pracaon.plpracaon.pl

Lead AI Security Engineer

Remote, Polska
EPAM
Partner
сьогодні
Зарплата за домовленістю
Повна зайнятість • Дистанційна робота • IT, дані та AI

Основні характеристики вакансії

  • Мін. 5 років досвіду

  • DevOps / Хмара: AWS, Azure, Docker, Kubernetes

  • Повний робочий день

  • Віддалена робота - без поїздок

Description

We are looking for a Lead AI Security Engineer who thrives on solving complex issues and helps and mentors others while delivering the best possible technical service. This role supports the Cyber Defense capability, focusing on contributing to the development of an agentic orchestration platform for the SOC, delivering practical automation and AI-enabled workflows across our SOC stack in response to the cyber frontier. Responsibilities Build and improve SOC automations and playbooks, including triage, enrichment, case handling, and response actions Develop AI-assisted workflows such as summarisation, guided triage, recommended next steps, and knowledge lookup over runbooks Develop and secure AI agents and their associated skills, designing robust controls for safe and effective transfer of control Integrate tools and data sources using APIs/webhooks and maintain reliable, observable workflows Partner with SOC/IR teams to move from prototype to production with auditability, safety controls, and documentation Track outcomes such as time-to-triage/close, automation success rates, and alert noise reduction Work iteratively with analysts, write clear runbooks, and operate calmly in an incident-driven environment Translate complex concepts into practical, actionable solutions Apply metrics and statistics to measure performance and capacity Requirements 5+ years of hands-on experience in security engineering within/for a SOC, especially automation (SOAR or equivalent) Proficiency in Python/PowerShell and APIs for building integrations and workflows Working knowledge of cloud environments such as Azure (essential) and AWS (useful), along with common security telemetry Practical experience applying LLMs/AI in security operations, or strong interest with evidence of a delivery mindset Familiarity with using LLMs to assist with personal development work Knowledge and experience of Agile methodologies such as SAFe, SCRUM, or Kanban Excellent command of the English language, both written and spoken Strong people and communication skills, good time management, and a self-starter mindset Nice to have Familiarity with CI/CD and GitHub Actions Knowledge of n8n Skills in Kubernetes (AKS in particular) Proficiency in Terraform and Ansible

Requirements

  • 5+ years of hands-on experience in security engineering within/for a SOC, especially automation (SOAR or equivalent)

  • Proficiency in Python/PowerShell and APIs for building integrations and workflows

  • Working knowledge of cloud environments such as Azure (essential) and AWS (useful), along with common security telemetry

  • Practical experience applying LLMs/AI in security operations, or strong interest with evidence of a delivery mindset

  • Familiarity with using LLMs to assist with personal development work

  • Knowledge and experience of Agile methodologies such as SAFe, SCRUM, or Kanban

  • Excellent command of the English language, both written and spoken

  • Strong people and communication skills, good time management, and a self-starter mindset

Responsibilities

  • Build and improve SOC automations and playbooks, including triage, enrichment, case handling, and response actions

  • Develop AI-assisted workflows such as summarisation, guided triage, recommended next steps, and knowledge lookup over runbooks

  • Develop and secure AI agents and their associated skills, designing robust controls for safe and effective transfer of control

  • Integrate tools and data sources using APIs/webhooks and maintain reliable, observable workflows

  • Partner with SOC/IR teams to move from prototype to production with auditability, safety controls, and documentation

  • Track outcomes such as time-to-triage/close, automation success rates, and alert noise reduction

  • Work iteratively with analysts, write clear runbooks, and operate calmly in an incident-driven environment

  • Translate complex concepts into practical, actionable solutions

  • Apply metrics and statistics to measure performance and capacity

Seniority

  • Lead

Nice to have

  • Familiarity with CI/CD and GitHub Actions

  • Knowledge of n8n

  • Skills in Kubernetes (AKS in particular)

  • Proficiency in Terraform and Ansible

Ключові слова / Навички

Security.Engineering
AIOps
Microsoft Azure
Scripting Languages
Secure SDLC
Security Orchestration and Automated Response
Vulnerability Management
Azure Kubernetes Service
CI/CD
GitHub Actions
Terraform
Цю пропозицію імпортовано із зовнішнього порталу.Джерело оголошення

Більше схожих вакансій