Senior AI Developer – SOC Automation (L2)

TOCUMULUS

Mumbai

On-site

INR 1,200,000 - 1,800,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

TOCUMULUS is seeking a Senior AI Developer – SOC Automation (L2) to build AI-powered components that automate cybersecurity workflows from Reliance Corporate Park, Navi Mumbai. You will develop LLM-powered bots, ML models, and automation scripts across cloud and on-prem environments, delivering scalable automation and autonomous agents.

The role requires hands-on development, CI/CD for models, and ongoing optimization based on SOC feedback.

Qualifications

  • 4 to 6 years of software development, AI/ML engineering, and cybersecurity automation experience.
  • B.Tech or M.Tech in Computer Science, Information Technology, AI/ML, Cyber Security, or related field.
  • Hands-on experience with Azure Sentinel and SOAR platforms (Sentinel SOAR, LogRhythm SIEM).

Responsibilities

  • Build and maintain AI agents and sec bots for alert classification, anomaly detection, threat prioritization, and automated triage.
  • Develop NLP models for log parsing, security alert summarization, phishing analysis, and IOC extraction.
  • Implement feature engineering pipelines processing log data from major security tools and on‑premises sources.
  • Build and optimize Retrieval-Augmented Generation (RAG) pipelines to ground LLMs in internal threat intel and playbook knowledge bases.
  • Develop Azure Functions and Logic Apps to automate alert enrichment and triage routing.
  • Integrate AI outputs with SIEM/SOAR and ticketing systems for incident creation and updates.
  • Write production Python scripts and FastAPI microservices exposing AI capabilities as internal security services.

Skills

AI/ML development
NLP modelling
Python scripting
Security automation

Education

B.Tech or M.Tech in CS/IT/AI/Cyber Security

Tools

Azure
GCP
AWS
Microsoft Sentinel
LogRhythm SIEM

Job description

Job Title: Senior AI Developer – SOC Automation (L2)

Working Hours: 9:00 AM – 6:00 PM

Mode of Interview: Face‑to‑Face or MS Teams

Headcount: 2 Positions (L2 Level)

Position Summary

As part of the SOC Automation team, the Senior AI Developer – SOC Automation (L2) will build and operate AI‑powered components that automate key cybersecurity workflows. Working closely with the AI Lead, the incumbent will develop LLM‑powered sec bots, machine learning models, and automation scripts, integrating them with monitored environments spanning cloud platforms (Azure, GCP, AWS) and on‑premises infrastructure. This is a hands‑on development and engineering role that requires building code, microservices, and autonomous agents, maintaining deployed models, and continuously expanding automation coverage based on operational SOC feedback

Requirements

Job Title: Senior AI Developer – SOC Automation (L2)

Location: Reliance Corporate Park (RCP), Navi Mumbai

Working Hours: 9:00 AM – 6:00 PM

Mode of Interview: Face‑to‑Face or MS Teams

Headcount: 2 Positions (L2 Level)

Position Summary

As part of the SOC Automation team, the Senior AI Developer – SOC Automation (L2) will build and operate AI‑powered components that automate key cybersecurity workflows. Working closely with the AI Lead, the incumbent will develop LLM‑powered sec bots, machine learning models, and automation scripts, integrating them with monitored environments spanning cloud platforms (Azure, GCP, AWS) and on‑premises infrastructure. This is a hands‑on development and engineering role that requires building code, microservices, and autonomous agents, maintaining deployed models, and continuously expanding automation coverage based on operational SOC feedback

