AI SOC Engineer

ByLabs

Seattle (WA)

On-site

USD 140,000 - 190,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

ByLabs perks not listed

Job summary

ByLabs is seeking an AI SOC Engineer who blends offensive/defensive security with hands-on AI engineering to build the Security Brain, automating detection rule generation and alert suppression within fully automated security operations.

You will leverage LLMs and AI agents to keep pace with AI-powered adversaries, design detection scenarios from an attacker’s view, and drive adoption of AI SOC capabilities across threat hunting, incident response, and SecOps automation.

Qualifications

  • 3+ years of SOC operations or penetration testing experience.
  • Experience with SIEM platforms and detection rule languages.
  • Familiar with MITRE ATT&CK framework and mapping TTPs.
  • Hands-on alert investigation, incident response, or threat hunting.
  • Strong Python for developing AI-assisted security tools and automation.
  • Familiar with AI/ML models applied to security use cases.
  • Preferred: designing or building AI SOC products or SecOps Copilot.
  • Familiarity with graph databases in security contexts.
  • Preferred: security certifications or public research contributions.

Responsibilities

  • Use LLMs and AI tools to automate generation, testing, and optimization of detection rules.
  • Design AI/ML-based alert triage, prioritization, and false-positive suppression.
  • Architect insights by integrating threat intel and context into a knowledge graph.
  • Research and deploy AI SOC capabilities for automated threat hunting and investigations.
  • Design detection scenarios from an attacker’s perspective covering TTPs.
  • Research AI-assisted attack techniques and build corresponding detection capabilities.
  • Track AI SOC frontier research and drive internal adoption.

Skills

SOC operations
Python engineering
AI/LLM security
Threat hunting
Incident response
AI tooling

Education

Security certifications (OSCP, GCIA, GCIH, GREM)

Tools

Splunk
Elastic
SPL
KQL
Sigma
LangChain
AutoGen
Neo4j

Job description

We are looking for an AI SOC Engineer who combines deep offensive/defensive security expertise with hands‑on AI engineering skills. You will be the core builder of our “Security Brain” — leveraging LLMs and AI agents to automate detection rule generation, suppress alert noise, and drive fully automated security operations. Using AI to fight AI, you will help ByLab’s SOC stay ahead of increasingly sophisticated, AI‑powered adversaries.

Key Responsibilities
  • Use LLMs and AI tools to automate generation, testing, and continuous optimization of SIEM/EDR/NDR detection rules based on threat intelligence and ATT&CK TTPs
  • Design and implement AI/ML‑based alert triage, prioritization, and false‑positive suppression models to continuously reduce MTTD/MTTR
  • Architect the “Security Brain”: integrate threat intelligence, attack graphs, asset context, and behavioral baselines into a unified knowledge graph
  • Research and deploy AI SOC platform capabilities: automated threat hunting, AI‑assisted incident investigation, and natural language security query (SecOps Copilot)
  • Design detection scenarios from an attacker’s perspective, ensuring coverage of real APT TTPs (including Lazarus and other crypto‑industry threat actors)
  • Research AI‑assisted attack techniques (AI‑generated payloads, automated reconnaissance, LLM‑assisted social engineering) and proactively build corresponding detection capabilities
  • Track AI SOC frontier research (LLM for Security, AI Agent for SOC, Agentic Security Operations) and drive internal adoption
Major Requirements
  • 3+ years of SOC/security operations or penetration testing experience with deep understanding of attack chains and defensive architectures
  • Proficient in major SIEM platforms (Splunk, Elastic etc.) and detection rule languages (SPL, KQL, Sigma)
  • Familiar with MITRE ATT&CK framework; able to map TTPs and design corresponding detection scenarios
  • Hands‑on experience in alert investigation, incident response, or threat hunting
  • Strong Python engineering skills; able to independently develop AI‑assisted security tools and automation scripts
  • Familiar with LLM application development (Prompt Engineering, RAG, Function Calling, AI Agent frameworks such as LangChain/AutoGen)
  • Practical experience applying AI/ML models to security use cases (alert classification, anomaly detection, NLP log analysis)
  • (Preferred) Experience designing or building AI SOC products or platforms (AI SOAR, SecOps Copilot, automated playbooks)
  • (Preferred) Familiarity with knowledge graphs and graph databases (Neo4j, etc.) in security contexts
  • (Preferred) Web3 / cryptocurrency security background (on-chain attack detection, exchange security operations)
  • (Preferred) Security certifications (OSCP, GCIA, GCIH, GREM) or public research contributions (CVE, conference talks, open‑source tools)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AI SOC Engineer
AI SOC Engineer

ByLabs • San Francisco (CA)

On-site
USD 140,000 - 210,000
AI SOC Engineer: Architect the Security Brain with LLMs
AI SOC Engineer: Architect the Security Brain with LLMs

ByLabs • San Francisco (CA)

On-site
USD 140,000 - 210,000
AI-Driven SOC Architect: Automated Threat Defense
AI-Driven SOC Architect: Automated Threat Defense

ByLabs • Seattle (WA)

On-site
USD 140,000 - 190,000
ByLabs perks not listed
Senior Lead Security Engineer, AI
Senior Lead Security Engineer, AI

JPMorgan Chase & Co. • Columbus (OH)

On-site
USD 180,000 - 230,000
Senior Lead Security Engineer, AI
Senior Lead Security Engineer, AI

TwinThread • Columbus (OH)

On-site
USD 120,000 - 150,000
Senior Lead AI Security Engineer
Senior Lead AI Security Engineer

JPMorgan Chase & Co. • Columbus (OH)

On-site
USD 140,000 - 190,000
Lead AI Security Engineer | Agentic SOC
Lead AI Security Engineer | Agentic SOC

AlignityX • McLean (VA)

On-site
USD 180,000 - 240,000
AI Security Engineer
AI Security Engineer

AlignityX • McLean (VA)

On-site
USD 100,000 - 200,000
AI Red Team Engineer
AI Red Team Engineer

ByLabs • Seattle (WA)

On-site
USD 140,000 - 190,000
AI Red Team Engineer
AI Red Team Engineer

ByLabs • San Francisco (CA)

On-site
USD 150,000 - 190,000