10 days ago
London, United KingdomStaff+
Responsibilities
- Design, build, test, monitor, alert on, and operate AI-assisted automation services across the global security function.
- Deliver automation for alert triage, case summarization, evidence collection, detection tuning, threat-intelligence synthesis, and investigative workflows.
- Develop LLM and agent-based workflows integrated with SIEM, EDR, SOAR, IGA, PAM, CSPM, DLP, ticketing, and threat-intelligence platforms.
- Support identity, privileged access, network and cloud security, data protection, and vulnerability-management workflows.
- Set the global AI security and automation roadmap and prioritize workflows across security domains.
- Establish engineering standards for prompt and tool review, agent permission scoping, output validation, and secure AI-assisted tooling.
- Build guardrails including least-privilege identities, human-in-the-loop checkpoints, audit logging, and defenses against prompt injection and tool-definition poisoning.
- Create reusable platform components, integration patterns, evaluation harnesses, prompt libraries, and tool libraries.
- Define and report measures including time recovered, cycle time, quality, and error rates.
- Mentor engineers in the Pune capability centre and document systems for a follow-the-sun support model.
Requirements
- 8+ years of professional software engineering experience with production ownership.
- Advanced Python experience including asynchronous programming, API integration, automated testing, and CI/CD.
- Production experience building LLM-backed or agentic systems involving retrieval, tool and function calling, orchestration, and evaluation or regression testing of nondeterministic outputs.
- Working knowledge of security operations tooling and workflows including SIEM, EDR, SOAR, case management, and threat intelligence.
- Practical familiarity with at least two additional security domains such as identity and access management, privileged access, network or cloud security, or data protection.
- Cloud engineering experience with AWS or Azure, containerization, and infrastructure-as-code.
- Secure development experience with secrets management, least-privilege service identities, input validation, and output encoding.
- Experience delivering across multiple time zones for distributed stakeholders.
- Preferred: financial-services or comparable regulated-industry experience and knowledge of audit, evidence, and change-control requirements.
- Preferred: familiarity with prompt injection, tool poisoning, excessive agency, and current mitigations.
- Preferred: detection engineering exposure including detection-as-code, Sigma, and MITRE ATT&CK mapping.
- Preferred: hands-on experience with enterprise IGA, PAM, or CSPM platforms.
- Preferred: experience transitioning vendor-managed automation to internally owned capability, open-source contributions, published research, or conference speaking.
Benefits
- London-anchored role providing global coverage across APAC afternoon and Americas morning.
- Global, distributed work with collaboration across regional teams and mentoring of the Pune capability centre.
