Principal Security Operations Engineer
Core
Lead incident analysis, triage, and forensic investigation for insider and external threats, while architecting an AI-enabled Security Operations Center (SOC) to automate detection and response.
Role type
Principal Security Operations Engineer (AI/ML focus)
Builds
AI-enabled SOC capabilities, automated threat detection systems, and investigative workflows
Domain
Cybersecurity, Threat Intelligence, AI/ML in Security
Deliverable
production ML models | infrastructure
Required skills
Threat modeling, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), operations incident response, software development lifecycle, large-scale computing, forensic review, evidence preservation, root-cause analysis, executive communication
Preferred skills
Agentic AI or LLM-based automation design, post-quantum cryptography concepts, CNSA 2.0 familiarity, export control (EAR/ITAR) knowledge, insider threat platform experience
Technologies
Purview, DTEX, Proofpoint ITM, Magnet Axiom, Forcepoint
Responsibilities
Manage insider and external threat incident analysis from indicators to root-cause analysis; Define requirements, architecture, and backlog for an AI-enabled SOC; Evaluate and guide implementation of first- and third-party security solutions; Collaborate with legal, compliance, and investigations functions; Design and deploy AI/LLM automation in security contexts.
Seniority
Principal, strategy & mentorship