Position:
MSSP Automation Engineer
Job Type:
Reports To:
Job Overview
developer-minded MSSP Automation Engineer
alert enrichment, incident response, IT support tasks,
Microsoft Sentinel, Defender XDR, Microsoft 365, and Azure
Key Responsibilities
🔹 Automation Development & Integration (SOC + MSS)
- Design and implement
Logic Apps
, Power Automate
flows, and custom connectors
to automate: - SOC workflows (alert enrichment, containment, escalation)
- MSS workflows (user onboarding, device compliance, license management)
- Build integrations across:
- Microsoft Sentinel, Defender (Endpoint, Identity, Office 365)
- Microsoft 365 (Exchange, SharePoint, Teams, Intune)
- Azure (VM provisioning, RBAC, networking, Entra ID)
🔹 Custom Scripting & API Integration
- Develop automation scripts using
PowerShell
, Python
, and Microsoft Graph API
. - Integrate with third-party platforms (e.g.,
JIRA, ServiceNow, Slack, email gateways
) via REST APIs and webhooks. - Build and maintain
Jupyter Notebooks
for automation, threat hunting, and analytics.
🔹 Use Case Enablement & Optimization
- Collaborate with SOC analysts and IT support teams to identify automation opportunities.
- Enable automated containment (e.g., isolate device, disable user, revoke session) and IT actions (e.g., password reset, onboarding).
- Support
Insider Risk
, DLP
, and compliance
workflows with automation.
🔹 Azure Platform Engineering
- Automate
Azure resource provisioning
, policy enforcement, and monitoring. - Implement
RBAC
, tagging, and governance for multi-tenant environments. - Support Azure automation for MSSP customer onboarding and delivery.
🔹 Governance, Security & Documentation
- Ensure workflows comply with standards (
ISO 27001, SOC2, NIST
). - Maintain documentation for all playbooks, scripts, and automation assets.
- Implement
logging, error handling, and version control
.
🔹 Collaboration & Enablement
- Collaborate with:
- SOC analysts and detection engineers (security automation)
- IT engineers (Microsoft 365 / Azure automation)
- Onboarding and JSM teams (workflow alignment)
- Deliver training and knowledge transfer on automation tools.
Required Skills & Qualifications
🎓 Education
Btech/BCA/MCA
🏅 Certifications
Required:
Microsoft Certified: Security Operations Analyst AssociatePreferred:
Azure Security Engineer, Azure Administrator (AZ-104), Defender XDR, ITIL Foundation
⚙️ Technical Expertise
- Proficiency in
Logic Apps, Power Automate, Microsoft Sentinel playbooks
- Strong hands-on with:
- Microsoft Defender XDR (MDE, MDI, MDO)
- Microsoft 365 (Intune, Exchange, Teams, SharePoint)
- Azure (VMs, Networking, Entra ID, RBAC)
- Skilled in
PowerShell, Python, KQL, Graph API, REST API
- Familiar with
Jupyter Notebooks, custom connectors
, and multi-tenant MSSP
setups
🧠 Soft Skills
- Strong analytical and problem-solving mindset
- Excellent communication and documentation skills
- Developer-oriented thinking (scalability, reusability, security focus)
- Fluent in English
Experience
5+ years
in cybersecurity, IT support, or SOC operations2–3 years
in automation engineering or security orchestration- Proven experience building automation in
Sentinel, Defender XDR, Microsoft 365, and Azure
- Prior
MSSP
or multi-tenant SOC/MSS
experience is highly preferred