integration between security tooling, ticketing platforms, asset inventories, identity systems and collaboration platforms.
  • Establish standards, documentation and best practice for automation development.
  • Track and demonstrate measurable efficiency gains through automation.

AI-Enabled Security Operations:

  • Assess opportunities to safely introduce AI into Security Operations workflows.
  • Design and implement AI-assisted investigation, triage and analyst support capabilities.
  • Define governance, quality assurance and human oversight models for AI-enabled security operations.
  • Establish methods to measure AI effectiveness, accuracy, quality and operational benefit.
  • Ensure AI capabilities complement analysts rather than simply replace human activities.
  • Help define the future operating model for analysts working alongside AI agents and automation platforms.

SOC Strategy and Transformation:

  • Develop a roadmap for Security Automation and AI adoption within the SOC.
  • Help identify which activities should remain human-led and which should become automated or AI-assisted.
  • Build frameworks for scaling automation while maintaining operational quality and risk management.
  • Provide recommendations on SOC maturity improvements and operational efficiencies.
  • Engage with security analysts, engineering teams and leadership stakeholders to ensure successful adoption.

Continuous Improvement:

  • Measure automation outcomes and identify opportunities for further optimisation.
  • Support knowledge sharing and capability uplift across the Security Operations team.
  • Contribute to the development of reusable playbooks, templates and investigation patterns.
  • Stay informed on emerging industry practices around Security Automation, AI SOCs and Agentic AI.

Requirements

  • Strong background in Security Operations, Incident Response, Detection Engineering or Security Engineering.
  • Demonstrable experience working within an enterprise SOC environment.
  • Experience improving security operations processes, workflows and analyst effectiveness.

Security Automation:

  • Hands-on experience with security orchestration and automation platforms such as: o Torq o Tines o Swimlane o Cortex XSOAR o Microsoft LogicApps o Similar SOAR / Hyperautomation platforms

Experience developing:

o Automated investigations o Alert enrichment workflows o Response playbooks o Case management integrations o Analyst productivity tooling

AI and Security Operations:

  • Practical experience implementing AI capabilities within a SOC environment.
  • Experience evaluating and deploying AI-assisted investigations, triage, alert analysis or response workflows.
  • Understanding of the opportunities, limitations and risks of AI in Security Operations.
  • Experience implementing quality control, governance and human oversight mechanisms for AI-driven workflows.

Technical Skills

  • Scripting or development experience (Python preferred).
  • Experience integrating security technologies using APIs.
  • Understanding of SIEM, EDR, Identity and Cloud Security technologies.
  • Strong analytical and problem-solving skills.

Desirable Experience

  • Experience designing an AI adoption strategy for a SOC.
  • Experience with agentic AI or autonomous security workflows.
  • Experience with Microsoft Sentinel, Splunk or equivalent SIEM platforms.
  • Experience with cloud security technologies (Azure, GCP or AWS).
  • Experience with detection engineering and security use case development.
  • Experience building automation metrics and measuring operational efficiency.
  • Familiarity with modern AI platforms including LLMs, AI agents and MCP.

Benefits & conditions

Retail Hybrid: London (2 days per week) 6 months £750 per day

In short: We’re looking for someone who will understand both how to build automation and how to embed the operational processes, governance and ways of working required for successful AI adoption within a SOC.

This is not a traditional SOAR administration role. The focus is on transforming Security Operations through automation, process optimisation and intelligent adoption of AI.

Essential: Experience designing an AI adoption strategy for a SOC.

About the company

Please be advised if you haven’t heard from us within 48 hours then unfortunately your application has not been successful on this occasion, we may however keep your details on file for any suitable future vacancies and contact you accordingly. Pontoon is an employment consultancy and operates as an equal opportunities employer.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adecco.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

Videos

See all

Related articles

See all