
Search by job, company or skills
What you will be working on
The SOC Automation Engineer is the primary builder and maintainer of the Cybersecurity Operations Centre's automation, orchestration, and AI-assisted capability layer. This role owns the engineering of SOAR playbooks, API integrations, and AI/ML-enhanced workflows that reduce manual analyst workload, accelerate detection-to-response timelines, and enable the SOC to operate at scale. Critically, this role is also the SOC's internal champion for identifying and implementing AI augmentation opportunities across all security operations functions - from alert triage to threat hunting to reporting.
Job Scope
What we are looking for
. Knowledge in Computer Science, Computer Engineering, Data Science, or related technical discipline
. Hands-on playbook development experience on FortiSOAR, Microsoft Sentinel Automation (Logic Apps / Playbooks), or equivalent enterprise SOAR platforms
. Proficiency in Python for automation, API integration, data transformation, and AI workflow development PowerShell for Windows/Azure automation
. Demonstrated experience building REST API integrations between security platforms
. Working knowledge of Microsoft Sentinel - Logic Apps, automation rules, watchlists, and KQL for automated query-based triggers
. Experience with agentic AI frameworks (e.g., LangChain, AutoGen, Microsoft Semantic Kernel) for building autonomous investigation workflows
. Familiarity with SIGMA rule format and automated rule conversion/testing toolchains
. Exposure to threat intelligence platform APIs (MISP, OpenCTI, commercial TIPs) and automated IOC ingestion pipelines
. Knowledge of LLM security risks - prompt injection, data leakage, model poisoning - and how to implement guardrails within automated SOC pipelines
. Experience with container-based deployment (Docker, Kubernetes) for hosting custom automation microservices
. At least 3 years in cybersecurity with at least 2 years focused on security automation, SOAR development, or security engineering
. Demonstrable portfolio of SOAR playbooks built and deployed in a production SOC environment - covering alert types, enrichment logic, and containment actions
. Hands-on experience integrating 5+ security tools via API in a SOC or security engineering context
. Possess relevant certification such as Microsoft Certified: Security Operations Analyst Associate (SC-200), Azure Security Engineer Associate (AZ-500), CrowdStrike Certified Falcon Responder (CCFR) or GIAC Certified Incident Handler (GCIH)
. Comfortable operating at the boundary of security operations and software engineering, without being fully siloed in either
As part of the shortlisting process for the role, you may be required to complete a medical declaration and / or undergo further assessment.
The Land Transport Authority is a statutory board under the Ministry of Transport of the Government of Singapore
Job ID: 148408321
Skills:
PowerShell, Kubernetes, Python, Docker, SIGMA rule format, FortiSOAR, KQL, agentic AI frameworks, SOAR playbooks, threat intelligence platform APIs, Microsoft Sentinel, AI ML-enhanced workflows, API integrations, REST API integrations, Logic Apps
Skills:
PowerShell, Kubernetes, Python, Docker, SIGMA rule format, FortiSOAR, KQL, agentic AI frameworks, SOAR playbooks, threat intelligence platform APIs, AI ML-enhanced workflows, Microsoft Sentinel, API integrations, REST API integrations, Logic Apps
We don’t charge any money for job offers