> Markdown version of [/jobs/ext/3091595-senior-ml-engineer-cyber-security](https://www.wearedevelopers.com/jobs/ext/3091595-senior-ml-engineer-cyber-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior ML Engineer - Cyber Security - **Company:** Optimum Communications Inc. - **Location:** Norwalk, CT, United States - **Experience:** Expert - **Salary:** $100,246.0 - $164,689.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Automation of Tests, Cloud Computing Security, Cyber Security, Computer Programming, Continuous Integration, Information Engineering, Data Governance, Digital Forensics, Intrusion Detection and Prevention, Python (Programming Language), Machine Learning, Open Web Application Security, Software Engineering, Feature Engineering, Large Language Models, Prompt Engineering, Mitre Att&ck, Mttr, Generative AI, Information Technology, Machine Learning Operations, Software Version Control, Data Pipelines - **Published:** September 26, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88294974/1 ## About the Role * Bachelor's degree in Computer Science, Engineering, or related field, or equivalent years of experience * 7+ years of combined experience across security operations, incident response, and software engineering * Hands-on incident response and digital forensics experience, including leading or coordinating response to complex and major incidents preffered * Strong programming skills (e.g., Python) and sound software-engineering practices, including version control, CI/CD, and automated testing * Hands-on experience building with AI/ML, including large language models, prompt engineering, retrieval-augmented generation (RAG), and/or agentic frameworks * Experience with SOAR/automation and detection engineering (detection-as-code) * Data engineering skills, including working with large security datasets, APIs, and pipelines * Working knowledge of SOC operations and the incident lifecycle, including the MITRE ATT&CK framework, the NIST incident response lifecycle (NIST SP 800-61), the Cyber Kill Chain, and SANS PICERL * Cloud security and cloud-platform experience * Awareness of AI and LLM security risks, such as prompt injection and the OWASP LLM Top 10 * Ability to translate fluently between security and engineering stakeholders. Preferred Qualifications * MLOps experience deploying and maintaining models in production * Relevant security and/or AI/ML certifications, including incident-response and forensics credentials (e.g., GCIH, GCFA, GCFE, GNFA) or CISSP/CISM At Optimum, every action and interaction we take part in, is driven by our three Guiding Principles: Do What's Right, Drive One Optimum, and Make It Happen. These aren't just words, they help us build trust, create real community, and embrace new ways of thinking. Our employees are empowered to do the right thing for our customers and co-workers and to recognize and reward these behaviors when we see them. It's all part of the bigger picture of "Be The Difference" where each employee knows they have the power to enact real change, share new ideas, and understand that learning never stops. If you have the drive to succeed and are ready to embark on a thrilling career, seize this opportunity today, and join our winning team. Together, we'll shape the future of connectivity. All job descriptions and required skills, qualifications and responsibilities for a particular position are subject to modification by the Company from time to time, in the Company's discretion based on business necessity. ## Description Are you looking to Optimize your life? Start your exciting path to a rewarding career today! We are Optimum, a leader in the fast-paced world of connectivity, and we're seeking driven and enthusiastic professionals to join our team, empower lives, fuel businesses, and drive innovation. Connectivity is now longer a luxury, but a necessity. A career at Optimum means you'll be enabling progress and enhancing lives by providing reliable, high-speed connectivity solutions that keep the world connected. Our successes, now and in the future, are powered by our amazing product, a commitment to our people and culture, and the connections we make in our communities. If you are resourceful, collaborative, and passionate about delivering consistent excellence, Optimum is for you! Job Summary As a Senior SOC Engineer (AI & Automation), you will design, build, and operate the AI, automation, and detection-engineering capabilities that power our Security Operations Center. Bridging security operations and software engineering, you will develop AI-driven detection, triage, and response tooling, integrate large language model (LLM) and agentic workflows into analyst operations, and ensure those capabilities are accurate, safe, measurable, and continuously improved. As a senior member of the team, you will also serve as a technical leader during major security incidents, leading investigations and turning lessons learned into stronger detections, automations, and playbooks. Responsibilities * Design, build, and maintain AI/ML- and automation-driven capabilities for alert enrichment, correlation, summarization, triage, and prioritization. * Develop and maintain SOAR automations and detection-as-code pipelines that are version-controlled, tested, and peer-reviewed. * Integrate LLM and agentic AI tooling into SOC workflows (copilots, auto-triage agents); engineer prompts, guardrails, and evaluation harnesses. * Evaluate, benchmark, and tune AI models and tools for security use cases, measuring precision and recall, false-positive reduction, and impact on mean time to detect and respond (MTTD/MTTR). * Build data pipelines and feature engineering from security telemetry to support detection and machine-learning use cases. * Apply MLOps practices, including model versioning, monitoring, drift detection, and retraining, to security models running in production. * Ensure responsible and secure AI use, including data governance, prompt-injection and model-abuse defenses, privacy, and output validation. * Partner with detection engineers, SOC analysts, and incident responders to operationalize tooling and feed lessons learned back into models and automations. * Serve as a senior escalation point and incident commander for complex and major incidents, coordinating cross-functional response and directing technical workstreams. * Lead investigations and forensic analysis for escalated incidents and provide hands-on incident response support across on-premises and cloud environments. * Own post-incident reviews and root cause analyses, translating lessons learned into new detections, automations, and playbook improvements. * Develop, run, and mature incident-response playbooks and tabletop exercises (TTX) to validate and improve organizational readiness. * Define and report detection and incident-response metrics (e.g., MTTD, MTTR) to measure and continuously improve SOC effectiveness. * Mentor analysts and engineers, fostering a culture of continuous learning across AI-augmented and incident-response workflows, and promote an AI-first operating model across the SOC. ## Related Videos - [Who Do We Hire Now?](https://www.wearedevelopers.com/videos/100601-who-do-we-hire-now) - [Boring Failover: Predictable Region Recovery Across 5,000 Microservices](https://www.wearedevelopers.com/videos/100455-boring-failover-predictable-region-recovery-across-5-000-microservices) - [Your imaginations is (no longer) the limit: how Generative AI empowers people to be creative](https://www.wearedevelopers.com/videos/741-your-imaginations-is-no-longer-the-limit-how-generative-ai-empowers-people-to-be-creative) - [Unlocking the potential of Digital & IT at Vodafone](https://www.wearedevelopers.com/videos/602-unlocking-the-potential-of-digital-it-at-vodafone) - [Reducing Cognitive Overload Through Platform Engineering](https://www.wearedevelopers.com/videos/679-reducing-cognitive-overload-through-platform-engineering) - [The shadows that follow the AI generative models](https://www.wearedevelopers.com/videos/624-the-shadows-that-follow-the-ai-generative-models) ## Related Articles - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [Prompt Engineering is a Job of the Past](https://www.wearedevelopers.com/magazine/342-prompt-engineering-is-a-job-of-the-past) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market)