Senior SOC AI Engineer
Summary
A 12-month B2B, 100% remote contract developing AI agents that enhance Security Operations Center (SOC) capabilities within an enterprise Microsoft-based environment. Day to day involves building agents with Python, Azure OpenAI/AI Foundry and LLMs, analyzing security data with KQL, and integrating with Sentinel, Defender XDR and Entra ID for incident response and threat hunting.
Details:
Contract: B2B, 12 months with possibility of extension
Location: Poland
Set-up: 100% remote
Rate: depending on experience, in range of 170-200 PLN netto per hour + VAT
Language: Polish & English - both fluent
As part of an innovative enterprise project, this role focuses on the development of AI agents aimed at enhancing Security Operations Center (SOC) capabilities. Ideal candidates will leverage their advanced skills in AI technologies to support robust security solutions.
Main Responsibilities:
Develop, implement, and assess AI agents to enhance SOC processes.
Collaborate with cross-functional teams to automate incident response workflows.
Utilize Kusto Query Language (KQL) for security data analysis.
Integrate AI solutions with existing Microsoft security technologies.
Engage in threat hunting and incident response activities.
Oversee the deployment of AI agents within security frameworks.
Maintain comprehensive documentation and conduct knowledge sharing sessions.
Key Requirements:
Experience with Azure AI Foundry, Azure OpenAI, and Azure AI Services.
Proficiency in Python for AI agent development and automation.
Knowledge of Large Language Models (LLMs) and prompt engineering.
Experience with Microsoft Security technologies, including Microsoft Sentinel, Defender XDR, Entra ID, and Azure Monitor.
Understanding of SOC operations, incident response, and security monitoring processes.
Strong knowledge of Kusto Query Language (KQL) for security data analysis.
Experience integrating AI agents with REST APIs and automation workflows.
Familiarity with Azure Data Explorer (ADX).
Understanding of MITRE ATT&CK and detection engineering principles.
Experience with Git, CI/CD, and DevOps practices.
Knowledge of data engineering concepts, including JSON and data normalization.
Familiarity with AI governance and responsible AI practices.
Nice to Have:
Experience with large-scale security telemetry platforms.
Familiarity with model evaluation practices in AI security.