NCR

Cyber Security AI Engineer, Security Operations Center

NCR
Apply
1 day ago
Atlanta, GA, USAMid Level
H1B sponsor

Responsibilities

  • Design, develop, maintain, and operationalize AI and machine learning solutions for threat detection, incident triage, threat hunting, and security investigations.
  • Build predictive, anomaly-detection, behavioral, and classification models for malicious activity, insider threats, anomalous user behavior, and emerging attack patterns.
  • Integrate LLMs, generative AI, advanced analytics, and AI-powered copilots into SOC investigation and incident-response workflows.
  • Support cybersecurity incident investigations, root-cause analysis, containment, automated evidence gathering, forensic analysis, and post-incident reviews.
  • Develop and optimize detection logic and automated detection pipelines using SIEM, XDR, EDR, cloud security, log analytics, threat intelligence, MITRE ATT&CK mappings, and behavioral analytics.
  • Reduce false positives and improve alert prioritization by applying machine learning techniques and continuously validating detection effectiveness.
  • Conduct AI-enhanced threat hunting and automate threat-intelligence ingestion, correlation, enrichment, and translation into detection and response capabilities.
  • Design security automation using SOAR platforms, APIs, scripting, and AI workflows, including integrations among AI tools, SIEM platforms, threat-intelligence systems, and case-management tools.

Requirements

  • 3+ years of experience in cybersecurity, security operations, security engineering, detection engineering, or incident response.
  • 2+ years of experience developing automation, analytics, AI, or machine learning solutions.
  • Strong understanding of SOC operations, incident response, threat hunting, threat intelligence, MITRE ATT&CK, the NIST Cybersecurity Framework, NIST SP 800-61, detection engineering, cloud security, identity and access management, and vulnerability management.
  • Experience with SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, or Elastic.
  • Experience with EDR/XDR platforms such as Microsoft Defender, CrowdStrike, SentinelOne, or Palo Alto Cortex.
  • Experience with Python, PowerShell, SQL, API development, SOAR platforms, and workflow orchestration tools.
  • Knowledge of machine learning concepts including anomaly detection, classification, clustering, and behavioral analytics.
  • Experience integrating and leveraging LLM technologies such as OpenAI, Azure OpenAI, Microsoft Security Copilot, Anthropic, or comparable technologies.
  • Preferred experience implementing AI security use cases in enterprise SOC environments and using Security Copilot, Azure AI Services, Azure OpenAI, or Microsoft Sentinel AI capabilities.
  • Preferred knowledge of MLOps, data engineering, AI governance, adversarial machine learning, and AI security risks.
  • Preferred experience with Databricks, Snowflake, Azure Data Lake, Azure Machine Learning, or RAG solutions for security operations.
  • Preferred certifications include CISSP, GCIH, GCTI, Microsoft Cybersecurity Architect Expert, Microsoft Security Operations Analyst SC-200, Microsoft Azure AI Engineer Associate AI-102, Microsoft Azure Security Engineer AZ-500, Security+, or Splunk Cybersecurity Defense Analyst.

Tech Stack

AWSAzureDatabricksGoogle Cloud PlatformPowerShellPythonSnowflakeSplunkSQL
NCR

About NCR

10,000+ employees

NCR builds enterprise technology for retail, restaurants, and banks, including point-of-sale and self-checkout systems, payments software, ATM networks, and managed services. The company separated in 2023 into two public entities: NCR Voyix (unified commerce and payments for retail and hospitality) and NCR Atleos (banking and ATM-as-a-service). Founded in 1884 and headquartered in Atlanta, it sells hardware, software subscriptions, and support to customers in many countries.

Contact me