Lead AI Security Engineer
Remote, PolskaОсновні характеристики вакансії
Мін. 5 років досвіду
DevOps / Хмара: AWS, Azure, Docker, Kubernetes
Повний робочий день
Віддалена робота - без поїздок
Description
We are looking for a Lead AI Security Engineer who thrives on solving complex issues and helps and mentors others while delivering the best possible technical service. This role supports the Cyber Defense capability, focusing on contributing to the development of an agentic orchestration platform for the SOC, delivering practical automation and AI-enabled workflows across our SOC stack in response to the cyber frontier. Responsibilities Build and improve SOC automations and playbooks, including triage, enrichment, case handling, and response actions Develop AI-assisted workflows such as summarisation, guided triage, recommended next steps, and knowledge lookup over runbooks Develop and secure AI agents and their associated skills, designing robust controls for safe and effective transfer of control Integrate tools and data sources using APIs/webhooks and maintain reliable, observable workflows Partner with SOC/IR teams to move from prototype to production with auditability, safety controls, and documentation Track outcomes such as time-to-triage/close, automation success rates, and alert noise reduction Work iteratively with analysts, write clear runbooks, and operate calmly in an incident-driven environment Translate complex concepts into practical, actionable solutions Apply metrics and statistics to measure performance and capacity Requirements 5+ years of hands-on experience in security engineering within/for a SOC, especially automation (SOAR or equivalent) Proficiency in Python/PowerShell and APIs for building integrations and workflows Working knowledge of cloud environments such as Azure (essential) and AWS (useful), along with common security telemetry Practical experience applying LLMs/AI in security operations, or strong interest with evidence of a delivery mindset Familiarity with using LLMs to assist with personal development work Knowledge and experience of Agile methodologies such as SAFe, SCRUM, or Kanban Excellent command of the English language, both written and spoken Strong people and communication skills, good time management, and a self-starter mindset Nice to have Familiarity with CI/CD and GitHub Actions Knowledge of n8n Skills in Kubernetes (AKS in particular) Proficiency in Terraform and Ansible
Requirements
5+ years of hands-on experience in security engineering within/for a SOC, especially automation (SOAR or equivalent)
Proficiency in Python/PowerShell and APIs for building integrations and workflows
Working knowledge of cloud environments such as Azure (essential) and AWS (useful), along with common security telemetry
Practical experience applying LLMs/AI in security operations, or strong interest with evidence of a delivery mindset
Familiarity with using LLMs to assist with personal development work
Knowledge and experience of Agile methodologies such as SAFe, SCRUM, or Kanban
Excellent command of the English language, both written and spoken
Strong people and communication skills, good time management, and a self-starter mindset
Responsibilities
Build and improve SOC automations and playbooks, including triage, enrichment, case handling, and response actions
Develop AI-assisted workflows such as summarisation, guided triage, recommended next steps, and knowledge lookup over runbooks
Develop and secure AI agents and their associated skills, designing robust controls for safe and effective transfer of control
Integrate tools and data sources using APIs/webhooks and maintain reliable, observable workflows
Partner with SOC/IR teams to move from prototype to production with auditability, safety controls, and documentation
Track outcomes such as time-to-triage/close, automation success rates, and alert noise reduction
Work iteratively with analysts, write clear runbooks, and operate calmly in an incident-driven environment
Translate complex concepts into practical, actionable solutions
Apply metrics and statistics to measure performance and capacity
Seniority
Lead
Nice to have
Familiarity with CI/CD and GitHub Actions
Knowledge of n8n
Skills in Kubernetes (AKS in particular)
Proficiency in Terraform and Ansible
Ключові слова / Навички