Overview
In this contract role, you will accelerate the evolution of our Security Operations by embedding automation and AI into SOC workflows. You’ll design and implement automation across Torq, Tines, Swimlane and related tools, while shaping governance and operating models for safe AI adoption. You will work with cross-functional teams to reduce manual toil, improve analyst effectiveness and scale security capabilities. This is a hands-on, strategic role that blends technical delivery with SOC workflow transformation and governance.
Responsibilities
- Design, develop and maintain security automation workflows using hyper-automation platforms (Torq, Tines, Swimlane or similar)
- Identify manual, repetitive operational activities suitable for automation in the SOC
- Develop automated triage, enrichment, investigation and response workflows
- Improve integration between security tooling, ticketing, asset inventories, identity systems and collaboration platforms
- Establish standards and best practices for automation development and document them
- Track and demonstrate measurable efficiency gains from automation
- Assess opportunities to safely introduce AI into Security Operations workflows
- Design and implement AI-assisted investigation, triage and analyst support capabilities
- Define governance, QA and human oversight models for AI-enabled security operations
- Establish methods to measure AI effectiveness, accuracy and operational benefit
- Ensure AI complements analysts rather than replaces human activities
- Help define future operating model for analysts working with AI agents and automation platforms
- Develop a roadmap for Security Automation and AI adoption within the SOC
- Identify activities to automate or keep human-led, and build scalable automation frameworks
- Provide recommendations on SOC maturity and operational efficiencies
- Engage with analysts, engineering teams and leadership to ensure successful adoption
- Measure automation outcomes and identify improvement opportunities
- Support knowledge sharing and capability uplift across the SOC
- Contribute to reusable playbooks, templates and investigation patterns
- Stay informed on industry practices around Security Automation, AI SOCs and Agentic AI
Key requirements
- Strong background in Security Operations, Incident Response, Detection Engineering or Security Engineering
- Experience in enterprise SOC environments
- Proven track record of improving security operations processes and analyst effectiveness
- Hands-on experience with SOAR/hyperautomation platforms such as Torq, Tines, Swimlane, Cortex XSOAR, Microsoft LogicApps or similar
- Experience developing automated investigations, alert enrichment workflows, response playbooks and case integrations
- Experience implementing AI capabilities within a SOC and ensuring governance and oversight
- Scripting or development experience (Python preferred)
- Experience integrating security technologies using APIs
- Understanding of SIEM, EDR, Identity and Cloud Security technologies
- Strong analytical and problem-solving skills
- Desirable: AI adoption strategy design for SOC, agentic AI, Microsoft Sentinel/Splunk, cloud security (Azure, GCP, AWS), detection engineering
- Desirable: automation metrics and operational efficiency measurement
- Familiarity with modern AI platforms including LLMs, AI agents and MCP
- cross-functional collaboration
- strategic thinking
- communication with stakeholders
- Torq
- Tines
- Swimlane
…
