We are looking for a Senior AI & Automation Engineer to help modernize Security Operations through production-grade automation, AI-assisted workflows and intelligent security orchestration.
You will work across SecOps, IAM, vulnerability management, incident response and infrastructure security, automating alert triage, investigation, enrichment, containment, remediation and evidence collection.
The role combines strong hands-on cyber security automation with modern GenAI and agentic AI capabilities.
What you will work with:
- Build AI-assisted security workflows using GenAI, LLMs/SLMs, RAG, Agentic RAG, AI agents, tool calling and MCP/A2A
- Develop automation across Microsoft Sentinel, Defender XDR, Entra ID, Security Copilot, Purview and Azure security services
- Build and integrate ServiceNow SecOps/ITSM, CMDB, Flow Designer and IntegrationHub
- Automate security operations including incident response, threat hunting, vulnerability management, IAM and endpoint security
- Develop reusable SIEM/SOAR and security automation playbooks
- Use Python, PowerShell, REST APIs, JSON/YAML, KQL and scripting for automation and integrations
- Work with Ansible Automation Platform, Terraform, Git/GitHub/GitLab and CI/CD
- Build event-driven security workflows using Azure Functions, Logic Apps, APIs and cloud services
- Apply DevSecOps, Security-as-Code, Zero Trust and automated security controls
- Develop intelligent alert correlation, anomaly detection, alert reduction and controlled closed-loop remediation
- Take AI and automation solutions from POC through secure, supportable production
- Apply human approval and risk-based controls for privileged or high-impact actions
Required experience:
- 10+ years of experience in Cyber Security, Security Engineering, SecOps, Detection Engineering or Security Automation
- Strong hands-on experience with Microsoft Sentinel
- Hands-on experience with Microsoft Defender XDR/EDR, Entra ID and Microsoft security services
- Strong experience with SIEM/SOAR, XDR/EDR, IAM/PAM, vulnerability management and security automation
- Hands-on experience with Python and/or PowerShell, REST APIs, JSON/YAML and KQL
- Experience with Ansible and/or Terraform
- Experience with ServiceNow SecOps/ITSM and CMDB
- Experience with Git-based development and CI/CD
- Practical experience with GenAI, AI agents, RAG or AI-assisted security automation
- Experience integrating enterprise security platforms through APIs, workflows and orchestration
- Good understanding of incident response, vulnerability management, IAM, cloud security and security controls
- Bachelor's degree in Cyber Security, Computer Science, Engineering, IT or equivalent practical experience
Preferred qualifications:
- Microsoft Security, Azure, AI or Cybersecurity certifications
- CISSP, CISM, GIAC, Security+ or equivalent
- Red Hat Ansible and/or ServiceNow SecOps certification
- Experience with ITIL, Zero Trust, DevSecOps, AIOps, SRE or FinOps