Job Specification
Job Title: Senior AI Security (SOC) Engineer
Location: Hybrid (3 days in London office)
Who we’re looking for
We’re looking for aSeniorAISecurity (SOC)Engineer who thrives on solving complex issues,whobuildsAI SoC workflowsand helpsand mentorsothers,while delivering the best possible technical service.
We want someone who can work well in a team but beself-motivated. We are looking for someone that can understand complex IT/Securityissues andarticulate clearly to technical andnon-technicalpeople alike.Someone who is always looking for improvements to our service.
The team
We support our international offices by developing, rolling out and maintaining our systems and processes, using cutting-edge software and hardware.
What you’ll do
We are seeking aSeniorAISecurityEngineer who will supporttheCyber Defencecapability.This role will be focused oncontributing to the development of an agentic orchestration platform for the SOC (in response tocyberfrontier).
You will deliver practical automation and AI-enabled workflows across our SOC stack-Cyware, Azure, n8n (future/expanding),Cribl Stream and AWS Bedrock, to name a few. The aim isto reduceSOCanalyst toil, improve triage quality and speed up response, with appropriate governance for a regulated environment.
The successful candidate will combine strong software engineeringandcloud engineeringskills.
You will:
- Build and improve SOC automations and playbooks (triage, enrichment, case handling, response actions).
- Develop AI-assisted workflows (e.g., summarisation, guided triage, recommended next steps, knowledge lookup over runbooks).
- Develop and secure AI agents and their associated skills, designing robust controls for safe and effective transfer of control.
- Integrate tools and data sources using APIs/webhooks and maintain reliable, observable workflows.
- Partner with SOC/IR to move from prototype to production with auditability, safety controls, and documentation.
- Track outcomes (e.g., time-to-triage/close, automation success rates, alert noise reduction).
What we’re looking for
- Strong hands-on experience in security engineering within/for a SOC, especially automation (SOAR or equivalent).
- Comfortable building integrations and workflows with scripts/code (e.g., Python/PowerShell) and APIs.
- Working knowledge of cloud environments (Azure essential; AWS useful) and common security telemetry.
- Practical experience applying LLMs/AI in operations (or strong interest with evidence of delivery mindset).
- Able to work iteratively with analysts, write clear runbooks, and operate calmly in an incident-driven environment.
- Someone who uses LLMs to assist with theirowndevelopmentwork.
Nice to have:
- CI/CD, Github Actions.
- n8n.
- Kubernetes (AKS in particular).
- Terraform.
- Ansible.
General Skills:
- Good people skills.
- Good time management.
- Self-starter.
- Good communication skills.
- Knowledge and experience of using Agile methodologies e.g. SAFe, SCRUM, Kanban.
- Has the ability to translate concepts into reality.
- Understand the importance of metricsand statisticswhen measuring performanceandcapacity.
- Excellent command of the English language, both written and spoken.
Personal Attributes:
- Positive attitude, capable of remaining positive when under immense pressure.
- A good communicator, and able towork with teams on a journey ofglobalisationand automation.
- Someone who never accepts the status-quo. Someone who challenges why things are done the way they are.
- Someone who is capable of ‘green-field’ thinking. Capable of imaging how the global platformcouldlook, and capable of creating a strategy to get us there.
- Friendly, approachable, enjoys working with people from a variety of backgrounds.
- Work well with others in a collaborative environment.
- Continuous improvement mind-set, challenges the status quo and seeks self- improvement.
By applying for this role, you consent to SGI contacting you by telephone regarding recruitment services, market updates, and relevant business opportunities
We believe in equal opportunity for all and actively encourage applications from diverse backgrounds, experiences, and perspectives.
Source Group International Ltd is acting as an Employment Business in relation to this vacancy
#J-18808-Ljbffr
AI Security (SOC) Engineer employer: Source Technology Limited
Source Technology Limited is an exceptional employer, offering a dynamic work environment in the heart of London where innovation meets collaboration. Employees benefit from a strong culture of professional development, with ample opportunities for growth and learning within the fast-paced financial sector. Join us to be part of a transformative journey that not only enhances your career but also contributes to impactful projects in fund migration.