I will build siem alert automation and soc workflows in python

Pakistan

I speak English, Urdu

3 orders completed

AI Engineer

AI Engineer & Security Automation Specialist specializing in turning raw data and security logs into production-grade intelligence using Python, PyTorch, and Docker.
About this Gig

I build Python automation that connects your SIEM directly to your response workflow alert triage, log parsing, and threat intel enrichment, wired into Splunk or Sentinel so your analysts stop doing by hand what a script can do in seconds.


What I build:

  • SIEM alert automation Splunk or Sentinel integrations that trigger on real alert conditions, not just scheduled polling
  • SOC workflow automation incident response playbooks, alert triage logic, and analyst task automation
  • Threat intel enrichment IOC lookups via VirusTotal/Shodan-style APIs, mapped to MITRE ATT&CK where relevant
  • Ticketing/SOAR integration automated ticket creation and Slack/Teams alerting on top of your existing stack
  • Compliance evidence automation scripted evidence collection for ISO 27001 / SOC 2 audit prep


I work specifically with Splunk and Sentinel. If your environment runs a different SIEM, message me first I'd rather confirm fit before you order than take a job I can't deliver well.

Message me before ordering with your platform (Splunk/Sentinel), the specific workflow you want automated, and roughly how many alerts/logs it handles per day that's the difference between Basic and Standard scope.