×
Register Here to Apply for Jobs or Post Jobs. X

AI SOC Engineer

Job in San Francisco, San Francisco County, California, 94199, USA
Listing for: ByLabs
Full Time position
Listed on 2026-06-21
Job specializations:
  • IT/Tech
    Cybersecurity, AI Engineer (Applied/Software), Security Management & Operations
Salary/Wage Range or Industry Benchmark: 125000 - 150000 USD Yearly USD 125000.00 150000.00 YEAR
Job Description & How to Apply Below

We are looking for an AI SOC Engineer who combines deep offensive/defensive security expertise with hands‑on AI engineering skills. You will be the core builder of our “Security Brain” — leveraging LLMs and AI agents to automate detection rule generation, suppress alert noise, and drive fully automated security operations. Using AI to fight AI, you will help Bybit’s SOC stay ahead of increasingly sophisticated, AI‑powered adversaries.

Key Responsibilities
  • Use LLMs and AI tools to automate generation, testing, and continuous optimization of SIEM/EDR/NDR detection rules based on threat intelligence and ATT&CK TTPs
  • Design and implement AI/ML‑based alert triage, prioritization, and false‑positive suppression models to continuously reduce MTTD/MTTR
  • Architect the “Security Brain”: integrate threat intelligence, attack graphs, asset context, and behavioral baselines into a unified knowledge graph
  • Research and deploy AI SOC platform capabilities: automated threat hunting, AI‑assisted incident investigation, and natural language security query (Sec Ops Copilot)
  • Design detection scenarios from an attacker’s perspective, ensuring coverage of real APT TTPs (including Lazarus and other crypto‑industry threat actors)
  • Research AI‑assisted attack techniques (AI‑generated payloads, automated reconnaissance, LLM‑assisted social engineering) and proactively build corresponding detection capabilities
  • Track AI SOC frontier research (LLM for Security, AI Agent for SOC, Agentic Security Operations) and drive internal adoption
Major Requirements
  • 3+ years of SOC/security operations or penetration testing experience with deep understanding of attack chains and defensive architectures
  • Proficient in major SIEM platforms (Splunk, Elastic etc.) and detection rule languages (SPL, KQL, Sigma)
  • Familiar with MITRE ATT&CK framework; able to map TTPs and design corresponding detection scenarios
  • Hands‑on experience in alert investigation, incident response, or threat hunti
  • ng Strong Python engineering skills; able to independently develop AI‑assisted security tools and automation scripts
  • Familiar with LLM application development (Prompt Engineering, RAG, Function Calling, AI Agent frameworks such as Lang Chain/Auto Gen)
  • Practical experience applying AI/ML models to security use cases (alert classification, anomaly detection, NLP log analysis)
  • (Bonus) Experience designing or building AI SOC products or platforms (AI SOAR, Sec Ops Copilot, automated playbooks)
  • (Bonus) Familiarity with knowledge graphs and graph databases (Neo4j, etc.) in security contexts
  • (Bonus) Web3 / cryptocurrency security background (on‑chain attack detection, exchange security operations)
  • (Bonus) Security certifications (OSCP, GCIA, GCIH, GREM) or public research contributions (CVE, conference talks, open‑source tools)
#J-18808-Ljbffr
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary