> Markdown version of [/jobs/ext/2634299-lead-engineer-cyber-security-counter-threat-management](https://www.wearedevelopers.com/jobs/ext/2634299-lead-engineer-cyber-security-counter-threat-management). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Engineer, Cyber Security Counter Threat Management - **Company:** Royal Caribbean Group - **Location:** Miramar, FL, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Audit Trail, Cloud Computing Security, Cyber Security, Information Leak Prevention, Query Languages, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), Key Management, Log Analysis, Machine Learning, Node.Js, Queueing Systems, Role-Based Access Control, Red Team (Cyber Security), Kusto Query Language, Security Information and Event Management, Systems Integration, Software Vulnerability Management, Large Language Models, Mitre Att&ck, Mttr, Cyber Threat Analysis, Firewalls (Computer Science), Event Driven Architecture, Falcon Platform, Cybercrime, Restful APIs, Splunk, Network Server, Devsecops, Security Orchestration, Automation & Response, Servicenow - **Published:** August 24, 2026 - **Apply:** https://www.dice.com/job-detail/e15ab8b4-8f57-4a36-9742-b185112234a9 ## About the Role * 6+ years in software, cybersecurity and/or automation engineering; 2+ years working hands-on with AI/LLM systems in production * Expert-level proficiency in Python and/or Node.js for building scalable integrations and automation * Proven experience designing with LLM APIs (Anthropic, OpenAI, AWS Bedrock) and agentic frameworks (LangChain, Mastra, CrewAI, or similar) in enterprise environments * Deep hands-on experience with security platforms (SIEM/SOAR, EDR, firewalls, ticketing) and their APIs * Strong understanding of REST APIs, MCP servers, event-driven architectures, and message queuing * Solid grasp of core security domains: MITRE ATT&CK, threat intelligence, IAM, vulnerability management, and incident response lifecycle * Security certifications (CySA+, CISSP, AWS Security Specialty, OSCP) * Experience securing AI/LLM systems against prompt injection, model abuse, and data leakage * Familiarity with Splunk SPL, KQL, or similar query languages at scale * Background in red team, threat hunting, or detection engineering * Prior experience in a SOC, MSSP, or enterprise security operations environment ## Description We are looking for a seasoned Lead Engineer, Cyber Security Counter Threat Management with a strong technical focus to architect, build, and operate AI-driven automation solutions that enhance our security defense capabilities. You will work at the intersection of AI/ML, security engineering, and DevSecOps to reduce manual work, accelerate threat response, and strengthen our security posture at enterprise scale., * Architect and deploy AI-powered automation workflows for security use cases including threat detection, incident response, vulnerability triage, and compliance monitoring * Build and maintain production-grade AI agents and orchestration pipelines that integrate deeply with security tooling (SIEM, EDR, SOAR, firewalls, identity platforms) * Lead development of LLM-based solutions for log analysis, alert enrichment, and natural language querying of security data * Own end-to-end integrations with platforms such as CrowdStrike, Splunk, ServiceNow, and cloud security services * Act as a technical SME for SOC analysts and incident responders - identifying high-value automation opportunities, owning delivery, and measuring impact on MTTR * Define and enforce standards for AI automation security: least privilege, secrets management, audit logging, and prompt injection controls * Evaluate emerging AI models, agentic frameworks, and cybersecurity tooling - translating them into actionable capability roadmap items * Mentor junior engineers and provide technical guidance across cross-functional security and engineering teams ## Related Videos - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Stop using Node.js like in 2020! What changed and what you can do today with Node.js](https://www.wearedevelopers.com/videos/100011-stop-using-node-js-like-in-2020-what-changed-and-what-you-can-do-today-with-node-js) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Stop Using Node.js Like It’s 2020! - Alfonso Graziano](https://www.wearedevelopers.com/videos/1863-stop-using-node-js-like-it-s-2020-alfonso-graziano) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 137 - AI'm not sure about this](https://www.wearedevelopers.com/magazine/485-dev-digest-137-ai-m-not-sure-about-this) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)