Cyber Security AI Engineer, Security Operations Center

NCR Corporation•Atlanta, GA
•Onsite

About The Position

The Cyber Security AI Engineer is a member of the Global Information Security team responsible for designing, developing, and operationalizing AI-driven cybersecurity capabilities that enhance Security Operations Center (SOC) effectiveness. This role combines expertise in cybersecurity, threat detection, automation, data science, machine learning, and security engineering to improve the organization's ability to identify, investigate, and respond to cyber threats at scale. The Cyber Security AI Engineer will partner closely with Threat Intelligence, Incident Response, Security Engineering, Detection Engineering, and IT Operations teams to develop intelligent detection models, automate security workflows, improve investigations through AI-assisted analytics, and create scalable solutions that reduce analyst workload while increasing detection accuracy. This role supports the organization's mission to protect the confidentiality, integrity, and availability of information assets through innovative use of artificial intelligence, machine learning, automation, and advanced analytics.

Requirements

  • 3+ years of experience in Cybersecurity, Security Operations, Security Engineering, Detection Engineering, or Incident Response.
  • 2+ years of experience developing automation, analytics, AI, or machine learning solutions.
  • Strong understanding of SOC operations, incident response, threat hunting, and threat intelligence.
  • Experience with SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, or Elastic.
  • Experience with EDR/XDR platforms such as Microsoft Defender, CrowdStrike, SentinelOne, or Palo Alto Cortex.
  • Experience with Python, PowerShell, SQL, and API development.
  • Knowledge of machine learning concepts including anomaly detection, classification, clustering, and behavioral analytics.
  • Experience integrating and leveraging Large Language Models (OpenAI, Azure OpenAI, Microsoft Security Copilot, Anthropic, or comparable technologies).
  • Experience building automation using SOAR platforms and workflow orchestration tools.
  • Strong understanding of: MITRE ATT&CK Framework, NIST Cybersecurity Framework, NIST SP 800-61 Incident Response, Threat Intelligence Lifecycle, Detection Engineering, Cloud Security (Azure, AWS, GCP), Identity and Access Management, Vulnerability Management.

Nice To Haves

  • Experience implementing AI security use cases in enterprise SOC environments.
  • Experience with Security Copilot, Azure AI Services, Azure OpenAI, Microsoft Sentinel AI capabilities, or comparable technologies.
  • Knowledge of MLOps, Data Engineering, and AI governance principles.
  • Experience with data platforms such as Databricks, Snowflake, Azure Data Lake, or Azure Machine Learning.
  • Familiarity with adversarial machine learning and AI security risks.
  • Experience developing Retrieval Augmented Generation (RAG) solutions for security operations.
  • Certified Information Systems Security Professional (CISSP)
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Cyber Threat Intelligence (GCTI)
  • Microsoft Certified: Cybersecurity Architect Expert
  • Microsoft Certified: Security Operations Analyst (SC-200)
  • Microsoft Certified: Azure AI Engineer Associate (AI-102)
  • Microsoft Certified: Azure Security Engineer (AZ-500)
  • Security+
  • Splunk Cybersecurity Defense Analyst

Responsibilities

  • Design, develop, and maintain AI and machine learning solutions to improve threat detection, incident triage, and security investigations.
  • Build predictive models to identify malicious activity, anomalous user behavior, insider threats, and emerging attack patterns.
  • Develop and operationalize AI-assisted threat hunting capabilities across enterprise environments.
  • Integrate Large Language Models (LLMs), Generative AI, and advanced analytics into SOC workflows to accelerate investigations and response activities.
  • Create AI-powered copilots to assist analysts with investigation, enrichment, summarization, and incident response recommendations.
  • Support investigation and response efforts for cybersecurity incidents.
  • Leverage AI analytics to accelerate root cause analysis and incident containment.
  • Assist incident responders with automated evidence gathering and forensic data analysis.
  • Participate in major incident investigations and contribute to post-incident reviews.
  • Develop and optimize detection logic using SIEM, XDR, EDR, cloud security, and log analytics platforms.
  • Build automated detection pipelines leveraging threat intelligence, MITRE ATT&CK mappings, and behavioral analytics.
  • Create AI-generated detection rules and continuously validate detection effectiveness.
  • Develop methods to reduce false positives and improve alert prioritization using machine learning techniques.
  • Utilize internal and external threat intelligence sources to train and improve detection models.
  • Conduct proactive threat hunting exercises utilizing AI-enhanced analytics and behavioral indicators.
  • Develop automated intelligence ingestion, correlation, and enrichment processes.
  • Translate intelligence findings into actionable detection and response capabilities.
  • Design and implement security automation using SOAR platforms, APIs, scripting, and AI workflows.
  • Automate repetitive SOC tasks including alert enrichment, triage, investigation, reporting, and containment recommendations.
  • Develop integrations between AI tools, SIEM platforms, threat intelligence systems, and case management tools.
  • Improve SOC operational efficiency through continuous process optimization and automation.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service