Engineer, Cyber Security II
About the role
The CyberSecurity AI Specialist will design, implement, and govern advanced AI-enabled security capabilities that predict and neutralize unknown threats in real time. This includes building defensive AI architecture to automate alert triage and applying adversarial machine learning to detect synthetic attacks that mimic legitimate behavior. The role will also enhance behavioral analytics to identify insider threats and zero-day exploits, establish policy frameworks for secure generative AI adoption, and support incident response by mapping attacker movement in real time. This position strengthens both proactive defense and operational resilience while enabling secure innovation.
Responsibilities
- Implements, maintains, and monitors security systems/tools for the protection of computer systems, networks, and data (25%). Configures and troubleshoots security infrastructure devices and security tools. Ensures proper security tools are being used effectively.
- Assists in the design of systems security infrastructure and provides technical security guidance for projects (25%). Researches, designs, and advocates new technologies, infrastructure, architectures, and security products that support security requirements for the enterprise and its customers, business partners, and vendors. Performs capacity and future growth planning of the enterprise security infrastructure to ensure a highly available security environment.
- Develops and documents standard operating procedures and work instructions (20%). Evaluates and recommends procedures and processes for the prevention, detection, containment, and correction of information security breaches. Analyzes business impact and exposure based on security threats, vulnerabilities, and risks. Advises management and users regarding security procedures.
- Performs system monitoring evaluations and audits to ensure compliance with corporate security policies and standards (20%). Communicates security risks and solutions to business partners and appropriate IT staff as needed. Provides direct support and guidance for security-related issues.
- Assists in the development of technical solutions to mitigate security vulnerabilities and associated risks (10%). Evaluates products and/or procedures to enhance productivity and effectiveness of information security across the organization.
- Publishes an AI threat detection catalog mapped to telemetry sources and deploys an initial prioritized detection set with a monthly tuning cadence.
- Reduces repeat false positives and improves time-to-triage/time-to-escalation for AI-related alerts through enrichment and tuning.
- Stands up baseline monitoring and anomaly thresholds for approved AI tools and delivers recurring executive-ready reporting on risky usage patterns and remediation.
- Publishes AI-focused incident response (IR) runbooks and validates via tabletop exercises; feeds lessons learned into playbooks and detection tuning.
Requirements
- Bachelor's degree in Computer Science, Information Technology, or other job-related degree, or 4 years of job-related work experience, or 2 years of job-related experience plus an associate's degree in Computer Science, Information Technology, or other job-related degree.
- 6 years of job-related technical experience.
- Understanding of GitHub or GitLab, and CI/CD pipelines.
- Security operations/detection engineering/IR experience with SIEM/SOAR workflows; automation/scripting skills (e.g., Python, KQL/SPL).
- Working knowledge of AI/ML risk patterns (prompt injection, data leakage, and over-trust of outputs).
Skills
- Strong data analysis and correlation abilities.
- Strong knowledge of enterprise data architecture, systems engineering, and data communications as applied to the automated storage and retrieval of information, using multiple platforms and protocols with inherent security risks.
- Ability to effectively prioritize and execute tasks in a high-pressure environment.
- Strong understanding of the organization's goals and objectives.
- Expertise with threat analysis, risk management, configuration management, business continuity, and contingency planning.
- Strong knowledge of administrative, procedural, and technical controls used to reduce security risks.
- Ability to troubleshoot multi-vendor security issues.
- Strong organizational, interpersonal, and oral communication skills.
- Advanced proficiency in network troubleshooting and diagnostic root cause analysis.
- Excellent analytical and problem-solving abilities.
- Excellent attention to detail.
- Advanced proficiency with applicable IT security tools (software and hardware).
- Proficiency with Microsoft Office.
- Machine learning and deep learning fundamentals.
- Programming skills in Python and scripting languages.
- Understanding of adversarial attacks and AI model security.
- Cloud platforms and secure deployment practices.
- Communication and leadership skills; ability to work across teams including executives, architects, and senior technical staff.
Nice to Have
- Previous network engineer experience.
- Previous SOC analyst/engineer experience.
- Certifications related to AI/Machine Learning.
Schedule
- Hours: 8 AM – 5 PM, Monday through Friday (possible, but likely rare: overtime, travel, weekends, off-hours).
- Partial onsite: Tuesday, Wednesday, Thursday onsite and as needed.
- Interviews: In-person preferred; remote acceptable.
Work Environment
Fast-paced, multi-platformed environment which may require action and response 24/7 to support the technical business needs of the customer.
The Team
Cybersecurity Operations Center (CSOC) – 13 people, half analysts, half engineers. Currently continuing to integrate a new SIEM with multiple platforms and roll out new AI security initiatives.