AI Threat Detection Engineer, Senior Specialist
Vanguard · Dallas, TX · 4 wk ago
HybridInformation TechnologyFull-time
Core Responsibilities
- Leads and responds to escalated cyber security alerts, cyber incidents, or related security investigations.
- Identifies real-time complex attack patterns and suggests mitigation strategies.
- Led the processes, tools and measures to monitor and detect compromises, risks, vulnerabilities, network security threats, tools and tactics used by modern and emerging threat actors.
- Facilitates security operations and incident response technologies and methodologies.
- Develops, manages, maintains and enhances security controls (alerts, rules, policies, and signatures) for the security platforms.
- Develop and enhance AI agents to streamline SOC operations and improve efficiency.
- Develops prompts and workflows to support LLM-based security use cases.
- Evaluates emerging AI technologies and contributes to innovation within the SOC.
- Implements safeguards and controls to ensure secure and responsible AI usage.
- Builds APIs, integrations, and automation workflows to support AI-driven capabilities.
- Writes clean, maintainable, and production-ready code aligned with engineering best practices.
- Collaborates with security, engineering, and platform teams to deliver AI-enabled solutions.
- Supports AI agent development and deployment across SOC use cases.
- Stays current on AI advancements and applies best practices to ongoing work.
- Mentors junior team members to improve their technical acumen.
- Participates in special projects and performs other duties as assigned.
Qualifications
- 4+ years of hands-on programming or scripting experience (e.g., Python, Java, Shell).
- 5+ years of experience with cloud platforms such as AWS or Microsoft Azure.
- 4+ years of experience building or supporting automation solutions (e.g., SOAR, GitHub, or similar tools).
- 4+ years of experience working with security technologies or supporting SOC/security operations.
- Exposure to AI, GenAI, or LLM-based solutions, with hands-on development experience preferred.
- Familiarity with security telemetry (logs, alerts, endpoint, network, and cloud data).
- 5+ years of exposure to SIEM platforms or detection engineering concepts.