AI & Security Infrastructure Integration Engineer
Listed on 2026-09-12
-
IT/Tech
Cybersecurity
Position Overview
As an AI & Security Infrastructure Integration Engineer on our team, you will bridge the gap between traditional security infrastructure and modern programmatic defense. You will operate, maintain, and evolve the network security infrastructure utilized by our 24x7x365 mission‑critical security operations team. Your primary focus will be transforming manual workflows into automated pipelines by leveraging Python, developing robust API integrations, and exploring AI/LLM orchestration to rapidly scale threat detection and response capabilities.
PrimaryResponsibilities
- Develop and maintain Python-based tools, scripts, and frameworks to automate routine security infrastructure tasks, policy deployments, and system health checks.
- Design, build, and integrate custom APIs to connect disparate cybersecurity tools (SIEM, IDS/IPS, Netflow, and threat intelligence feeds) into a cohesive, orchestrated ecosystem.
- Evaluate and integrate AI/ML technologies and LLM-based solutions to optimize alert triage, automate playbook generation, and accelerate incident analysis for the SOC team.
- Operate, maintain, and upgrade core cybersecurity capabilities (IDS/IPS, Netflow, SIEM, Snort, Linux, and Virtualization environments).
- Manage high-priority tasks, infrastructure outages, and routine patching/updates.
- Maintain precise network topology and elevation diagrams for all managed security equipment.
- Ensure strict adherence to government compliance standards and coordinate changes through official Change Control Boards (CCB).
- Advise and strategize with program and government leadership on engineering modern, code-driven security infrastructure solutions.
- Active DoD Secret Required with DoD TS/SCI Eligibility
- Must have DoD 8570 IAT II certification OR meet DoD 8140 Intermediate Cyber Defense Infrastructure Support Specialist requirements prior to start
- Must obtain DOD-8570 CSSP Infrastructure Support certification within 6 months of hire.
- Bachelor's degree with 8+ years of professional experience (additional relevant military or work experience may be considered in lieu of a degree).
- 2+ years of hands-on experience deploying and maintaining cybersecurity tools (especially IDS/IPS, SIEM, or firewalls).
- Strong, practical knowledge of network protocols, traffic analysis, and routing/switching.
- Proficiency in Linux administration and shell scripting (Bash).
- Strong proficiency in Python (specifically writing scripts for system automation, network interaction, and data parsing).
- Demonstrated experience working with RESTful APIs, JSON/YAML data structures, and webhooks to integrate security platforms.
- Exposure utilizing or fine‑tuning AI/ML models, prompt engineering, or integrating AI APIs into operational workflows.
- Hands‑on experience with automation/orchestration frameworks (e.g., Ansible, Terraform, Puppet, or Chef).
- Practical familiarity with Intelligence‑Driven Defense, the Cyber Kill Chain, and mapping controls to the MITRE ATT&CK framework.
- Prior experience working as or directly supporting a Security Operations Center (SOC) analyst team.
If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares.
Pay RangePay Range $ - $
About LeidosLeidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).