AI SOC Engineer

ByLabs

San Francisco (CA)

On-site

USD 140,000 - 210,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

ByLabs is seeking an AI SOC Engineer who blends offensive/defensive security with hands-on AI engineering to build a Security Brain that uses LLMs and AI agents to automate rule generation, reduce alert noise, and run automated security operations.

You will design AI-driven triage, integrate threat intel, ATT&CK mappings, and SIEM/EDR/NDR detections, and prototype AI SOC products to stay ahead of AI-powered adversaries.

Qualifications

  • 3+ years of SOC/security operations or pentesting experience.
  • Familiar with MITRE ATT&CK framework and mapping TTPs to detections.
  • Hands-on experience building AI-assisted security tooling.

Responsibilities

  • Automate generation, testing, and optimization of detection rules using LLMs and AI tools.
  • Design AI-based alert triage, prioritization, and false-positive suppression models.
  • Architect a unified knowledge graph integrating threat intel, attack graphs, and context.
  • Research and deploy AI SOC platform capabilities: automated threat hunting and AI-assisted investigations.
  • Develop detection scenarios from attacker perspective covering real-world TTPs.
  • Track AI SOC frontier research and drive internal adoption.

Skills

SOC operations
SIEM platforms
Python
LLM integration
Threat hunting
MITRE ATT&CK

Tools

Splunk
Elastic
SPL
KQL
Sigma
LangChain
AutoGen

Job description

We are looking for an AI SOC Engineer who combines deep offensive/defensive security expertise with hands-on AI engineering skills. You will be the core builder of our “Security Brain” — leveraging LLMs and AI agents to automate detection rule generation, suppress alert noise, and drive fully automated security operations. Using AI to fight AI, you will help ByLab’s SOC stay ahead of increasingly sophisticated, AI-powered adversaries.

Key Responsibilities
  • Use LLMs and AI tools to automate generation, testing, and continuous optimization of SIEM/EDR/NDR detection rules based on threat intelligence and ATT&CK TTPs
  • Design and implement AI/ML-based alert triage, prioritization, and false-positive suppression models to continuously reduce MTTD/MTTR
  • Architect the “Security Brain”: integrate threat intelligence, attack graphs, asset context, and behavioral baselines into a unified knowledge graph
  • Research and deploy AI SOC platform capabilities: automated threat hunting, AI-assisted incident investigation, and natural language security query (SecOps Copilot)
  • Design detection scenarios from an attacker’s perspective, ensuring coverage of real APT TTPs (including Lazarus and other crypto-industry threat actors)
  • Research AI-assisted attack techniques (AI-generated payloads, automated reconnaissance, LLM-assisted social engineering) and proactively build corresponding detection capabilities
  • Track AI SOC frontier research (LLM for Security, AI Agent for SOC, Agentic Security Operations) and drive internal adoption
Major Requirements
  • 3+ years of SOC/security operations or penetration testing experience with deep understanding of attack chains and defensive architectures
  • Proficient in major SIEM platforms (Splunk, Elastic etc.) and detection rule languages (SPL, KQL, Sigma)
  • Familiar with MITRE ATT&CK framework; able to map TTPs and design corresponding detection scenarios
  • Hands‑on experience in alert investigation, incident response, or threat hunting
  • Strong Python engineering skills; able to independently develop AI‑assisted security tools and automation scripts
  • Familiar with LLM application development (Prompt Engineering, RAG, Function Calling, AI Agent frameworks such as LangChain/AutoGen)
  • Practical experience applying AI/ML models to security use cases (alert classification, anomaly detection, NLP log analysis)
  • (Preferred) Experience designing or building AI SOC products or platforms (AI SOAR, SecOps Copilot, automated playbooks)
  • (Preferred) Familiarity with knowledge graphs and graph databases (Neo4j, etc.) in security contexts
  • (Preferred) Web3 / cryptocurrency security background (on‑chain attack detection, exchange security operations)
  • (Preferred) Security certifications (OSCP, GCIA, GCIH, GREM) or public research contributions (CVE, conference talks, open‑source tools)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AI SOC Engineer
AI SOC Engineer

ByLabs • Seattle (WA)

On-site
USD 140,000 - 190,000
ByLabs perks not listed
AI SOC Engineer: Architect the Security Brain with LLMs
AI SOC Engineer: Architect the Security Brain with LLMs

ByLabs • San Francisco (CA)

On-site
USD 140,000 - 210,000
AI-Driven SOC Architect: Automated Threat Defense
AI-Driven SOC Architect: Automated Threat Defense

ByLabs • Seattle (WA)

On-site
USD 140,000 - 190,000
ByLabs perks not listed
Senior Lead Security Engineer, AI
Senior Lead Security Engineer, AI

JPMorgan Chase & Co. • Columbus (OH)

On-site
USD 180,000 - 230,000
Senior Lead AI Security Engineer
Senior Lead AI Security Engineer

JPMorgan Chase & Co. • Columbus (OH)

On-site
USD 140,000 - 190,000
Senior Lead Security Engineer, AI
Senior Lead Security Engineer, AI

TwinThread • Columbus (OH)

On-site
USD 120,000 - 150,000
Lead AI Security Engineer | Agentic SOC
Lead AI Security Engineer | Agentic SOC

AlignityX • McLean (VA)

On-site
USD 180,000 - 240,000
AI Security Engineer
AI Security Engineer

AlignityX • McLean (VA)

On-site
USD 100,000 - 200,000
AI Security Operations Lead
AI Security Operations Lead

Veriipro • Center Square (PA)

On-site
USD 140,000 - 190,000
Senior Lead AI Security Engineer
Senior Lead AI Security Engineer

JPMorganChase • Columbus (OH)

On-site
USD 125,000 - 160,000