HamburgerMenu
hirist

Job Description

Role Overview :

Design, implement, and scale AI-driven automation solutions with a primary focus on cybersecurity operations, security engineering, and enterprise defense use cases. This role is responsible for applying AI/ML, GenAI, and Agentic AI capabilities to automate security workflows, improve operational efficiency, accelerate threat response, and enhance cyber decision-making while maintaining strong governance and control.

Practice Area :

AI Automation & Cyber Defense

- Core Domains : Cybersecurity Automation, GenAI for Security Operations, Agentic AI for Cyber Workflows, SOAR & SecOps Transformation, AI-Assisted Defense

Required Skills :

1. AI Automation Strategy & Design :

- Automation Architecture : Design AI-enabled automation architectures for cybersecurity use cases spanning SOC operations, incident response, threat intelligence, vulnerability management, identity security, and security engineering.

- Use-Case Prioritization : Identify, assess, and prioritize AI automation opportunities based on operational pain points, repeatability, risk reduction potential, and measurable security outcomes.

- Workflow Engineering : Build scalable automation workflows that combine AI reasoning, decision support, orchestration, and system integrations across security platforms and enterprise tools.

2. Cybersecurity Operations Automation :

- SOC Automation : Develop AI-enabled solutions for alert triage, case enrichment, incident summarization, correlation support, ticket generation, and analyst workflow acceleration.

- Incident Response Automation : Implement automation for investigation support, playbook execution, evidence gathering, containment assistance, and post-incident reporting.

- Threat Intelligence Automation : Use AI to automate intelligence summarization, IOC extraction, threat correlation, adversary mapping, and contextual enrichment for security teams.

- Vulnerability & Exposure Automation : Build automations for vulnerability prioritization, asset-context correlation, remediation tracking, and risk-based exposure management.

3. Agentic AI & Security Orchestration :

- Agentic Workflow Design : Design controlled agentic systems that can perform bounded cybersecurity tasks such as data gathering, workflow routing, investigation support, and controlled action execution.

- Tool Integration : Integrate AI automation capabilities with SIEM, SOAR, EDR, IAM, ITSM, CMDB, case management, cloud security, and ticketing platforms.

- Human-in-the-Loop Controls : Ensure cyber automation workflows include approvals, escalation logic, confidence thresholds, and oversight for sensitive or high-impact actions.

4. GenAI Enablement for Security Teams :

- Security Copilots : Build GenAI-enabled copilots and assistants to support analysts, engineers, and security leaders with query handling, documentation generation, threat analysis, and knowledge retrieval.

- Knowledge Integration : Implement secure RAG and enterprise knowledge integrations across playbooks, runbooks, incident records, architecture documents, and threat repositories.

- Prompt and Workflow Optimization : Develop and refine prompts, orchestration logic, and decision pathways to improve automation reliability, relevance, and safety.

5. Governance, Security & Reliability :

- Automation Guardrails : Apply security, trust, and governance controls to ensure AI automation solutions operate safely, transparently, and within approved action boundaries.

- Performance Monitoring : Define metrics to evaluate automation effectiveness including analyst time savings, reduction in mean time to detect/respond, false positive reduction, and case throughput improvements.

- Operational Resilience : Monitor automation quality, failure modes, exception paths, and system performance to ensure stability in production environments.

Key Responsibilities :

- Automation Delivery : Design and implement AI-driven cybersecurity automation solutions across security operations, engineering, and risk management functions.

- Use-Case Development : Translate cybersecurity operational challenges into high-value automation use cases, technical designs, and deployable solutions.

- Platform Integration : Integrate AI workflows with security tools, enterprise platforms, and operational datasets to create end-to-end cyber automation capabilities.

- Agentic Security Solutions : Develop controlled agentic AI capabilities for bounded security tasks while enforcing approvals, logging, and action constraints.

- SOC Transformation : Improve analyst productivity and operational efficiency through AI-assisted triage, enrichment, summarization, investigation, and response support.

- Governance by Design : Ensure AI automation solutions align with enterprise AI governance, cybersecurity standards, data protection requirements, and operational risk controls.

- Measurement & Optimization : Define KPIs and continuously refine automations based on operational feedback, control effectiveness, and measurable security outcomes.

- Cross-Functional Partnership : Partner with SOC teams, threat intelligence, incident response, engineering, IT operations, and governance teams to drive successful adoption.

- Practice Innovation : Build reusable automation components, prompt libraries, agent patterns, workflow templates, and accelerators for repeatable implementation.

Qualifications :

1. Education & Experience :

- Degree : Bachelors or masters degree in computer science, Cybersecurity, Engineering, Data Science, Information Systems, or a related technical field.

- Core Experience : 5+ years in cybersecurity operations, security engineering, SOAR, automation engineering, or related domains.

- Specialized Experience : 2+ years specifically focused on AI automation, GenAI applications, agentic systems, or AI-enabled cybersecurity transformation.

2. Technical Skills & Certifications :

- Security Platforms : Hands-on experience with cybersecurity platforms such as SIEM, SOAR, EDR/XDR, ITSM, IAM, cloud security, vulnerability management, and threat intelligence tools.

- AI & Automation Tooling : Experience with workflow orchestration, LLM application development, API integration, Python scripting, automation pipelines, RAG architectures, and agent frameworks.

- Preferred Certifications : CISSP, GCIH, GCIA, GCFA, Splunk/QRadar/Microsoft Sentinel certifications, cloud security certifications, or relevant AI/automation certifications.

3. Soft Skills :

- Problem Solving : Strong analytical and systems-thinking skills with the ability to convert operational cyber problems into scalable automation solutions.

- Stakeholder Management : Effective communication with both technical security teams and executive stakeholders, with the ability to explain value, controls, and implementation trade-offs.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...