AI Security (SOC) Engineer

Source Technology Limited

Greater London

Hybrid

GBP 110,000 - 150,000

Full time

7 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Source Group International Ltd in London is seeking a Senior AI Security (SOC) Engineer to strengthen our Cyber Defence capability with automation and AI-enabled workflows. You will develop SOC orchestration, integrate tools, and push automation across the stack while ensuring governance in a regulated environment.

The role combines software and cloud engineering, focusing on AI-assisted triage, runbooks, and safe transfer of control.

Qualifications

  • Experience in security engineering within/for a SOC, with automation focus.
  • Ability to build integrations and workflows via scripts and APIs (Python/PowerShell).
  • Cloud experience across Azure (essential) and AWS (useful).

Responsibilities

  • Build and improve SOC automations and playbooks (triage, enrichment, case handling, response actions).
  • Develop AI-assisted workflows (summarisation, guided triage, recommended next steps).
  • Develop and secure AI agents and their skills with robust controls.
  • Integrate tools and data sources via APIs/webhooks with observable workflows.
  • Partner with SOC/IR to move prototypes to production with auditability and safety controls.
  • Track outcomes like time-to-triage, automation success rates, and alert noise reduction.

Skills

Automation
SOAR
Python
PowerShell
Azure
AWS

Tools

n8n
Cribl Stream
GitHub Actions
Kubernetes (AKS)
Terraform
Ansible

Job description

Job Specification

Job Title: Senior AI Security (SOC) Engineer

Location: Hybrid (3 days in London office)

Who we’re looking for

We’re looking for aSeniorAISecurity (SOC)Engineer who thrives on solving complex issues,whobuildsAI SoC workflowsand helpsand mentorsothers,while delivering the best possible technical service.

We want someone who can work well in a team but beself-motivated. We are looking for someone that can understand complex IT/Securityissues andarticulate clearly to technical andnon-technicalpeople alike.Someone who is always looking for improvements to our service.

The team

We support our international offices by developing, rolling out and maintaining our systems and processes, using cutting-edge software and hardware.

What you’ll do

We are seeking aSeniorAISecurityEngineer who will supporttheCyber Defencecapability.This role will be focused oncontributing to the development of an agentic orchestration platform for the SOC (in response tocyberfrontier).

You will deliver practical automation and AI-enabled workflows across our SOC stack-Cyware, Azure, n8n (future/expanding),Cribl Stream and AWS Bedrock, to name a few. The aim isto reduceSOCanalyst toil, improve triage quality and speed up response, with appropriate governance for a regulated environment.

The successful candidate will combine strong software engineeringandcloud engineeringskills.

You will:
  • Build and improve SOC automations and playbooks (triage, enrichment, case handling, response actions).
  • Develop AI-assisted workflows (e.g., summarisation, guided triage, recommended next steps, knowledge lookup over runbooks).
  • Develop and secure AI agents and their associated skills, designing robust controls for safe and effective transfer of control.
  • Integrate tools and data sources using APIs/webhooks and maintain reliable, observable workflows.
  • Partner with SOC/IR to move from prototype to production with auditability, safety controls, and documentation.
  • Track outcomes (e.g., time-to-triage/close, automation success rates, alert noise reduction).
What we’re looking for
  • Strong hands-on experience in security engineering within/for a SOC, especially automation (SOAR or equivalent).
  • Comfortable building integrations and workflows with scripts/code (e.g., Python/PowerShell) and APIs.
  • Working knowledge of cloud environments (Azure essential; AWS useful) and common security telemetry.
  • Practical experience applying LLMs/AI in operations (or strong interest with evidence of delivery mindset).
  • Able to work iteratively with analysts, write clear runbooks, and operate calmly in an incident-driven environment.
  • Someone who uses LLMs to assist with theirowndevelopmentwork.
Nice to have:
  • CI/CD, Github Actions.
  • n8n.
  • Kubernetes (AKS in particular).
  • Terraform.
  • Ansible.
General Skills:
  • Good people skills.
  • Good time management.
  • Self-starter.
  • Good communication skills.
  • Knowledge and experience of using Agile methodologies e.g. SAFe, SCRUM, Kanban.
  • Has the ability to translate concepts into reality.
  • Understand the importance of metricsand statisticswhen measuring performanceandcapacity.
  • Excellent command of the English language, both written and spoken.
Personal Attributes:
  • Positive attitude, capable of remaining positive when under immense pressure.
  • A good communicator, and able towork with teams on a journey ofglobalisationand automation.
  • Someone who never accepts the status-quo. Someone who challenges why things are done the way they are.
  • Someone who is capable of ‘green-field’ thinking. Capable of imaging how the global platformcouldlook, and capable of creating a strategy to get us there.
  • Friendly, approachable, enjoys working with people from a variety of backgrounds.
  • Work well with others in a collaborative environment.
  • Continuous improvement mind-set, challenges the status quo and seeks self- improvement.

By applying for this role, you consent to SGI contacting you by telephone regarding recruitment services, market updates, and relevant business opportunities

We believe in equal opportunity for all and actively encourage applications from diverse backgrounds, experiences, and perspectives.

Source Group International Ltd is acting as an Employment Business in relation to this vacancy

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AI Security SOC Engineer - SGI
AI Security SOC Engineer - SGI

eFinancialCareers • Greater London

Hybrid
GBP 90,000 - 140,000
Senior AI Security Engineer — Hybrid (London)
Senior AI Security Engineer — Hybrid (London)

Source Technology Limited • Greater London

Hybrid
GBP 110,000 - 150,000
Senior SOC Analyst - Leeds
Senior SOC Analyst - Leeds

BAE Systems Digital Intelligence • Leeds

Hybrid
GBP 45,000 - 60,000
£5,000 referral bonus
Hybrid Working
Senior SOC Analyst – Leeds
Senior SOC Analyst – Leeds

BAE Systems • Leeds

Hybrid
GBP 65,000 - 90,000
£5,000 referral bonus
Security Engineer - AI and Emerging Technologies
Security Engineer - AI and Emerging Technologies

Harrington Starr • Greater London

Hybrid
GBP 85,000 - 110,000
Hybrid work environment
Exposure to senior stakeholders
Career development opportunities
+1
Embedded Security Team Lead
Embedded Security Team Lead

Sibylline Ltd • Greater London

Hybrid
GBP 70,000 - 110,000
Embedded Security Team Lead
Embedded Security Team Lead

Sibylline • Greater London

Hybrid
GBP 70,000 - 110,000
AI Cyber Tech Lead
AI Cyber Tech Lead

Cyber UK • Sheffield

Hybrid
GBP 75,000 - 95,000
SOC Automation Engineer
SOC Automation Engineer

Phoenix Software • Pocklington

On-site
GBP 65,000 - 90,000
Hybrid working
SC clearance support
Senior SOC Manager – Managed Cyber Defence
Senior SOC Manager – Managed Cyber Defence

SwiftCruit • Glasgow

Hybrid
GBP 90,000 - 130,000
Private medical cover
Flexible working arrangement
Volunteer days
+1