Job Summary
This role sits within CLOUDSUFIs live engagement where AI is already embedded operationally across reliability and security - not a future aspiration. The team runs an AI co-pilot spanning multiple platforms, a set of purpose-built AI security sub-agents, and a formal AI governance program that assesses CLOUDSUFI's own internal AI agents for risk. As a Junior Security Engineer, you will work under the guidance of senior engineers and architects to support, operate, and learn from this AI-driven program.
Shift
US Shift
Responsibilities
AI-Augmented Security Operations Incident Response
- Support incident response activities by using AI-driven detection, correlation, and root-cause analysis tools under the guidance of senior engineers to speed up triage.
- Help operate and monitor existing AI security sub-agents (covering areas such as vulnerability scanning, threat intel, and vendor risk), flagging anomalies or failures for senior review.
- Assist in documenting and following up on AI-assisted incident findings, including tracking remediation actions through to closure.
AI-Driven Threat Vulnerability Prioritization
- Assist in triaging vulnerability scan results using risk-based prioritization supported by intelligent vulnerability analysis tooling (SAST/SCA, EASM, container scanning)
- Support cloud security posture reviews by using predictive analytics and intelligent monitoring dashboards, escalating notable trends to senior team members.
AI-Augmented Perimeter, WAF Anomaly Detection
- Help monitor and tune WAF policies using behavioral analytics and anomaly detection dashboards, under supervision, and learn to interpret traffic pattern alerts.
AI Governance, Risk Threat Modeling (Learning Track)
- Participate in architecture and design reviews that use automated threat modeling tools, learning how AI-agent risk (e.g., prompt injection, authorization gaps, secrets exposure) is assessed and documented.
- Assist in tracking action items from the AI-risk remediation roadmap and help prepare status updates for stakeholders.
AI-Enabled DevSecOps CI/CD
- Support the implementation of security controls within CI/CD pipelines, learning automation-first and AI-augmented approaches and shift-left practices from senior engineers.
- Help integrate basic AI-assisted checks (e.g., secret-scanning, dependency checks) into the development lifecycle.
AI-Enabled Program Workflow Support
- Support multiple concurrent security initiatives using AI-enabled workflow and tracking tools shared across SRE and Security teams.
- Help promote a security-first culture by learning and sharing data-driven, AI-backed security practices with the wider team.
Security Capabilities
- Foundational knowledge of container, application, and cloud security concepts, with interest in automated risk detection tooling.
- Exposure to static and dynamic application security testing tools, including basic code analysis.
- Basic understanding of API and web/mobile application security testing concepts.
- Interest in penetration testing and threat assessment fundamentals; willingness to learn AI-assisted reconnaissance techniques.
- Familiarity with threat detection and response concepts, including behavioral analytics and anomaly-based detection.
- Some hands-on exposure to security automation or scripting (Python, Bash, or similar).
- Basic exposure to cloud security posture management (CSPM) and continuous monitoring concepts.
- Interest in observability and monitoring, and a willingness to learn predictive analytics and anomaly detection.
About You
- 1-3 years of experience in cloud security, IT security, or a related engineering role, with an eagerness to build deeper expertise in infrastructure as code.
- Some exposure to cloud-native logging and monitoring tools; interest in AI-driven alerting and noise reduction.
- Basic familiarity with WAF concepts and a willingness to learn adaptive rule tuning.
- Coursework or hands-on exposure to security monitoring and observability platforms.
- Exposure to CI/CD pipelines and interest in integrating security controls and shift-left practices.
- Basic understanding of vulnerability management concepts and risk-based prioritization.
- Awareness of common compliance frameworks (PCI-DSS, SOC2, SOX, HIPAA).
- Beginner-to-intermediate familiarity with Infrastructure as Code tools (Terraform, Ansible, or CloudFormation).
- Willingness to learn incident management processes, including AI-assisted triaging.
- Strong analytical and problem-solving skills, with curiosity to assess simple architectures.