Thales Group

Security AI Ops Engineer

Thales Group • $115K — $214K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, IT, Engineering, or related field.
  • 8+ years in a Security Operations Center, Managed Security Services, or technical workflow coordination role.
  • 2+ years of experience with AI/Gen AI-enabled tools or workflows.
  • Working knowledge of security operations, threat lifecycle, and common security frameworks (e.g., MITRE ATT&CK, NIST).
  • Practical experience with generative AI tools and enterprise ticketing/orchestration platforms (e.g., Jira, ServiceNow).
  • Familiarity with AWS Management Console, specifically Amazon Bedrock and OpenSearch.

Responsibilities

  • Supervise AI-assisted security workflows and manage Human-in-the-Loop triage queues.
  • Review and validate AI-generated threat summaries and triage recommendations.
  • Assign and track complex security investigations to appropriate analysts.
  • Curate and organize internal documentation and knowledge bases.
  • Audit AI outputs for accuracy and identify gaps in knowledge coverage.
  • Train security analysts on prompt best practices and AI tools usage.
  • Collaborate with Sales Engineering to demonstrate the value of services to clients.

Benefits

  • Elective Health, Dental, Vision, and various insurance options including Pet Insurance.
  • Retirement Savings Plan with company contribution and no vesting period.
  • Paid holidays and Paid Time Off.
  • Company provided Life Insurance, Disability, and Employee Assistance Program.
Full Job Description
Location: Austin, United States of America

Position Summary

Austin, Hybrid

Thales is looking for a Security AI Operations Engineer who bridges automated AI systems and human security operations. This role is responsible for the day-to-day supervision, quality control, and execution of AI-assisted security workflows.

Working alongside the Security Automation & AI Engineering team, the Specialist manages "Human-in-the-Loop" (HITL) triage queues, maintains and updates knowledge bases feeding generative models, audits AI outputs for accuracy, and ensures prioritized investigation tasks are routed seamlessly to front-line security analysts and consultants.

Key Areas of Responsibility

1. AI Workflow Supervision & Human-in-the-Loop (HITL) Routing
• Review and validate low-confidence alert enrichments, threat summaries, and triage recommendations generated by AI agents.
• Assign, dispatch, and track complex security investigations, policy changes, and incident response playbooks to appropriate Tier 2/3 analysts and consultants.
• Serve as the operational escalation point when automated pipelines encounter exceptions, edge cases, or platform integration errors.

2. Knowledge Base & Prompt Lifecycle Management
• Curate, clean, and organize internal runbooks, standard operating procedures (SOPs), threat intelligence, and product documentation stored in Amazon Bedrock Knowledge Bases and Amazon OpenSearch Service.
• Audit AI retrieval quality and document gaps in knowledge coverage that lead to model hallucinations or poor responses.
• Perform routine prompt adjustments and template maintenance, submitting structured enhancement tickets to engineering when underlying code changes are required.

3. Quality Assurance & Performance Auditing
• Regularly audit AI-generated outputs (incident summaries, triage context, customer reports) against human analyst benchmarks to ensure high fidelity and operational safety.
• Identify recurring false positives or hallucination patterns, collaborating directly with automation engineers to refine model guardrails and prompt evaluation datasets.
• Track and report on operational KPIs, including Mean Time to Respond (MTTR), task assignment velocity, and analyst AI adoption.

4. Team Enablement & Operational Feedback
• Train security analysts and services teams on prompt best practices, effective use of internal AI copilots, and feedback submission workflows.
• Gather front-line feedback and feature requests from security practitioners to help shape the automation engineering roadmap.

5. Sales
• Partner with the Sales Engineering team to develop and deliver Value-Added Services (VAS) proof-of-values (POVs), clearly demonstrating the business value and impact of these services.
• Collaborate with Account teams to accelerate time-to-value for Thales solutions among non-VAS customers, strengthening customer adoption, retention, and renewal outcomes.

Minimum Qualifications
• Bachelor's degree, in Computer Science, Cybersecurity, Information Technology, Engineering, or a related field.
• 8+ years in a Security Operations Center (SOC), Managed Security Services (MSSP), IT Service Management (ITSM), or technical workflow coordination role, including 2+ years working with AI/Gen AI-enabled tools or workflows.
• Cybersecurity Foundation: Working knowledge of security operations, threat lifecycle, alert triage, WAF, API security, and common security frameworks (e.g., MITRE ATT&CK, NIST).
• AI & Workflow Tooling: Practical experience interacting with generative AI tools, prompt workflows, and enterprise ticketing/orchestration platforms (e.g., Jira, ServiceNow, PagerDuty, or SOAR platforms).
• Cloud & Search Interface Familiarity: Working comfort navigating the AWS Management Console (specifically Amazon Bedrock, Amazon OpenSearch Dashboards, and CloudWatch metrics).
• Communication & Documentation: Strong technical writing skills with experience authoring security runbooks, SOPs, and structured process documentation.

