> Markdown version of [/jobs/ext/3027710-cyber-security-ai-engineer](https://www.wearedevelopers.com/jobs/ext/3027710-cyber-security-ai-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security AI Engineer - **Company:** NCR VOYIX CORPORATION - **Location:** Atlanta, GA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Data Analysis, Microsoft Azure, Cloud Computing Security, Cyber Security, Information Engineering, Identity and Access Management, Information Technology Operations, Intrusion Detection and Prevention, Information Systems Security Architecture Professional, Python (Programming Language), Log Analysis, Machine Learning, Microsoft Security Essentials, Windows PowerShell, Azure Machine Learning, Azure Data Lake, Security Information and Event Management, SQL Databases, Systems Integration, Software Vulnerability Management, Workflow Management Systems, Scripting, Google Cloud, Large Language Models, Snowflake, Mitre Att&ck, QRadar, Generative AI, Cyber Threat Analysis, Cybercrime, Data Analytics, Microsoft Sentinel, Data Management, Machine Learning Operations, Api Design, Splunk, SentinelOne Expertise, Automation Anywhere, Security Orchestration, Automation & Response, Databricks - **Published:** September 22, 2026 - **Apply:** https://startup.jobs/cyber-security-ai-engineer-security-operations-center-ncr-voyix-corporation-8550752 ## About the Role * 3+ years of experience in Cybersecurity, Security Operations, Security Engineering, Detection Engineering, or Incident Response. * 2+ years of experience developing automation, analytics, AI, or machine learning solutions. * Strong understanding of SOC operations, incident response, threat hunting, and threat intelligence. * Experience with SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, or Elastic. * Experience with EDR/XDR platforms such as Microsoft Defender, CrowdStrike, SentinelOne, or Palo Alto Cortex. * Experience with Python, PowerShell, SQL, and API development. * Knowledge of machine learning concepts including anomaly detection, classification, clustering, and behavioral analytics. * Experience integrating and leveraging Large Language Models (OpenAI, Azure OpenAI, Microsoft Security Copilot, Anthropic, or comparable technologies). * Experience building automation using SOAR platforms and workflow orchestration tools. Cybersecurity Knowledge * Strong understanding of: + MITRE ATT&CK Framework + NIST Cybersecurity Framework + NIST SP 800-61 Incident Response + Threat Intelligence Lifecycle + Detection Engineering + Cloud Security (Azure, AWS, GCP) + Identity and Access Management + Vulnerability Management Preferred Skills * Experience implementing AI security use cases in enterprise SOC environments. * Experience with Security Copilot, Azure AI Services, Azure OpenAI, Microsoft Sentinel AI capabilities, or comparable technologies. * Knowledge of MLOps, Data Engineering, and AI governance principles. * Experience with data platforms such as Databricks, Snowflake, Azure Data Lake, or Azure Machine Learning. * Familiarity with adversarial machine learning and AI security risks. * Experience developing Retrieval Augmented Generation (RAG) solutions for security operations. Preferred Certifications * Certified Information Systems Security Professional (CISSP) * GIAC Certified Incident Handler (GCIH) * GIAC Cyber Threat Intelligence (GCTI) * Microsoft Certified: Cybersecurity Architect Expert ## Description The Cyber Security AI Engineer is a member of the Global Information Security team responsible for designing, developing, and operationalizing AI-driven cybersecurity capabilities that enhance Security Operations Center (SOC) effectiveness. This role combines expertise in cybersecurity, threat detection, automation, data science, machine learning, and security engineering to improve the organization's ability to identify, investigate, and respond to cyber threats at scale. The Cyber Security AI Engineer will partner closely with Threat Intelligence, Incident Response, Security Engineering, Detection Engineering, and IT Operations teams to develop intelligent detection models, automate security workflows, improve investigations through AI-assisted analytics, and create scalable solutions that reduce analyst workload while increasing detection accuracy. This role supports the organization's mission to protect the confidentiality, integrity, and availability of information assets through innovative use of artificial intelligence, machine learning, automation, and advanced analytics., AI-Driven Security Operations * Design, develop, and maintain AI and machine learning solutions to improve threat detection, incident triage, and security investigations. * Build predictive models to identify malicious activity, anomalous user behavior, insider threats, and emerging attack patterns. * Develop and operationalize AI-assisted threat hunting capabilities across enterprise environments. * Integrate Large Language Models (LLMs), Generative AI, and advanced analytics into SOC workflows to accelerate investigations and response activities. * Create AI-powered copilots to assist analysts with investigation, enrichment, summarization, and incident response recommendations. Incident Response Support * Support investigation and response efforts for cybersecurity incidents. * Leverage AI analytics to accelerate root cause analysis and incident containment. * Assist incident responders with automated evidence gathering and forensic data analysis. * Participate in major incident investigations and contribute to post-incident reviews. Security Detection Engineering * Develop and optimize detection logic using SIEM, XDR, EDR, cloud security, and log analytics platforms. * Build automated detection pipelines leveraging threat intelligence, MITRE ATT&CK mappings, and behavioral analytics. * Create AI-generated detection rules and continuously validate detection effectiveness. * Develop methods to reduce false positives and improve alert prioritization using machine learning techniques. Threat Intelligence & Threat Hunting * Utilize internal and external threat intelligence sources to train and improve detection models. * Conduct proactive threat hunting exercises utilizing AI-enhanced analytics and behavioral indicators. * Develop automated intelligence ingestion, correlation, and enrichment processes. * Translate intelligence findings into actionable detection and response capabilities. Security Automation & Orchestration * Design and implement security automation using SOAR platforms, APIs, scripting, and AI workflows. * Automate repetitive SOC tasks including alert enrichment, triage, investigation, reporting, and containment recommendations. * Develop integrations between AI tools, SIEM platforms, threat intelligence systems, and case management tools. * Improve SOC operational efficiency through continuous process optimization and automation., To ALL recruitment agencies: NCR Voyix only accepts resumes from agencies on the preferred supplier list. Please do not forward resumes to our applicant tracking system, NCR Voyix employees, or any NCR Voyix facility. NCR Voyix is not responsible for any fees or charges associated with unsolicited resumes ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [WWC24 - Chris Wysopal, Helmut Reisinger and Johannes Steger - Fighting Digital Threats in the Age of AI](https://www.wearedevelopers.com/videos/926-wwc24-chris-wysopal-helmut-reisinger-and-johannes-steger-fighting-digital-threats-in-the-age-of-ai) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [Oops! Stories of supply chain shenanigans](https://www.wearedevelopers.com/videos/245-oops-stories-of-supply-chain-shenanigans) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [MLOps And AI Driven Development](https://www.wearedevelopers.com/magazine/82-mlops-and-ai-driven-development) - [Dev Digest 137 - AI'm not sure about this](https://www.wearedevelopers.com/magazine/485-dev-digest-137-ai-m-not-sure-about-this) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems)