Role Overview
We're hiring someone who builds AI systems for security. You'll design and ship accelerators, turnkey solutions, and standalone capabilities that go into production for enterprise clients across energy, financial services, healthcare, and technology. The ceiling on this role is high: we're working toward a security-domain LLM that generalizes across industries, and the person in this seat will be part of making that real. That takes two things at once. You must engineer — Python, ML, agent frameworks, retrieval, evaluation, deployment. And you must understand security at the fundamentals level.
Responsibilities
- Delivery accelerators — AI-assisted alert triage, evidence summarization, automated assessment and reporting that compresses weeks of consulting into days
- Turnkey solutions — packaged, repeatable, deployable capabilities with documentation and handover
- Agentic systems — multi-step workflows with tool use, retrieval, memory, and guardrails, integrated into SenOptic, our TechFinSecOps platform
- Domain LLM work — dataset curation, synthetic data generation, fine-tuning, grounding, and evaluation
- Evaluation harnesses — because "it looked right in the demo" is not a standard we accept for anything touching client security decisions
Requirements
- Python and software craft — clean, typed, testable code; Git, Docker, CI/CD, Linux, REST/API development (FastAPI or similar), data pipelines
- LLM and agent engineering — orchestration frameworks (LangGraph, LangChain, LlamaIndex, CrewAI, or equivalent); RAG in practice — chunking, embeddings, vector stores, hybrid and re-ranked retrieval; tool calling, structured output, context management, MCP; prompt engineering as a versioned, tested discipline
- ML foundations — PyTorch or scikit-learn, anomaly detection and clustering; fine-tuning and adaptation (LoRA/QLoRA, PEFT); evaluation and observability (eval sets, hallucination and regression measurement, tracing); the judgment to know when a rule or small classifier beats an LLM
- Security domain depth — understanding attack paths, controls, identity, trust boundaries, risk. Genuine depth in at least two: Offensive security (VAPT, web and API testing (OWASP Top 10), AD attack paths, privilege escalation, cloud misconfiguration), External attack surface management, Detection & response / SOC (detection engineering, Sigma rules, KQL/SPL, MITRE ATT&CK, threat hunting, incident response, SOAR), Identity & access management (OAuth 2.0, OIDC, SAML, SCIM, RBAC/ABAC, Zero Trust), Threat intelligence (STIX/TAXII, MISP), or GRC (NIST CSF 2.0, ISO 27001, SOC 2, PCI-DSS, HIPAA)
- Securing AI itself — OWASP Top 10 for LLM Applications and MITRE ATLAS; prompt injection, data leakage, insecure output handling, guardrails
- B.E./B.Tech/M.Tech/MCA in CS, Cybersecurity, IT, or related
- Evidence of building (GitHub, CTF profiles, home lab, published research, open-source contributions, deployed side projects)
- Clear technical writing
- Self-direction
Skills
- Python
- PyTorch
- LangChain
- Docker
- FastAPI