Cyber Security AI Engineer

NCR VOYIX CORPORATION
Atlanta, GA, United States
1 day ago
Apply on startup.jobs
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Data Analysis Microsoft Azure Cloud Computing Security Cyber Security Information Engineering Identity and Access Management Information Technology Operations Intrusion Detection and Prevention Information Systems Security Architecture Professional
+31 more
Python (Programming Language) Log Analysis Machine Learning Microsoft Security Essentials Windows PowerShell Azure Machine Learning Azure Data Lake Security Information and Event Management SQL Databases Systems Integration Software Vulnerability Management Workflow Management Systems Scripting Google Cloud Large Language Models Snowflake Mitre Att&ck QRadar Generative AI Cyber Threat Analysis Cybercrime Data Analytics Microsoft Sentinel Data Management Machine Learning Operations Api Design Splunk SentinelOne Expertise Automation Anywhere Security Orchestration, Automation & Response Databricks

Job description

The Cyber Security AI Engineer is a member of the Global Information Security team responsible for designing, developing, and operationalizing AI-driven cybersecurity capabilities that enhance Security Operations Center (SOC) effectiveness. This role combines expertise in cybersecurity, threat detection, automation, data science, machine learning, and security engineering to improve the organization’s ability to identify, investigate, and respond to cyber threats at scale.

The Cyber Security AI Engineer will partner closely with Threat Intelligence, Incident Response, Security Engineering, Detection Engineering, and IT Operations teams to develop intelligent detection models, automate security workflows, improve investigations through AI-assisted analytics, and create scalable solutions that reduce analyst workload while increasing detection accuracy.

This role supports the organization’s mission to protect the confidentiality, integrity, and availability of information assets through innovative use of artificial intelligence, machine learning, automation, and advanced analytics., AI-Driven Security Operations

  • Design, develop, and maintain AI and machine learning solutions to improve threat detection, incident triage, and security investigations.
  • Build predictive models to identify malicious activity, anomalous user behavior, insider threats, and emerging attack patterns.
  • Develop and operationalize AI-assisted threat hunting capabilities across enterprise environments.
  • Integrate Large Language Models (LLMs), Generative AI, and advanced analytics into SOC workflows to accelerate investigations and response activities.
  • Create AI-powered copilots to assist analysts with investigation, enrichment, summarization, and incident response recommendations.

Incident Response Support

  • Support investigation and response efforts for cybersecurity incidents.
  • Leverage AI analytics to accelerate root cause analysis and incident containment.
  • Assist incident responders with automated evidence gathering and forensic data analysis.
  • Participate in major incident investigations and contribute to post-incident reviews.

Security Detection Engineering

  • Develop and optimize detection logic using SIEM, XDR, EDR, cloud security, and log analytics platforms.
  • Build automated detection pipelines leveraging threat intelligence, MITRE ATT&CK mappings, and behavioral analytics.
  • Create AI-generated detection rules and continuously validate detection effectiveness.
  • Develop methods to reduce false positives and improve alert prioritization using machine learning techniques.

Threat Intelligence & Threat Hunting

  • Utilize internal and external threat intelligence sources to train and improve detection models.
  • Conduct proactive threat hunting exercises utilizing AI-enhanced analytics and behavioral indicators.
  • Develop automated intelligence ingestion, correlation, and enrichment processes.
  • Translate intelligence findings into actionable detection and response capabilities.

Security Automation & Orchestration

  • Design and implement security automation using SOAR platforms, APIs, scripting, and AI workflows.
  • Automate repetitive SOC tasks including alert enrichment, triage, investigation, reporting, and containment recommendations.
  • Develop integrations between AI tools, SIEM platforms, threat intelligence systems, and case management tools.
  • Improve SOC operational efficiency through continuous process optimization and automation., To ALL recruitment agencies: NCR Voyix only accepts resumes from agencies on the preferred supplier list. Please do not forward resumes to our applicant tracking system, NCR Voyix employees, or any NCR Voyix facility. NCR Voyix is not responsible for any fees or charges associated with unsolicited resumes

Requirements

  • 3+ years of experience in Cybersecurity, Security Operations, Security Engineering, Detection Engineering, or Incident Response.
  • 2+ years of experience developing automation, analytics, AI, or machine learning solutions.
  • Strong understanding of SOC operations, incident response, threat hunting, and threat intelligence.
  • Experience with SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, or Elastic.
  • Experience with EDR/XDR platforms such as Microsoft Defender, CrowdStrike, SentinelOne, or Palo Alto Cortex.
  • Experience with Python, PowerShell, SQL, and API development.
  • Knowledge of machine learning concepts including anomaly detection, classification, clustering, and behavioral analytics.
  • Experience integrating and leveraging Large Language Models (OpenAI, Azure OpenAI, Microsoft Security Copilot, Anthropic, or comparable technologies).
  • Experience building automation using SOAR platforms and workflow orchestration tools.

Cybersecurity Knowledge

  • Strong understanding of:
  • MITRE ATT&CK Framework
  • NIST Cybersecurity Framework
  • NIST SP 800-61 Incident Response
  • Threat Intelligence Lifecycle
  • Detection Engineering
  • Cloud Security (Azure, AWS, GCP)
  • Identity and Access Management
  • Vulnerability Management

Preferred Skills

  • Experience implementing AI security use cases in enterprise SOC environments.
  • Experience with Security Copilot, Azure AI Services, Azure OpenAI, Microsoft Sentinel AI capabilities, or comparable technologies.
  • Knowledge of MLOps, Data Engineering, and AI governance principles.
  • Experience with data platforms such as Databricks, Snowflake, Azure Data Lake, or Azure Machine Learning.
  • Familiarity with adversarial machine learning and AI security risks.
  • Experience developing Retrieval Augmented Generation (RAG) solutions for security operations.

Preferred Certifications

  • Certified Information Systems Security Professional (CISSP)
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Cyber Threat Intelligence (GCTI)
  • Microsoft Certified: Cybersecurity Architect Expert

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on startup.jobs
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all