Vulnerability Operations Engineer (Hybrid - NYC/Charlotte, NC)
The Mom Project · Charlotte, NC · 1 mo ago
HybridEngineeringContract
Responsibilities
- Build and maintain integrations and automation across the security tooling stack, including data normalization, deduplication, and enrichment pipelines.
- Develop AI-assisted reporting pipelines that transform security tool outputs into business-unit-specific narratives and executive-ready reporting.
- Automate monthly metric review processes by replacing manual report assembly with scalable reporting workflows.
- Develop and maintain LLM-integrated workflows for alert triage, vulnerability summarization, remediation guidance generation, and finding prioritization.
- Evaluate, prototype, and operationalize emerging AI security tools, including agentic testing platforms and AI-driven offensive security tooling.
- Provide evidence-based recommendations regarding the adoption of security and AI technologies.
- Own and maintain the technical infrastructure supporting monthly business unit metric reviews, including dashboards, reporting pipelines, and data quality processes.
- Partner with vulnerability management teams to encode operational knowledge into scalable automation workflows.
- Reduce operational dependency risks through automation and knowledge-sharing initiatives.
- Contribute to AI governance practices for security operations, including documentation of prompts, model selection, validation methods, and human-in-the-loop controls.
- Produce internal documentation, operational runbooks, and executive-level summaries.
- Support security operations automation within CI/CD, cloud, and infrastructure-as-code environments.
Qualifications
- 5+ years of experience in security engineering, detection engineering, SOAR, or security automation roles.
- Strong Python programming skills with experience building REST API integrations and working with structured data at scale.
- Experience deploying and maintaining production-level automation and integrations.
- Hands-on experience with at least two enterprise security platforms such as Tenable, CrowdStrike, Wiz, Qualys, Rapid7, or Splunk.
- Practical experience integrating LLMs into production workflows using platforms such as Anthropic, OpenAI, or equivalent technologies.
- Strong understanding of prompt engineering, production reliability, and LLM failure modes, including hallucinations, prompt injection, and cost management.
- Experience working within CI/CD pipelines, infrastructure-as-code environments, and cloud-based systems.
- Strong written communication skills with the ability to create documentation, runbooks, and executive-ready summaries.
- Strong analytical and problem-solving skills.
- Ability to work cross-functionally within security and engineering environments.
Preferred Qualifications
- Experience with agent frameworks such as LangChain, LlamaIndex, or similar technologies.
- Experience implementing retrieval-augmented generation (RAG) patterns for security data workflows.
- Background in SOAR development using tools such as Tines, Torq, Cortex XSOAR, or Splunk SOAR.
- Experience with detection-as-code workflows.
- Familiarity with the enterprise security tooling vendor landscape and build-versus-buy evaluations.
- Experience working within multi-tenant or multi-business-unit environments with data isolation and reporting requirements.
- Knowledge of AI security risks, including prompt injection, model abuse, and data leakage mitigation strategies.