AI SOC Engineer
ByLabs - San Francisco Bay Area
Hiring: AI SOC Engineer Company: ByLabs Location: San Francisco Bay Area Job Posted Time: 2026-09-16 22:39:11 Target Skills & Keywords : LLM, LangChain, NLP, Neo4j, Penetration Testing, Python, RAG, SIEM, SOC, Splunk, Web3 About the job Experience: •3+ years of SOC/security operations or penetration testing experience with deep understanding of attack chains and defensive architectures Required Skills: •Use LLMs and AI tools to automate generation, testing, and continuous optimization of SIEM/EDR/NDR detection rules based on threat intelligence and ATT&CK TTPs •Build a full detection rule lifecycle management system: auto-generate → validate → deploy → evaluate → iterate •Design and implement AI/ML-based alert triage, prioritization, and false-positive suppression models to continuously reduce MTTD/MTTR •Build AI Agent-driven alert automation pipelines: triage → context enrichment → automated verdict → response recommendation •Architect the “Security Brain”: integrate threat intelligence, attack graphs, asset context, and behavioral baselines into a unified knowledge graph •Research and deploy AI SOC platform capabilities: automated threat hunting, AI-assisted incident investigation, and natural language security query (SecOps Copilot) •Design detection scenarios from an attacker’s perspective, ensuring coverage of real APT TTPs (including Lazarus and other crypto-industry threat actors) •Research AI-assisted attack techniques (AI-generated payloads, automated reconnaissance, LLM-assisted social engineering) and proactively build corresponding detection capabilities Qualifications: •Proficient in major SIEM platforms (Splunk, Elastic etc.) and detection rule languages (SPL, KQL, Sigma) •Familiar with MITRE ATT&CK framework; able to map TTPs and design corresponding detection scenarios •Applied hands-on capability in alert investigation, incident response, or threat hunting •Strong Python engineering skills; able to independently develop AI-assisted security tools and automation scripts •Familiar with LLM application development (Prompt Engineering, RAG, Function Calling, AI Agent frameworks such as LangChain/AutoGen) •Practical experience applying AI/ML models to security use cases (alert classification, anomaly detection, NLP log analysis) •(Preferred) Experience designing or building AI SOC products or platforms (AI SOAR, SecOps Copilot, automated playbooks) •(Preferred) Familiarity with knowledge graphs and graph databases in security contexts •(Preferred) Web3 / cryptocurrency security background (on-chain attack detection, exchange security operations) •(Preferred) Security certifications (OSCP, GCIA, GCIH, GREM) or public research contributions (CVE, conference talks, open-source tools) Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!