Senior AI & Automation Engineer (Team)
Assignment Description We are looking for a senior AI & Automation Engineer to make security operations faster, smarter and more consistent through production-grade automation and AI-assisted security workflows across SecOps, IAM, vulnerability management, compliance and infrastructure security. You will automate alert triage, enrichment, investigation, containment, remediation and evidence collection, while building secure AI assistants and agents using GenAI, LLMs/SLMs, RAG/Agentic RAG, vector search, tool calling, MCP/A2A and LLMOps/GenAIOps. Solutions will include controlled self-healing and human approval for privileged or high-risk actions. The role covers Microsoft Sentinel, Defender XDR, Entra ID, Security Copilot, Copilot Studio, Purview and Azure security services, as well as ServiceNow SecOps/ITSM, SOAR and threat-intelligence integrations. You will develop reusable security playbooks for incident response, threat hunting, identity and endpoint security. You will also work with Ansible Automation Platform, Terraform/IaC, Security/Policy-as-Code and DevSecOps, including CI/CD security controls and automated testing. The role includes vulnerability and exposure management, security baselines, compliance automation and Zero Trust. AIOps and security observability are key areas, including event correlation, anomaly detection, intelligent alert reduction and closed-loop response. Success is measured through improved MTTD/MTTR, reduced false positives, increased automation coverage and improved analyst productivity. Required skills: You have hands-on experience with Python, PowerShell, REST APIs, JSON/YAML, KQL and scripting. You have experience with Ansible Automation Platform, Terraform, Git/GitHub/GitLab, GitHub Actions and Azure DevOps. You have experience with Microsoft Sentinel, Defender XDR, Entra ID, Purview, Security Copilot and Azure security services. You have experience with ServiceNow SecOps/ITSM, CMDB, Flow Designer and IntegrationHub. You have experience with SIEM/SOAR, XDR/EDR, IAM/PAM, vulnerability management and threat-intelligence platforms. You have experience with Docker/Kubernetes, Azure Functions, Logic Apps, event-driven technologies and API gateways. You have 10+ years of experience in Cyber Security, Security Engineering, SecOps, Detection Engineering or Security Automation. You have strong hands-on experience building enterprise security automation and integrating security platforms through APIs, workflows and orchestration. You have practical Microsoft Security and SIEM/SOAR experience and have taken automation or AI solutions from POC to production. You have a good understanding of incident response, vulnerability management, IAM, cloud security and security controls. You have a bachelor’s degree in Cyber Security, Computer Science, Engineering, IT or equivalent experience. Preferred qualifications: You have relevant Microsoft Security Operations, Cybersecurity Architect, Identity, Azure AI and/or Security certifications. You have CISSP, CISM, GIAC, Security+ or equivalent certification. You have Red Hat Ansible and/or ServiceNow SecOps certification. You have experience with ITIL, Zero Trust, DevSecOps, AIOps, SRE and/or FinOps.
Distansarbete: Konsult kan arbeta 100% på distans
Findigo hittar jobben och fyller i ansökan. Du klickar Skicka.
Visa jobbet och ansökUrsprunglig annons: upgraded.se