- Design and build systems combining security-relevant data, detection signals, context, and foundation models to identify and predict threats
- Prototype and test AI features for decoding events and system environments and predicting anomalies and threats
- Work with security SMEs and security researchers to validate real-world utility
- Develop an AIDevOps pipeline for rapid experimentation with data, knowledge bases, models, and context memory
- Define clear, measurable success criteria to evaluate iterations
- Architect and build a distributed platform correlating trillions of events and signals into explainable findings and alerts
- Build capabilities for triage resolution agents in Cisco/Splunk’s Agentic SOC
- Collaborate with product and platform teams to co-design scalable AI-enhanced threat detection and prediction workflows
- Contribute to the core architecture powering AI-native security operations and trusted enterprise automation
Requirements
- Bachelor's Degree with 7+ years of related experience or Master's with 4+ years of related experience
- Experience designing and implementing distributed systems, emphasizing storage systems and storage access layers
- Familiarity with data platforms, data lakes and warehouses, or streaming platforms
- Fluent Python or Go development experience building scalable backend services, APIs, and automation workflows
- Experience with CI/CD pipelines, GitHub/GitLab, Jira, and automated testing frameworks
- Experience designing agent systems that perform coding tasks
- Experience partnering with product managers, security SMEs, and engineers
- Preferred: experience building and maintaining pipelines for large-scale security telemetry
- Preferred: familiarity with TDIR/SIEM architectures, correlation searches, and threat hunting support systems
- Preferred: understanding of security operations concepts including attack surface management, threat analytics, detection, triage, investigation, and response
- Preferred: former Tier 3 SOC analyst or equivalent experience automating SecOps workflows and building scalable detection infrastructure
- Preferred: exposure to event storage systems or custom cybersecurity embeddings
- Preferred: hands-on RAG/GraphRAG pipelines and vector databases such as FAISS, Pinecone, or Weaviate
- Preferred: experience integrating and optimizing large language models or GNNs, GCNs, and GATs
- Preferred: experience shipping AI-powered features or products
- Preferred: ability to design model-output evaluation experiments for accuracy, usability, performance, and cost
- Preferred: background or interest in AI-assisted analyst workflows focused on usability, trust, and decision support
Core Competencies
Demonstrates expertise in designing and implementing distributed systems, with a strong focus on security operations and AI-enhanced threat detection. Proficient in Python or Go for building scalable backend services and automation workflows, alongside experience in CI/CD pipelines and data platforms.
Highest-signal resume keywords
- Distributed Systems Design
- Python Development
- CI/CD Pipeline Implementation
- AI-Powered Feature Development
- Security Operations Concepts
ATS Optimization Keywords
Hard Skills
- Distributed Systems
- Backend Services
- APIs
- Automation Workflows
- Data Platforms
- Storage Systems
- Threat Detection
- Model Evaluation
- Agent Systems
- Security Telemetry
Soft Skills
- Collaboration
- Communication
- Problem-Solving
- Partnership
Industry Keywords
- Threat Analytics
- Attack Surface Management
- Detection
- Triage
- Investigation
- Response
- Security Operations Center
- Large Language Models
- GNNs
- GCNs
Tools & Technologies
- GitHub
- GitLab
- Jira
- FAISS
- Pinecone
- Weaviate
- TDIR
- SIEM
- Automated Testing Frameworks
- RAG/GraphRAG Pipelines
Senior Software Engineer in san francisco at Unknown Company
This position is listed as full time and onsite.