Posted on: 30/09/2026
Job Description :
AI Engineer | Global Enterprise Security | AI Engineering
Level : Security Engineer III / IV
Team Overview :
GES AI Engineering is a small, high-leverage team that builds agentic AI and automation capability for Global Enterprise Security as a whole - not for a single program.
The team is chartered to build once, reuse everywhere : shared agent platforms, evaluation tooling, and automation patterns that any GES team can adopt.
Role Overview :
The AI Engineer designs, builds, and operates agentic AI workflows and automation on behalf of Global Enterprise Security's teams - most often as an embedded partner rather than the workflow's eventual owner.
What You'll Do :
- Take an ambiguous, partner-team-described problem in any security domain and scope a narrow, testable first version of it.
- Build agents and automation on the organization's shared model and orchestration platform(s) (for example AWS Bedrock or a comparable managed platform).
- Build an evaluation harness for every assignment before calling it done.
- Contribute to the shared agentic AI platform used across GES.
- Apply secure design and secure coding practices to all automation and agent code.
- Document every workflow, agent, and its known limitations well enough that the receiving team can operate and trust it.
Required Qualifications :
- Six or more years in software, security, or platform engineering, including experience building and shipping automation or AI-assisted tooling into production.
- Hands-on experience building agentic workflows on at least one managed model platform.
- Four or more years in a cybersecurity specialization to build from.
- Strong Python development skills, with proven experience building and consuming REST APIs.
- Practical experience with at least one major cloud provider (AWS, Azure, or GCP).
- Demonstrated experience building agent evaluation approaches.
Preferred Qualifications :
- Direct experience with a SOAR platform (Splunk SOAR, Torq, Tines, Swimlane, Cortex XSOAR, or equivalent).
- Familiarity with AI risk frameworks including the OWASP Top 10 for LLM Applications, NIST AI RMF, and MITRE ATLAS.
- Detection engineering background : MITRE ATT&CK mapping, detection-as-code, SIEM query languages and data models.
- Experience with fleet/endpoint management and patch automation tooling, or with infrastructure as code (Terraform) and Kubernetes.
- Certifications such as AWS Security Specialty, AWS Certified Machine Learning, GCIA, GCIH, GCDA, AZ-500, or SC-200.
Working Expectations :
- Operates under formal change management for anything touching production, customer-facing, or partner-team environments.
- Participates in a shared on-call rotation for platform availability and major incident support.
- Assignments are set by GES leadership based on current priorities and may shift with limited notice.
- Cross-covers teammates' assignments during surges, incidents, or absences.
Did you find something suspicious?