About this SOC Automation Engineer role at Phoenix Software
Phoenix enables digital transformation across the UK public sector, empowering organisations to innovate with cloud and hybrid infrastructures, data, AI, security and collaboration technologies.
We are now hiring a SOC Automation Engineer to join our Security Operations Centre team and support the continued development of our managed security services.
This is a hands-on technical role focused on designing, developing and enhancing security automation solutions that improve the effectiveness, efficiency and scalability of SOC operations. Working closely with SOC Analysts, Incident Responders and Service Owners, you will help automate security processes, streamline investigations and improve customer outcomes through intelligent automation and orchestration.
What will you be doing?
- Design, develop and maintain security automation workflows to support SOC operations.
- Create and optimise automated playbooks that improve detection, triage, enrichment and response activities.
- Work closely with SOC, engineering and service delivery teams to understand operational requirements and deliver automation solutions.
- Build and maintain integrations with security technologies including SIEM, SOAR, EDR, threat intelligence and cloud platforms.
- Leverage APIs and external data sources to enhance security workflows and processes.
- Explore and implement AI-enhanced automation capabilities where appropriate.
- Develop reusable automation components and assets that can be deployed across multiple customer environments.
- Produce and maintain technical documentation, workflow diagrams, implementation guides and operational runbooks.
- Monitor the performance and reliability of automation solutions and implement continuous improvements.
- Support knowledge sharing and training activities across the SOC team.
- Contribute to the ongoing development of automation standards and best practices.
What are we looking for?
- Experience designing and implementing security automation solutions.
- Strong software development or automation engineering background.
- Experience with Python, JavaScript or similar scripting and development languages.
- Good understanding of REST APIs and systems integration.
- Experience working within a Security Operations, Incident Response, Threat Engineering or Security Engineering environment.
- Understanding of modern security technologies including SIEM, SOAR, EDR, IAM, threat intelligence and vulnerability management solutions.
- Knowledge of cloud security and cloud-based platforms.
- Awareness of AI technologies and their practical application within security operations.
- Strong troubleshooting and problem-solving skills.
- Excellent communication and technical documentation abilities.
- Ability to work independently while collaborating effectively across multiple teams.
Experience & Qualifications
- Minimum of 3 years' experience within a SOC, Security Engineering, Incident Response or related environment.
- Minimum of 2 years' experience developing or maintaining security automations.
- Experience working with SOAR technologies such as Swimlane, Cortex XSOAR, Tines or similar platforms.
- Experience integrating enterprise security technologies into automated workflows.
- Experience working within Managed Security Services (MSSP) environments desirable.
- Experience delivering automation projects from design through to implementation and support.
Certifications (desirable):
- Swimlane Certified SOAR Administrator (SCSA) or Swimlane Certified SOAR Developer (SCSD).
- Azure, AWS or GCP cloud certifications.
- Kubernetes certifications such as CKA or CKAD.
- Python, DevOps or API development certifications.
Practical stuff
Where is the role based?
Primary location is our HQ in Pocklington (YO42).
What about hybrid/remote working?
Hybrid working is supported, with flexibility depending on business and customer requirements.
How many interviews?
Following a screen with the Recruitment Team, you can expect a two-stage interview process — one online and one in-person.
Important Security Clearance
Due to the nature of our customers and the work delivered by our Security Operations Centre, candidates must either hold current SC (Security Check) clearance or be eligible and willing to obtain and maintain it.
Candidates who already hold active SC clearance will be highly advantageous.
Important BPSS Check
As part of our recruitment process and due to the nature of the work we do, all employees are required to undertake a BPSS check. While some employees may require further security clearance, the BPSS check is mandatory and all offers of employment are conditional upon successful completion.
Have you made it this far?
If you're still reading, we think there's a strong chance you might be our kind of person.
Here's the thing, research suggests many women and underrepresented groups don't apply unless they meet every requirement. Even if you don't tick every box above, we encourage you to introduce yourself.
We believe a diversity of perspectives and experiences makes a team stronger, and the stronger our team, the more successful we will be.