> Markdown version of [/jobs/ext/134241-information-security-engineer-i](https://www.wearedevelopers.com/jobs/ext/134241-information-security-engineer-i). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Engineer, I - **Company:** Zebra Technologies - **Location:** Lincolnshire, IL, United States (Remote available) - **Experience:** Starter - **Salary:** $70,000.0 - $80,000.0 - **Contract:** Permanent contract - **Skills:** Zebra (Programming Language), Microsoft Excel, Artificial Intelligence, Cloud Computing Security, Cyber Security, Intelligence Analysis, Python (Programming Language), Microsoft Security Essentials, Security Information and Event Management, Software Vulnerability Management, Application Enhancement Tool, Large Language Models, Mitre Att&ck, Mttr, Cyber Threat Analysis, Information Technology, Cybercrime, Microsoft Sentinel, Cortex XSOAR Platform, Splunk, Security Orchestration, Automation & Response - **Published:** May 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=3dbbeb9e28f7bc72 ## About the Role * Bachelor's Degree required or equivalent experience * 0-2 years of experience * Proven experience in a 24/7 SOC environment with hands-on responsibilities in incident response, threat hunting, or threat intelligence. * Strong practical experience with SOAR platforms (e.g., Palo Alto XSOAR, Splunk SOAR, Microsoft Sentinel) and developing complex automation playbooks. * Demonstrated ability to write and utilize scripts (e.g., Python) for security automation and integration. * Deep understanding of existing security platforms such as SIEM, EDR, and threat intelligence platforms. * Familiarity with the concepts of AI in cybersecurity, including crafting effective prompts for security use cases and understanding the principles of agentic AI workflows. Preferred Requirements: * Hands-on experience integrating AI, particularly large language models (LLMs), into security tools and workflows. * Direct experience with AI-native security platforms like Microsoft Security Copilot. * Knowledge of API integration for connecting disparate security systems and data sources. * A strong understanding of threat actor methodologies (TTPs) and the MITRE ATT&CK framework. * Certifications related to security operations, automation, or cloud security (e.g., GCIH, GCIA, GDAT). * Good verbal and written communication Skills * Ability to understand end user issues * Technical hands-on experience * Able to work independently and excel in a collaborative environment * Ability to trouble shoot * Demonstrated knowledge of applicable IT systems/applications * Ability to develop new systems and tools * Demonstrated analytical skills * Comfortable performing in a fast-paced, high growth, rapidly changing environment * Ability to identify and implement process improvements ## Description We are seeking a forward-thinking AI Security Operations Engineer to spearhead the integration and creation of advanced AI capabilities within our 24/7 Security Operations Center (SOC). This role is pivotal in transforming our security posture by embedding agentic AI into our core operational functions. You will be responsible for architecting and implementing AI-driven solutions to enhance our threat detection, response, and intelligence analysis, directly impacting our vulnerability management, threat hunting, and incident response processes. Responsibilities: * AI-Enhanced Incident Response: + Design, build, and deploy agentic AI frameworks to accelerate the full incident response lifecycle, from initial detection and triage to containment and eradication. + Develop and refine sophisticated SOAR (Security Orchestration, Automation, and Response) playbooks that leverage AI prompts for dynamic, context-aware decision-making and automated remediation actions. + Integrate AI agents into existing security platforms (SIEM, EDR, XDR) to provide real-time analysis of security events, automated evidence gathering, and recommended response actions for SOC analysts. * AI-Driven Threat Hunting and Intelligence: + Create and manage AI-powered systems to proactively hunt for threats by analyzing vast datasets for anomalous patterns, novel attack techniques, and indicators of compromise (IOCs) that evade traditional detection methods. + Develop AI models and prompts to automate the collection, correlation, and analysis of threat intelligence from multiple sources, providing actionable insights tailored to our threat landscape. + Build AI agents capable of contextualizing threat intelligence, predicting potential attack vectors, and recommending proactive defensive adjustments. * Automated Vulnerability Management: + Implement AI-driven workflows to automate the identification, prioritization, and remediation of vulnerabilities across the enterprise. + Utilize AI to analyze vulnerability data in conjunction with threat intelligence and asset criticality, creating a dynamic, risk-based prioritization model. + Develop SOAR rules and AI prompts to orchestrate mitigation efforts, reducing the mean time to remediate (MTTR). * AI Capability Development and Integration: + Act as the subject matter expert for integrating generative and agentic AI into the SOC's toolset and daily operations. + Collaborate with security analysts to identify and develop custom AI-powered tools and automations that address specific operational challenges and reduce manual effort. + Continuously evaluate and experiment with emerging AI technologies and security platforms to ensure our SOC remains at the cutting edge of security innovation. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)