Senior Cyber Security Software Engineer

Altice USATown of Oyster Bay, NY
$100,246 - $164,689

About The Position

As a Senior SOC Engineer (AI & Automation), you will design, build, and operate the AI, automation, and detection-engineering capabilities that power our Security Operations Center. Bridging security operations and software engineering, you will develop AI-driven detection, triage, and response tooling, integrate large language model (LLM) and agentic workflows into analyst operations, and ensure those capabilities are accurate, safe, measurable, and continuously improved. As a senior member of the team, you will also serve as a technical leader during major security incidents, leading investigations and turning lessons learned into stronger detections, automations, and playbooks.

Requirements

  • Bachelor's degree in Computer Science, Engineering, or related field, or equivalent years of experience
  • 7+ years of combined experience across security operations, incident response, and software engineering
  • Hands-on incident response and digital forensics experience, including leading or coordinating response to complex and major incidents
  • Strong programming skills (e.g., Python) and sound software-engineering practices, including version control, CI/CD, and automated testing
  • Hands-on experience building with AI/ML, including large language models, prompt engineering, retrieval-augmented generation (RAG), and/or agentic frameworks
  • Experience with SOAR/automation and detection engineering (detection-as-code)
  • Data engineering skills, including working with large security datasets, APIs, and pipelines
  • Working knowledge of SOC operations and the incident lifecycle, including the MITRE ATT&CK framework, the NIST incident response lifecycle (NIST SP 800-61), the Cyber Kill Chain, and SANS PICERL
  • Cloud security and cloud-platform experience
  • Awareness of AI and LLM security risks, such as prompt injection and the OWASP LLM Top 10
  • Ability to translate fluently between security and engineering stakeholders.

Nice To Haves

  • MLOps experience deploying and maintaining models in production
  • Relevant security and/or AI/ML certifications, including incident-response and forensics credentials (e.g., GCIH, GCFA, GCFE, GNFA) or CISSP/CISM

Responsibilities

  • Design, build, and maintain AI/ML- and automation-driven capabilities for alert enrichment, correlation, summarization, triage, and prioritization.
  • Develop and maintain SOAR automations and detection-as-code pipelines that are version-controlled, tested, and peer-reviewed.
  • Integrate LLM and agentic AI tooling into SOC workflows (copilots, auto-triage agents); engineer prompts, guardrails, and evaluation harnesses.
  • Evaluate, benchmark, and tune AI models and tools for security use cases, measuring precision and recall, false-positive reduction, and impact on mean time to detect and respond (MTTD/MTTR).
  • Build data pipelines and feature engineering from security telemetry to support detection and machine-learning use cases.
  • Apply MLOps practices, including model versioning, monitoring, drift detection, and retraining, to security models running in production.
  • Ensure responsible and secure AI use, including data governance, prompt-injection and model-abuse defenses, privacy, and output validation.
  • Partner with detection engineers, SOC analysts, and incident responders to operationalize tooling and feed lessons learned back into models and automations.
  • Serve as a senior escalation point and incident commander for complex and major incidents, coordinating cross-functional response and directing technical workstreams.
  • Lead investigations and forensic analysis for escalated incidents and provide hands-on incident response support across on-premises and cloud environments.
  • Own post-incident reviews and root cause analyses, translating lessons learned into new detections, automations, and playbook improvements.
  • Develop, run, and mature incident-response playbooks and tabletop exercises (TTX) to validate and improve organizational readiness.
  • Define and report detection and incident-response metrics (e.g., MTTD, MTTR) to measure and continuously improve SOC effectiveness.
  • Mentor analysts and engineers, fostering a culture of continuous learning across AI-augmented and incident-response workflows, and promote an AI-first operating model across the SOC.

Benefits

  • Pay is competitive and based on a number of job-related factors, including skills and experience.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service