
Principal AI SOC Engineer
Tyto Athene, LLC23 hours ago
Reston, VA, USAStaff+
Base Salary
$200k - $225k/yr
Responsibilities
- Design and engineer AI-powered SOC capabilities for alert enrichment, triage, prioritization, correlation, investigation summarization, phishing analysis, insider-threat triage, and response recommendation.
- Own the AI SDLC from problem framing and data curation through model or prompt development, evaluation, deployment, monitoring, and rollback.
- Build evaluation methodology using golden datasets, regression suites, precision/recall measurement, false-positive analysis, and human-in-the-loop review gates.
- Implement AI guardrails, output validation, prompt and response logging, decision traceability, data minimization, retention controls, and model-training exclusions.
- Build and evolve SOC detection and response pipelines across SIEM, SOAR, EDR, email security, identity, and cloud security platforms.
- Engineer Splunk content and infrastructure, including advanced SPL, CIM normalization, correlation searches, notable-event tuning, ingest architecture, and performance tuning.
- Build Python-based SOAR playbooks, microservices, API integrations, and AI-driven decisioning across security and infrastructure controls.
- Develop telemetry onboarding and normalization pipelines and support logging maturity, retention tiering, and log integrity requirements.
- Maintain integrations for CISA sensor and CDM data flows, directive response, federal reporting, and incident notification timelines.
- Own and groom the Jira engineering backlog, translate operational requirements into technical designs, and document architecture, runbooks, SOPs, and decisions in Confluence.
- Set engineering standards for AI-enabled SOC capabilities, conduct code and design reviews, and mentor engineers on Python, Splunk, and AI engineering practices.
Requirements
- 8–12 years of hands-on enterprise IT and cybersecurity engineering experience across security operations, cloud platforms, automation, and AI/ML.
- 3–5 years of direct SOC engineering experience, including at least 2 years supporting federal SOC environments.
- Expert-level Python experience with production services, automation frameworks, API integrations, testing, packaging, and code review.
- Deep hands-on Splunk experience with advanced SPL, data models, CIM, Splunk Enterprise Security, ingest architecture, and Splunk SOAR playbooks.
- At least 3 years applying AI/ML to cybersecurity or operational systems and at least 2 years working with production or near-production LLM or GenAI systems, including RAG pipelines.
- Demonstrated ownership of AI capabilities through requirements, evaluation, deployment, versioning, reproducibility, testing, monitoring, and sustained operation.
- Experience with SOC automation, orchestration, playbook design, API integrations, and detection, correlation, and response pipelines.
- Proficiency with Git-based workflows, CI/CD pipelines, and containerized deployment.
- Working fluency with Jira and Confluence for backlog ownership, delivery, design documentation, and decision records.
- Working knowledge of FISMA, NIST 800-53, RMF, ATO processes, FedRAMP, and CISA directive-driven operations.
- Ability to set technical strategy, review designs, and establish engineering best practices across a team.
- Current TS/SCI clearance is required.
- Preferred qualifications include experience with federal civilian or law-enforcement SOCs, OMB AI governance, NIST AI RMF, TIC 3.0, CDM, CISA reporting, FedRAMP-authorized AI/ML workloads, self-hosted open-weight models, CJIS, Terraform, Ansible, Kubernetes, Azure, Microsoft Sentinel, Azure OpenAI, Azure ML, and relevant cybersecurity or Microsoft certifications.
Benefits
- Health, dental, and vision insurance.
- 401(k) match, paid time off, and short-term disability, long-term disability, and life insurance.
- Referral bonuses, professional development reimbursement, and parental leave.
- Hybrid work arrangement at the Reston, Virginia headquarters and client site in Washington, DC, with approximately two work-from-home days of flexibility.
Tech Stack
Categories
About Tyto Athene, LLC
Tyto Athene, LLC provides IT services and systems integration for U.S. defense and national security customers, delivering network modernization, unified communications, hybrid cloud, cybersecurity, and enterprise IT. The privately held company, founded in 2018 and headquartered in Reston, Virginia, designs, deploys, and manages mission-critical infrastructure including command centers, mobility, wireless, and physical security systems. Its work is primarily delivered under government contracts for design-build projects, managed services, and lifecycle support across CONUS and OCONUS locations.