
Lead Engineer, Cyber Security Counter Threat Management
Royal Caribbean Group13 days ago
Miramar, FL, USAStaff+
Responsibilities
- Architect and deploy AI-powered automation workflows for threat detection, incident response, vulnerability triage, and compliance monitoring.
- Build and maintain production AI agents and orchestration pipelines integrated with SIEM, EDR, SOAR, firewall, identity, and cloud security tooling.
- Develop LLM-based solutions for log analysis, alert enrichment, and natural-language querying of security data.
- Own integrations with CrowdStrike, Splunk, ServiceNow, and cloud security services.
- Identify automation opportunities for SOC analysts and incident responders, own delivery, and measure impact on MTTR.
- Define and enforce AI automation security standards covering least privilege, secrets management, audit logging, and prompt-injection controls.
- Evaluate AI models, agentic frameworks, and cybersecurity tools and translate findings into capability roadmaps.
- Mentor junior engineers and provide technical guidance across security and engineering teams.
Requirements
- 6+ years of experience in software, cybersecurity, and/or automation engineering.
- 2+ years of hands-on experience with AI/LLM systems in production.
- Expert proficiency in Python and/or Node.js for scalable integrations and automation.
- Experience designing with Anthropic, OpenAI, and AWS Bedrock LLM APIs and agentic frameworks such as LangChain, Mastra, or CrewAI.
- Deep hands-on experience with SIEM/SOAR, EDR, firewall, ticketing, and related security-platform APIs.
- Strong understanding of MCP servers, event-driven architectures, and message queuing.
- Knowledge of MITRE ATT&CK, threat intelligence, IAM, vulnerability management, and incident response.
- Experience securing AI/LLM systems against prompt injection, model abuse, and data leakage.
- Familiarity with Splunk SPL, KQL, or similar query languages at scale.
- Background in red teaming, threat hunting, or detection engineering and prior experience in a SOC, MSSP, or enterprise security operations environment.
- Security certifications such as CySA+, CISSP, AWS Security Specialty, or OSCP are listed as qualifications.
Benefits
- Competitive compensation and benefits package.
- Career development opportunities.
- Full-time onsite position based in Miramar, Florida.
- The position is not eligible for work authorization sponsorship.