Key Responsibilities
  • AI/ML Development & Sec Bots:
    • Build and maintain AI agents and sec bots for alert classification, anomaly detection, threat prioritization, and automated triage.
    • Develop and fine‑tune NLP models for log parsing, security alert summarization, phishing analysis, and IOC extraction.
    • Implement feature engineering pipelines processing log data from Microsoft Sentinel, GCP Security Command Center (SCC), Trend Micro XDR, on‑premises SIEM sources, and other security monitoring tools.
    • Build and optimize Retrieval‑Augmented Generation (RAG) pipelines to provide LLMs with context grounded in internal threat intelligence and playbook knowledge bases.
    • Experiment with, evaluate, and prompt‑engineer AI models tailored for SOC‑specific use cases.
  • Automation & Security Integration:
    • Develop Azure Functions and Logic Apps to automate real‑time alert enrichment, triage routing, and notification workflows.
    • Build and maintain SIEM/SOAR integrations—writing custom playbook actions and connectors for Microsoft Sentinel SOAR and LogRhythm SIEM.
    • Integrate AI model outputs with enterprise ticketing systems for automated incident creation, update tracking, and status resolution.
    • Consume and normalize event streams from Azure Event Hub, GCP Pub/Sub, Trend Micro XDR, and on‑premises log forwarders.
    • Build production Python scripts and FastAPI microservices to expose AI capabilities as internal security microservices.
  • Quality, Monitoring & MLOps:
    • Write unit and integration tests for all AI components and actively participate in code reviews with the AI Lead.
    • Monitor deployed model performance, track accuracy, and alert on model/data drift using Azure ML monitoring tools and custom dashboards.
    • Maintain CI/CD pipelines for model retraining, prompt versioning, and automated code deployment.
    • Document AI components, data schemas, API contracts, and operational runbooks.
    • Participate in SOC analyst feedback sessions to collect operational insights and continuously refine model accuracy and agent performance.
Candidate Profile & Qualifications

Category

Requirements & Details

Experience 4 to 6 years of software development, AI/ML engineering, and cybersecurity automation experience

Education B.Tech or M.Tech in Computer Science, Information Technology, AI/ML, Cyber Security, or related field

SIEM / SOAR & Cloud

  • Hands‑on experience with Azure Sentinel (Analytics Rules, Workbooks, Playbooks) and SOAR platforms (Sentinel SOAR, LogRhythm SIEM)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior AI Developer – SOC Automation (L2)
Senior AI Developer – SOC Automation (L2)

Theomnihire • Mumbai

On-site
INR 600,000 - 1,200,000
Senior AI Developer – InfraSec Automation (L2)
Senior AI Developer – InfraSec Automation (L2)

Theomnihire • Mumbai

On-site
INR 1,800,000 - 2,800,000
Sr. AI Developer Engineer – Lead/Backend/Cloud (L4)
Sr. AI Developer Engineer – Lead/Backend/Cloud (L4)

TOCUMULUS • Mumbai

On-site
INR 4,000,000 - 6,000,000
Sr. AI Developer Engineer – DevSecOps Tools (L3)
Sr. AI Developer Engineer – DevSecOps Tools (L3)

TOCUMULUS • Mumbai

On-site
INR 3,000,000 - 4,200,000
Sr. AI Developer Engineer – DevSecOps Tools (L3)
Sr. AI Developer Engineer – DevSecOps Tools (L3)

Theomnihire • Mumbai

On-site
INR 3,000,000 - 5,000,000
Senior Full-Stack Engineer – AI Developer
Senior Full-Stack Engineer – AI Developer

TOCUMULUS • Mumbai

On-site
INR 1,500,000 - 2,100,000
Senior Developer AI and Automation
Senior Developer AI and Automation

Visdin Solutions • Pune District

Hybrid
INR 2,500,000 - 4,200,000
Senior Cloud Automation Engineer
Senior Cloud Automation Engineer

TOCUMULUS • Mumbai

On-site
INR 2,500,000 - 4,200,000
Senior Full-Stack Engineer – AI Developer
Senior Full-Stack Engineer – AI Developer

Theomnihire • Mumbai

On-site
INR 2,800,000 - 4,200,000
Cyber AI Engineer
Cyber AI Engineer

EY • India

Hybrid
INR 1,200,000 - 2,000,000