Software Engineer, SOC Automation

ATCO

Calgary, CAonsitePosted Jul 3, 2026
Posting intelligenceActively listedReposted 7×, possible evergreen/ghost posting

Skills

pythoncicdllmml

About the role

Why Work Here?

Help defend critical infrastructure through advanced cybersecurity innovation. Build threat analytics and automation capabilities that operate at scale.

At ATCO, you’ll do meaningful work strengthening cybersecurity resilience across complex IT and OT environments. You’ll contribute to next-generation security operations, automation, and AI-driven security solutions while continuing to grow your expertise in an evolving threat landscape. You’ll help shape next-generation SOC capabilities alongside a collaborative team that values accountability, practical innovation, and continuous development.

About the Role:

The Software Engineer, SOC Automation plays a key role in advancing ATCO’s threat mitigation capabilities across enterprise IT, cloud, and operational technology environments.

Reporting to the Manager, Cybersecurity Operations Center, this role focuses on designing, implementing, and continuously improving automated threat protection and response solutions that support a modern, high-performing Security Operations Center (SOC).

As a subject matter expert in detection engineering and automation, you will connect threat intelligence to real-time operations by developing high-fidelity correlation rules, integrating AI/ML capabilities, and enabling faster, more consistent response through automation and orchestration.

You will work across diverse technologies and platforms to embed security visibility into digital systems while maintaining alignment with regulatory frameworks and cybersecurity best practices.

What You Get to Do:

Design, build, and optimize high-fidelity signatures across SIEM, EDR, NDR, and cloud platforms to improve threat visibility

Align protection coverage to frameworks such as MITRE ATT&CK® and identify and prioritize visibility gaps

Improve alert quality by reducing false positives and strengthening analytics logic to enable faster response

Develop and implement automated SOAR playbooks and workflows to enhance response speed and consistency

Build integrations and scripts to connect security tools and streamline SOC operations

Contribute to AI/ML-driven capabilities to identify advanced threats and anomalies

Leverage automation and LLM technologies to improve alert triage and response processes

Conduct threat modeling and proactive threat hunting activities

Translate threat intelligence and adversary techniques into actionable SOC workflow logic

Support a Detection-as-Code approach using CI/CD and version control practices

Participate in testing, validation, and continuous tuning of SOC use case content

Maintain documentation for use case coverage, automation workflows, and integrations

Collaborate with IT, OT, cloud, and application teams to embed threat protection capabilities into systems

Communicate technical findings and recommendations to both technical and business stakeholders

What You Bring:

University degree in Software Engineering or Computer Engineering

5+ years’ experience in cybersecurity operations, detection engineering, incident response, or security automation

Strong proficiency in programming and scripting (e.g., Python) and security analytics query languages (e.g., KQL, SPL, Sigma, YARA)

Experience working with SIEM, EDR, NDR, and SOAR platforms

Knowledge of Threat Analytics Engineering principles, including Detection-as-Code methodologies

Familiarity with AI/ML applications in cybersecurity and automation of SOC workflows

Strong understanding of cybersecurity frameworks and standards such as NIST CSF, MITRE ATT&CK®, and NERC CIP

Ability to analyze evolving threats across IT, OT, and cloud environments

Experience developing automated workflows and orchestration strategies to improve response times

Strong analytical, problem-solving, and communication skills

Ability to work independently and collaborate across teams

Available to respond to after-hours incidents

CISM, CISSP and/or CRISC certifications are considered assets

Experience working in complex environments such as utilities, energy, or critical infrastructure is an asset

What We Offer:

A culture based on caring, integrity, agility, collaboration, and striving for excellence

Competitive compensation

Flex benefits

Tuition assistance program

Training and mentorship programs

Charitable donation matching

We would like to thank everyone for their application; however, only those being considered for an interview will be contacted.

Questions about this role

Click "Apply with AI Applyd" above. We auto-fill the application from your resume and answer screening questions in seconds. No copy and paste, no juggling tabs.

Compensation for Software Engineer roles in Canada varies widely by seniority, employer size, and remote vs onsite arrangement. Check the salary range on this listing when published, or browse our Software Engineer hub for Canada medians across recent openings.

Most applications complete in under 90 seconds. You can track the status in your dashboard and watch the screenshot proof land the moment the application submits.

AI Applyd supports Greenhouse, Lever, Ashby, Workday, iCIMS, SmartRecruiters, Personio, Teamtailor and other major ATS platforms. If we can submit through the platform, we do.

Want AI Applyd to auto-apply to roles like this?

We tailor your resume per posting, fill the forms, and track replies for you.