Role Overview:
We are looking for a hands-on security professional who can lead our organizational security functions and apply agentic AI to practical cybersecurity challenges.
The ideal candidate will combine strong security operations experience with the ability to build, test, and demonstrate AI-assisted security workflows using OpenAI Codex or comparable agent harnesses and frameworks. Candidates must bring current implementation experience and be ready to contribute to agentic AI projects from the outset.
Key Responsibilities:
- Security leadership and operations
- Own and improve day-to-day security operations across endpoints, identities, networks, cloud infrastructure, applications, and business data.
- Maintain a prioritized security improvement roadmap based on business risks, operational needs, and audit findings.
- Lead incident investigation, containment, recovery, root-cause analysis, and corrective actions.
- Manage vulnerability identification, risk-based prioritization, remediation coordination, and closure verification.
- Implement and improve controls involving SIEM, EDR/XDR, identity and access management, MFA, endpoint management, email security, and data loss prevention.
- Maintain security policies, incident response playbooks, access review processes, and security awareness initiatives.
- Coordinate with IT, engineering, business stakeholders, and external security providers to deliver measurable improvements.
- Report security posture, significant risks, incidents, and remediation progress to management.
- Agentic AI and security automation
- Identify security processes where AI agents can reduce manual effort, improve investigation quality, or accelerate remediation.
- Build and maintain workflows using Codex or comparable tools that can work with code repositories, execute approved tools, interact with APIs, and produce verifiable outputs.
- Integrate AI workflows with security platforms, ticketing systems, repositories, and internal knowledge sources.
- Review and test AI-generated scripts, detections, findings, and remediation proposals before operational use.
- Apply appropriate controls for sensitive data, credentials, tool permissions, execution environments, audit logging, and human approval of consequential actions.
- Evaluate workflows for accuracy, false positives, reliability, cost, and measurable operational benefit.
Required Skills & Experience:
- At least 5–6 years of experience leading and delivering organizational security functions, including responsibility for an environment supporting 200 or more users.
- Demonstrated ownership of security outcomes, including incident handling, control implementation, risk reduction, and remediation follow-through.
- Strong working knowledge of endpoint security, identity security, network security, cloud security, and data protection.
- Hands-on experience with SIEM and EDR/XDR platforms, vulnerability management tools, and security investigations.
- Ability to write, understand, troubleshoot, and maintain Python, PowerShell, or Bash scripts.
- Practical experience with Git, APIs, structured data, and automation integrations.
- Current hands-on experience building agentic AI workflows using Codex or comparable agent harnesses. General chatbot usage or prompt-writing experience alone is insufficient.
- Ability to explain an agent’s tools, permissions, context, execution steps, failure modes, and validation approach.
- Strong communication skills, with the ability to translate technical findings into clear business risks and actions.
Examples of Relevant AI Projects:
Candidates should be able to demonstrate one or more practical use cases such as:
- Alert investigation: Enrich security alerts with relevant logs and asset context, then produce evidence-backed investigation summaries.
- Phishing analysis: Examine suspicious emails, extract indicators, correlate available evidence, and recommend response actions.
- Vulnerability management: Combine scanner findings with asset criticality and exposure to prioritize remediation and prepare tickets.
- Detection engineering: Develop and test detection queries or rules against representative security events.
- Application security: Investigate code vulnerabilities, validate findings in an isolated environment, and propose tested fixes for review.
- Security assurance: Collect control evidence, identify configuration gaps, and draft reports linked to supporting records.
Preferred Qualification:
- Experience securing Microsoft 365, Azure, AWS, Google Cloud, or comparable enterprise environments.
- Familiarity with ISO 27001, NIST CSF, CIS Controls, and MITRE ATT&CK.
- Experience with SOAR, CI/CD security, infrastructure as code, or container security.
- Familiarity with prompt injection, unsafe tool execution, excessive agent permissions, and sensitive-data exposure risks.
- Relevant certifications such as CISSP, CISM, GCIH, GCIA, Security+, or vendor security certifications.
Practical Assessment:
Shortlisted candidates will be asked to demonstrate a working AI-enabled security workflow using sanitized or synthetic data and explain:
- The security problem and their personal contribution.
- The architecture, integrations, and agent permissions.
- How outputs were tested and verified.
- How errors, sensitive information, and approval requirements are handled.
- The observed results, limitations, and operational value.
Success in This Role:
Success will be measured through improved security coverage, faster investigation and remediation, fewer recurring control gaps, and reliable AI workflows that deliver demonstrable benefits.