HamburgerMenu
hirist

Job Description

Job Description :


We are seeking a Senior AI-First SOC Engineer who thrives at the intersection of security engineering, data analysis, and applied machine learning. In this role, you will design, build, and continuously enhance detection, analytics, and automated response capabilities across application, network, and identity domains. This position goes far beyond traditional alert triage : you will leverage large-scale log analysis, behavioral modeling, and AI-assisted workflows to reduce dwell time, improve signal fidelity, and automate SOC responses.

Key Responsibilities :

Detection Engineering & Analytics :

- Design and implement advanced detection logic across :

1. Application logs (APIs, authentication flows, business logic abuse)

2. Network telemetry (NetFlow, DNS, proxy, firewall logs)

3. Identity and user behavior (SSO, IAM, endpoint activity)

- Develop high-fidelity detection rules using SIEM, XDR, and modern data platforms.

- Apply statistical methods, anomaly detection, and machine learning techniques to identify novel threats.

- Continuously tune detections to reduce false positives and optimize precision and recall.

AI-Driven SOC Transformation :

- Integrate AI/LLM-based tooling into SOC workflows for triage, enrichment, and investigation.

- Build and operationalize pipelines for log normalization, feature extraction, and model inference.

- Develop use cases for AI-assisted threat hunting, incident summarization, and root-cause analysis.

- Evaluate and deploy AI security tools with a focus on explainability, reliability, and auditability.

Required Qualifications :

- 7+ years of experience in Security Operations, Detection Engineering, or Threat Hunting.

- Strong expertise with SIEM platforms (Splunk, Microsoft Sentinel, Elastic) and query languages.

- Deep understanding of :

1. Network protocols and traffic analysis

2. Application architectures (microservices, APIs, auth flows)

3. Identity systems (SSO, OAuth, IAM)

- Proven experience analyzing large-scale log datasets and building detection logic.

- Hands-on programming and scripting experience (Python preferred; experience with data processing libraries is a plus).

- Familiarity with SOAR tools and security automation frameworks.

- Strong incident response and investigation skills across multiple telemetry sources.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...