368,634open jobs
9,437companies
50,578added this week
Browse all
Salary
$45k – $134k per year (Estimated)
Location
Remote/Hybrid (United Kingdom)
Seniority
Middle · 3+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Phoenix Software utilises technology to enable UK organisations to innovate and transform, delivering remarkable, outcome focused IT solutions and services. Phoenix supports digital transformation in the workplace by understanding the individual goals of organisations and harnessing the power of cloud, data, AI, security, and collaboration tools. Phoenix is a signatory on the Race at Work Charter and Disability Confident Committed employer.

Phoenix enables digital transformation across the UK public sector, empowering organisations to innovate with cloud and hybrid infrastructures, data, AI, security and collaboration technologies.

We are now hiring a SOC Automation Engineer to join our Security Operations Centre team and support the continued development of our managed security services.

This is a hands-on technical role focused on designing, developing and enhancing security automation solutions that improve the effectiveness, efficiency and scalability of SOC operations. Working closely with SOC Analysts, Incident Responders and Service Owners, you will help automate security processes, streamline investigations and improve customer outcomes through intelligent automation and orchestration.

What will you be doing?

  • Design, develop and maintain security automation workflows to support SOC operations.
  • Create and optimise automated playbooks that improve detection, triage, enrichment and response activities.
  • Work closely with SOC, engineering and service delivery teams to understand operational requirements and deliver automation solutions.
  • Build and maintain integrations with security technologies including SIEM, SOAR, EDR, threat intelligence and cloud platforms.
  • Leverage APIs and external data sources to enhance security workflows and processes.
  • Explore and implement AI-enhanced automation capabilities where appropriate.
  • Develop reusable automation components and assets that can be deployed across multiple customer environments.
  • Produce and maintain technical documentation, workflow diagrams, implementation guides and operational runbooks.
  • Monitor the performance and reliability of automation solutions and implement continuous improvements.
  • Support knowledge sharing and training activities across the SOC team.
  • Contribute to the ongoing development of automation standards and best practices.

What are we looking for?

  • Experience designing and implementing security automation solutions.
  • Strong software development or automation engineering background.
  • Experience with Python, JavaScript or similar scripting and development languages.
  • Good understanding of REST APIs and systems integration.
  • Experience working within a Security Operations, Incident Response, Threat Engineering or Security Engineering environment.
  • Understanding of modern security technologies including SIEM, SOAR, EDR, IAM, threat intelligence and vulnerability management solutions.
  • Knowledge of cloud security and cloud-based platforms.
  • Awareness of AI technologies and their practical application within security operations.
  • Strong troubleshooting and problem-solving skills.
  • Excellent communication and technical documentation abilities.
  • Ability to work independently while collaborating effectively across multiple teams.

Experience & Qualifications

  • Minimum of 3 years' experience within a SOC, Security Engineering, Incident Response or related environment.
  • Minimum of 2 years' experience developing or maintaining security automations.
  • Experience working with SOAR technologies such as Swimlane, Cortex XSOAR, Tines or similar platforms.
  • Experience integrating enterprise security technologies into automated workflows.
  • Experience working within Managed Security Services (MSSP) environments desirable.
  • Experience delivering automation projects from design through to implementation and support.

Certifications (desirable):

  • Swimlane Certified SOAR Administrator (SCSA) or Swimlane Certified SOAR Developer (SCSD).
  • Azure, AWS or GCP cloud certifications.
  • Kubernetes certifications such as CKA or CKAD.
  • Python, DevOps or API development certifications.

Practical stuff

Where is the role based?

Primary location is our HQ in Pocklington (YO42).

What about hybrid/remote working?

Hybrid working is supported, with flexibility depending on business and customer requirements.

How many interviews?

Following a screen with the Recruitment Team, you can expect a two-stage interview process - one online and one in-person.

ImportantSecurity Clearance

Due to the nature of our customers and the work delivered by our Security Operations Centre, candidates must either hold current SC (Security Check) clearance or be eligible and willing to obtain and maintain it.

Candidates who already hold active SC clearance will be highly advantageous.

ImportantBPSS Check

As part of our recruitment process and due to the nature of the work we do, all employees are required to undertake a BPSS check. While some employees may require further security clearance, the BPSS check is mandatory and all offers of employment are conditional upon successful completion.

Have you made it this far?

If you're still reading, we think there's a strong chance you might be our kind of person.

Here's the thing, research suggests many women and underrepresented groups don't apply unless they meet every requirement. Even if you don't tick every box above, we encourage you to introduce yourself.

We believe a diversity of perspectives and experiences makes a team stronger, and the stronger our team, the more successful we will be.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,634 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
Cloud Engineer (AWS) 6 hours ago
In office • Full-Time • 5+ years exp • Bachelor's Degree • Dalian
Python
DevOps
AWS
CI/CD
CloudFormation
Docker
FinOps
GitHub Actions
Kubernetes
Terraform
GitHub
Apply
$20k – $48k per year (Estimated) • In office • Full-Time • Moscow
Python
SQL
Databases
Oracle
AI/ML
Hadoop
Management
Confluence
Jira
Apply
$22k – $50k per year (Estimated) • In office • Full-Time • 5+ years exp • Tomsk
JavaScript
Node JS
TypeScript
Frontend
React.js
DevOps
GitHub
Apply
$22k – $50k per year (Estimated) • In office • Full-Time • 5+ years exp • Perm
JavaScript
Node JS
TypeScript
Frontend
React.js
DevOps
GitHub
Apply
$17k – $43k per year (Estimated) • In office • Full-Time • Tomsk
C#
Java
Python
DevOps
CI/CD
Docker
Git
Grafana
Graylog
Kubernetes
Prometheus
Splunk
Apply
$73k – $149k per year (Estimated) • In office • Full-Time
DevOps
Azure
Splunk
Cybersecurity
Crowdstrike
LogRhythm
Microsoft Defender
Microsoft Entra ID
Microsoft Sentinel
Sophos
Apply
See all jobs
This is one of many
368,634 more open roles from verified company boards, updated every day.