Summary
The AI Cyber Lead is the senior technical expert for AI-driven security capabilities within the CSIRT. This role designs and operationalizes agentic AI solutions across security platforms and incident response workflows, with a focus on secure adoption, governance, and measurable improvements to security operations.
Responsibilities
- Lead the design, prototyping, and implementation of AI enhancements for Cortex XSIAM and other security platforms, including automated incident triage, threat hunting, investigation, and response.
- Architect secure agentic AI workflows with human oversight, auditability, least-privilege access, and appropriate safeguards.
- Partner with CSIRT, Threat Hunting, Threat Intelligence, Red Team, Forensics, and security technology teams to align AI solutions and roadmaps.
- Identify AI security use cases and risks, evaluate emerging tools, and establish secure patterns and operational standards.
- Share knowledge, mentor SOC analysts, document best practices, and report on AI maturity, performance, and risk.
Requirements
- Bachelor's degree in a relevant technical field or equivalent practical experience; a master's degree is preferred.
- At least 3 years of experience in technology or advanced engineering, preferably in cybersecurity, security operations, detection engineering, or AI/ML engineering.
- Practical expertise in agentic AI, LLMs, RAG, multi-agent orchestration, and tool-using agents, including secure production deployment and governance.
- Experience with security operations platforms such as Cortex XSIAM/XDR, SIEM, SOAR, Microsoft Sentinel, or Defender XDR.
- Understanding of SOC workflows, incident response, security telemetry, AI-specific risks, and relevant security and regulatory frameworks.
- Strong analytical, communication, and collaboration skills, including the ability to explain technical risks and plans to senior leaders.
- Based in New York and able to work in a hybrid model; occasional travel may be required.