Applicants must be legally authorized to work in the United States for any employer at the time of hire. This position is not eligible for visa sponsorship or for assuming sponsorship of an employment visa now or in the future.

Preferred Qualifications
• Data & Query Skills: Basic scripting ability in Python or experience writing search queries (OpenSearch / Elasticsearch queries, SQL, or Lucene).
• Workflow Automation: Experience configuring no-code/low-code workflow tools, webhook triggers, or ticketing automation rules.
• Industry Certifications:

o AWS Certified Security - Specialty or AWS Certified Solutions Architect - Associate/Professional

o AWS Certified AI Practitioner or Machine Learning - Specialty

o CISSP (Certified Information Systems Security Professional)

o GIAC Certifications: GCIH (Incident Handler), GCIA (Intrusion Analyst), GCDA (Detection Analyst), or GASAE (AI Security Automation Engineer)

Special Position Requirements

Schedule: Monday to Friday 9hrs shift (8hrs work + 1 hour lunch included) and occasional paid weekend on-calls (Once every 2 months)

#LI- Hybrid

#LI-TI1

This position will require successfully completing a post-offer background check. Qualified candidates with [a] criminal history will be considered and are not automatically disqualified, consistent with federal law, state law, and local ordinances.

The reference Total Target Compensation (TTC) market range for this position, inclusive of annual base salary and the variable compensation target, is between

Total Target Cash (TTC) 115,599.00 - 214,834.00 USD Annual

This reflects how companies in a similar industry and geographic region generally pay for similar jobs. This range helps the Company make pay decisions as one data point among many. Where a position falls within this range is also dependent on other factors including - but not limited to - the employee's career path history, competencies, skills and performance, as well as the company's annual salary budget, the customer's program requirements, and the company's internal equity. Thales may offer additional benefits and other compensation, depending on circumstances not related to an applicant's status protected by local, state, or federal law.

(For Internal candidate, if you need more information, please raise HR request through MyThales)

Thales provides an extensive benefits program for all full-time employees working 30 or more hours per week and their eligible dependents, including the following:
• Elective Health, Dental, Vision, FSA/HSA, Voluntary Life and AD&D, Whole Group Life w/LTC, Critical Illness, Hospital Indemnity, Accident Insurance, Legal Plan, Identity Theft, and Pet Insurance
• Retirement Savings Plan after 30 days of employment with a company contribution and a match, and with no vesting period
• Company paid holidays and Paid Time Off
• Company provided Life Insurance, AD&D, Disability, Employee Assistance Plan, and Well-being Program

About Thales Group

Thales Group is a multinational company that specializes in providing advanced technology solutions for the aerospace, defense, and security industries. The company was founded in 2000 and is headquartered in Courbevoie, France. Thales Group operates in over 50 countries and has a strong focus on innovation and research and development. The company's products and services include avionics, cybersecurity, transportation systems, and more. Thales Group is committed to sustainability and has been recognized for its efforts to reduce its environmental impact.
Learn more about Thales Group
Size
83,000 employees
Industry
Founded
1976

Similar Jobs

More Jobs at Thales Group

  • Thales Group
    Embedded Technical Consultant
    $121K — $202K *
    Austin, TX 78745 (Travis County)
    Telecommunications & Hardware
    Hybrid
  • Thales Group
    Security AI Ops Engineer
    $115K — $214K *
    Austin, TX 78745 (Travis County)
    Information Technology
    Hybrid
  • Thales Group
    Technical Project Manager
    $79K — $141K *
    Austin, TX 78745 (Travis County)
    Technical Services
    Hybrid
  • Thales Group
    Logistic Lead
    $57K — $120K *
    Chanhassen, MN 55317 (Carver County)
    Transportation
    In-Person
  • Thales Group
    PMO Specialist
    $80K — $143K *
    Austin, TX 78745 (Travis County)
    Business Services
    Hybrid

More Information Technology Jobs

Find similar Security AI Ops Engineer jobs: