We are hiring a Security Engineer who lives at the intersection of SOC alerting and vulnerability remediation - the work that connects 'something looks wrong' to 'something is fixed'. You will own the close-the-loop motion: triage SOC alerts and vulnerability findings, prioritise against business context and threat intel, assign and chase down remediation owners, and measure what actually got fixed. AI leverage: AI SAST AppSec triage, CSPM findings, and prioritising AISOC for L1/L2 alert handling and intel agents for the repetitive parts owners' remediation loop.
Responsibilities
- SOC alert triage and response. Operate primarily as a SOC engineer and analyst. Triage alerts. Calibrate severity. Route or escalate. Be the human in the loop with AI and agents operating under your authority.
- Vulnerability alert handling and remediation coordination. Take the daily dose of vulnerability findings (SAST/SCA/secrets, CSPM, container/infra, and endpoint via EDR) and turn it into a managed remediation pipeline. Apply CTEM/risk-context prioritisation: CVSS + EPSS + KEV + business context.
- Close-the-loop ownership. Open the ticket; assign the right owner (engineering / SRE / Corp IT / AppSec); ensure the SLA (runAppSec) can rescan/retest; SLA-manage the rescan/retest platform; and close the GRC Platform - 'open and forgotten' is a thing of the past.
- SLA enforcement and metrics. Operate the SLA dashboard. Watch for ageing items at 75% of the SLA window and escalate. Run the WeAgeingLA compliance report on the SLA. Own the monthly CISO view of open vulnerabilities, MTTR trends, and ageing by owner.
- Threat hunting partnership. Support the senior SOC/detection engineer's senior detection engineer accounts. Bring vulnerability and remediating context into hunts (e. g., a known unpatched asset-focused hunt).
- AI agents for the loop. Build agents where the work is repetitive (e. g., alert deduplication and enrichment, vuln-to-owner routing, SLA-vulnerability-to-owner referen