Cyber Defence Automation Engineer
IAG Transform
- Harmondsworth, Greater London
- Permanent
- Full-time
- Third-party partners and key solution suppliers
- Other areas of IAG Cybersecurity, particularly the cyber programme
- Group Security Team(s)
- Senior managers/customers from across the Group and relevant business areas
- Senior managers/customers/colleagues from operating companies
- Bachelor’s degree in, Cybersecurity, Computer Science, Information Technology, or Artificial Intelligence.
- Industry certifications such as:
- Certified Information Systems Security Professional (CISSP)
- Certified Incident Handler (GCIH)
- GIAC Security Automation Expert (GCSA)
- Splunk Certified Automation Consultant, or relevant SOAR certifications.
- Experience with automation tools (e.g., SOAR platforms, Ansible, Phantom or similar).
- Proficiency in scripting languages (e.g., Python, PowerShell, Bash).
- Strong understanding of SOC processes, including incident response and threat detection.
- Experience with SIEM platforms (e.g., Splunk).
- Knowledge of security frameworks (e.g., NIST, MITRE ATT&CK).
- Proficiency in automation tools (e.g., SOAR platforms, Ansible, Phantom).
- Expertise in scripting languages (e.g., Python, PowerShell, Bash).
- Strong knowledge of SOC processes (incident response, threat detection).
- Experience with SIEM platforms (e.g., Splunk).
- Ability to integrate and automate security tools with AI / ML capabilities.
- Strong problem-solving and analytical skills.
- Experience in developing automated workflows and playbooks.
- Knowledge of security frameworks (e.g., MITRE ATT&CK, NIST).
- Strong collaboration and communication skills.
- Experience with log management and event correlation automation.
- 3-5 years of experience in SOC or cybersecurity roles.
- Hands-on experience with automation tools (e.g., SOAR, Ansible, Phantom, Demisto).
- Experience with scripting languages (e.g., Python, PowerShell, Bash) for automation.
- Experience integrating and automating security tools and processes.
- Strong background in SOC operations, incident response, and threat detection.
- Experience with SIEM platforms (e.g., Splunk, QRadar, ArcSight).
- Experience developing and managing automated response workflows.
- Familiarity with security frameworks like MITRE ATT&CK or NIST.
- Experience working with security log management and event correlation tools.
We are sorry but this recruiter does not accept applications from abroad.