img
Contract

Security Automation and AI SOC Engineer (Torq, Tines, Swimlane)

London
money-bag £750/day
225626615
Posted Today

Security Automation and AI SOC Engineer (Torq, Tines, Swimlane)
Retail
Hybrid: London (2 days per week)
6 months
-750 per day

In short: We''re looking for someone who will understand both how to build automation and how to embed the operational processes, governance and ways of working required for successful AI adoption within a SOC.

This is not a traditional SOAR administration role. The focus is on transforming Security Operations through automation, process optimisation and intelligent adoption of AI.

Essential: Experience designing an AI adoption strategy for a SOC.

In full:

We are seeking an experienced Security Automation and AI SOC Engineer to help accelerate the evolution of our Security Operations capability through further automation, orchestration and the pragmatic adoption of AI.
This role will focus on identifying, designing and implementing automation that reduces manual effort, improves consistency and quality, and enables analysts to spend more time on high-value security activities. The successful candidate will also help shape and deliver our approach to AI within the SOC, ensuring that automation and AI are implemented safely, effectively and with appropriate governance.

The role requires a blend of technical capability, strategic thinking and practical delivery experience. We are looking for someone who has successfully implemented automation and AI within a Security Operations environment and can articulate both the technical implementation and the operating model required for long-term success.

Key Responsibilities

Security Automation:

* Design, develop and maintain security automation workflows using hyper-automation platforms such as Torq, Tines, Swimlane or similar technologies.
* Working with the SOC to identify manual, repetitive and time-consuming operational activities suitable for automation.
* Develop automated triage, enrichment, investigation and response workflows.
* Improve integration between security tooling, ticketing platforms, asset inventories, identity systems and collaboration platforms.
* Establish standards, documentation and best practice for automation development.
* Track and demonstrate measurable efficiency gains through automation.

AI-Enabled Security Operations:

* Assess opportunities to safely introduce AI into Security Operations workflows.
* Design and implement AI-assisted investigation, triage and analyst support capabilities.
* Define governance, quality assurance and human oversight models for AI-enabled security operations.
* Establish methods to measure AI effectiveness, accuracy, quality and operational benefit.
* Ensure AI capabilities complement analysts rather than simply replace human activities.
* Help define the future operating model for analysts working alongside AI agents and automation platforms.

SOC Strategy and Transformation:

* Develop a roadmap for Security Automation and AI adoption within the SOC.
* Help identify which activities should remain human-led and which should become automated or AI-assisted.
* Build frameworks for scaling automation while maintaining operational quality and risk management.
* Provide recommendations on SOC maturity improvements and operational efficiencies.
* Engage with security analysts, engineering teams and leadership stakeholders to ensure successful adoption.

Continuous Improvement:

* Measure automation outcomes and identify opportunities for further optimisation.
* Support knowledge sharing and capability uplift across the Security Operations team.
* Contribute to the development of reusable playbooks, templates and investigation patterns.
* Stay informed on emerging industry practices around Security Automation, AI SOCs and Agentic AI.


Essential Skills & Experience

Security Operations:

* Strong background in Security Operations, Incident Response, Detection Engineering or Security Engineering.
* Demonstrable experience working within an enterprise SOC environment.
* Experience improving security operations processes, workflows and analyst effectiveness.

Security Automation:

* Hands-on experience with security orchestration and automation platforms such as:
o Torq
o Tines
o Swimlane
o Cortex XSOAR
o Microsoft LogicApps
o Similar SOAR / Hyperautomation platforms

Experience developing:

o Automated investigations
o Alert enrichment workflows
o Response playbooks
o Case management integrations
o Analyst productivity tooling

AI and Security Operations:

* Practical experience implementing AI capabilities within a SOC environment.
* Experience evaluating and deploying AI-assisted investigations, triage, alert analysis or response workflows.
* Understanding of the opportunities, limitations and risks of AI in Security Operations.
* Experience implementing quality control, governance and human oversight mechanisms for AI-driven workflows.


Technical Skills

* Scripting or development experience (Python preferred).
* Experience integrating security technologies using APIs.
* Understanding of SIEM, EDR, Identity and Cloud Security technologies.
* Strong analytical and problem-solving skills.


Desirable Experience

* Experience designing an AI adoption strategy for a SOC.
* Experience with agentic AI or autonomous security workflows.
* Experience with Microsoft Sentinel, Splunk or equivalent SIEM platforms.
* Experience with cloud security technologies (Azure, GCP or AWS).
* Experience with detection engineering and security use case development.
* Experience building automation metrics and measuring operational efficiency.
* Familiarity with modern AI platforms including LLMs, AI agents and MCP.


Candidates will ideally show evidence of the above in their CV in order to be considered.
Please be advised if you haven''t heard from us within 48 hours then unfortunately your application has not been successful on this occasion, we may however keep your details on file for any suitable future vacancies and contact you accordingly. Pontoon is an employment consultancy and operates as an equal opportunities employer.

We use generative AI tools to support our candidate screening process. This helps us ensure a fair, consistent, and efficient experience for all applicants. Rest assured, all final decisions are made by our hiring team, and your application will be reviewed with care and attention.

Other jobs of interest...

A2Dominion
LondonYesterday
money-bag58714.00-58714.00 Annual
Randstad Digital
London1 week ago
money-bag380.00-380.00 Daily
VIQU IT
City1 week ago
money-bag400.00-400.00 Daily
Computer Futures
London2 weeks ago
money-bag60000.00-60000.00 Annual

Perform a fresh search...

  • Create your ideal job search criteria by
    completing our quick and simple form and
    receive daily job alerts tailored to you!

Jobs. Straight to your inbox!