Staff Cyber Defense Engineer (SOC Lead) – Automation & AI
Core
Lead the transition to an AI-driven, agentic Security Operations Center (SOC) by architecting automation, integrating LLMs, and overseeing incident response.
Role type
Staff Cyber Defense Engineer (SOC Lead)
Builds
AI-driven autonomous agents, automated playbooks, and SOAR integrations for enterprise security.
Domain
Cybersecurity / AI & Machine Learning
Deliverable
production ML models
Required skills
SOC operations, incident response, LLM orchestration, Python scripting, MITRE ATT&CK, SOAR platforms, threat hunting, network architecture, forensic analysis, data analytics
Preferred skills
GSE, GCIA, GCFA, CISSP, AWS Certified Security / Machine Learning, SANS SEC573/SEC540/MGT512
Technologies
Python, REST API, Cortex XSOAR, Splunk SOAR, Torq, Tines, SIEM, EDR, NDR
Responsibilities
Define automation roadmap and enforce Detection as Code (DaC) CI/CD pipelines; Serve as Incident Commander for major breaches; Supervise threat hunting and operationalize APT behaviors; Manage core security stack integration; Mentor engineers in prompt engineering and data practices.
Seniority
Staff, hands-on IC with leadership