28 Aug
|
Theomnihire
|
Mumbai
28 Aug
Theomnihire
Mumbai
Job Title: Senior AI Developer – SOC Automation (L2)
Location: Reliance Corporate Park (RCP), Navi Mumbai
Working Hours: 9:00 AM – 6:00 PM
Mode of Interview: Face-to-Face or MS Teams
Headcount: 2 Positions (L2 Level)
Position Summary
As part of the SOC Automation team, the Senior AI Developer – SOC Automation (L2) will build and operate AI-powered components that automate key cybersecurity workflows. Working closely with the AI Lead, the incumbent will develop LLM-powered sec bots, machine learning models, and automation scripts, integrating them with monitored environments spanning cloud platforms (Azure, GCP, AWS) and on-premises infrastructure. This is a hands-on development and engineering role that requires building code, microservices, and autonomous agents, maintaining deployed models, and continuously expanding automation coverage based on operational SOC feedback
Requirements
Key Responsibilities
- AI/ML Development & Sec Bots:
- Build and maintain AI agents and sec bots for alert classification, anomaly detection, threat prioritization, and automated triage.
- Develop and fine-tune NLP models for log parsing, security alert summarization, phishing analysis, and IOC extraction.
- Implement feature engineering pipelines processing log data from Microsoft Sentinel, GCP Security Command Center (SCC), Trend Micro XDR, on-premises SIEM sources, and other security monitoring tools.
- Build and optimize Retrieval-Augmented Generation (RAG) pipelines to provide LLMs with context grounded in internal threat intelligence and playbook knowledge bases.
- Experiment with, evaluate, and prompt-engineer AI models tailored for SOC-specific use cases.
- Automation & Security Integration:
- Develop Azure Functions and Logic Apps to automate real-time alert enrichment, triage routing, and notification workflows.
- Build and maintain SIEM/SOAR integrations—writing custom playbook actions and connectors for Microsoft Sentinel SOAR and LogRhythm SIEM.
- Integrate AI model outputs with enterprise ticketing systems for automated incident creation, update tracking, and status resolution.
- Consume and normalize event streams from Azure Event Hub, GCP Pub/Sub, Trend Micro XDR, and on-premises log forwarders.
- Build production Python scripts and FastAPI microservices to expose AI capabilities as internal security microservices.
- Quality, Monitoring & MLOps:
- Write unit and integration tests for all AI components and actively participate in code reviews with the AI Lead.
- Monitor deployed model performance, track accuracy, and alert on model/data drift using Azure ML monitoring tools and custom dashboards.
- Maintain CI/CD pipelines for model retraining, prompt versioning, and automated code deployment.
- Document AI components, data schemas, API contracts, and operational runbooks.
- Participate in SOC analyst feedback sessions to collect operational insights and continuously refine model accuracy and agent performance.
Candidate Profile & Qualifications
Category
Requirements & Details
Experience
4 to 6 years of software development, AI/ML engineering, and cybersecurity automation experience
Education
B.Tech or M.Tech in Computer Science, Information Technology, AI/ML, Cyber Security, or related field
SIEM / SOAR & Cloud
• Hands-on experience with Azure Sentinel (Analytics Rules, Workbooks, Playbooks) and SOAR platforms (Sentinel SOAR, LogRhythm SIEM)
📌 Senior AI Developer – SOC Automation (Mumbai)
🏢 Theomnihire
📍 Mumbai