Senior ML Engineer - Cyber Security

Altice USA

• $100K — $164K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Engineering, or related field, or equivalent years of experience
  • 7+ years of combined experience in security operations, incident response, and software engineering
  • Hands-on incident response and digital forensics experience, particularly with complex incidents
  • Proficient in programming (e.g., Python) and solid software engineering practices
  • Demonstrated experience with AI/ML technologies, including large language models and prompt engineering
  • Familiarity with SOAR, automation initiatives, and detection-as-code principles
  • Solid data engineering skills for handling large security datasets and APIs

Responsibilities

  • Design, build, and maintain AI/ML- and automation-driven capabilities for incident triage and response.
  • Develop and manage SOAR automations and detection-as-code pipelines with testing and version control.
  • Integrate LLM and agentic AI tools into SOC operations, including engineering prompts and guardrails.
  • Evaluate and optimize AI models for security functions, focusing on precision, recalls, and incident response metrics.
  • Create and manage data pipelines to support machine learning applications in security contexts.
  • Implement MLOps practices to ensure model performance and reliability in production environments.
  • Lead investigations for major security incidents and drive post-incident analysis to enhance systems and operations.

Benefits

  • Collaborative work environment promoting continuous learning and innovation
  • Opportunities for professional development and mentorship
  • Access to cutting-edge AI and security technologies
  • Participation in high-impact, meaningful projects in cybersecurity
  • Focus on responsible AI usage with initiatives for data governance and privacy
Full Job Description
Job Summary

As a Senior SOC Engineer (AI & Automation), you will design, build, and operate the AI, automation, and detection-engineering capabilities that power our Security Operations Center. Bridging security operations and software engineering, you will develop AI-driven detection, triage, and response tooling, integrate large language model (LLM) and agentic workflows into analyst operations, and ensure those capabilities are accurate, safe, measurable, and continuously improved. As a senior member of the team, you will also serve as a technical leader during major security incidents, leading investigations and turning lessons learned into stronger detections, automations, and playbooks.

Responsibilities
• Design, build, and maintain AI/ML- and automation-driven capabilities for alert enrichment, correlation, summarization, triage, and prioritization.
• Develop and maintain SOAR automations and detection-as-code pipelines that are version-controlled, tested, and peer-reviewed.
• Integrate LLM and agentic AI tooling into SOC workflows (copilots, auto-triage agents); engineer prompts, guardrails, and evaluation harnesses.
• Evaluate, benchmark, and tune AI models and tools for security use cases, measuring precision and recall, false-positive reduction, and impact on mean time to detect and respond (MTTD/MTTR).
• Build data pipelines and feature engineering from security telemetry to support detection and machine-learning use cases.
• Apply MLOps practices, including model versioning, monitoring, drift detection, and retraining, to security models running in production.
• Ensure responsible and secure AI use, including data governance, prompt-injection and model-abuse defenses, privacy, and output validation.
• Partner with detection engineers, SOC analysts, and incident responders to operationalize tooling and feed lessons learned back into models and automations.
• Serve as a senior escalation point and incident commander for complex and major incidents, coordinating cross-functional response and directing technical workstreams.
• Lead investigations and forensic analysis for escalated incidents and provide hands-on incident response support across on-premises and cloud environments.
• Own post-incident reviews and root cause analyses, translating lessons learned into new detections, automations, and playbook improvements.
• Develop, run, and mature incident-response playbooks and tabletop exercises (TTX) to validate and improve organizational readiness.
• Define and report detection and incident-response metrics (e.g., MTTD, MTTR) to measure and continuously improve SOC effectiveness.
• Mentor analysts and engineers, fostering a culture of continuous learning across AI-augmented and incident-response workflows, and promote an AI-first operating model across the SOC.

Qualifications
• Bachelor's degree in Computer Science, Engineering, or related field, or equivalent years of experience
• 7+ years of combined experience across security operations, incident response, and software engineering
• Hands-on incident response and digital forensics experience, including leading or coordinating response to complex and major incidents preffered
• Strong programming skills (e.g., Python) and sound software-engineering practices, including version control, CI/CD, and automated testing
• Hands-on experience building with AI/ML, including large language models, prompt engineering, retrieval-augmented generation (RAG), and/or agentic frameworks
• Experience with SOAR/automation and detection engineering (detection-as-code)
• Data engineering skills, including working with large security datasets, APIs, and pipelines
• Working knowledge of SOC operations and the incident lifecycle, including the MITRE ATT&CK framework, the NIST incident response lifecycle (NIST SP 800-61), the Cyber Kill Chain, and SANS PICERL
• Cloud security and cloud-platform experience
• Awareness of AI and LLM security risks, such as prompt injection and the OWASP LLM Top 10
• Ability to translate fluently between security and engineering stakeholders.

Preferred Qualifications
• MLOps experience deploying and maintaining models in production
• Relevant security and/or AI/ML certifications, including incident-response and forensics credentials (e.g., GCIH, GCFA, GCFE, GNFA) or CISSP/CISM

Pay is competitive and based on a number of job-related factors, including skills and experience. The starting pay rate/range at time of hire for this position in the posted location is $100,246.00 - $164,689.00 / year. The rate/range provided herein is the anticipated pay at the time of hire, and does not reflect future job opportunity.

We appreciate your interest in this opportunity. Applicants must be authorized to work for ANY employer in the U.S. Please note that at this time, we do not provide visa sponsorship for employment.

Similar Jobs

More Jobs at Altice USA

More Information Technology Jobs

Find similar Senior ML Engineer - Cyber Security jobs: