Defend your organization proactively with automated security solutions that streamline threat detection and response.
AI Engineer, Security Operations (Remote, US)
About Us
For more than four decades, Compuquip Cybersecurity has designed, implemented, and operated security programs for organizations that cannot afford to get it wrong. Our teams deliver 24x7 detection and response, managed firewall and network security, vulnerability management, and offensive security services across cloud, network, and endpoint environments.
We are evolving how those services are delivered. Rather than having analysts triage every alert and engineers hand-write every change, we are building AI systems that handle reasoning work at scale so our people can focus on judgment, escalation, and customer outcomes. This work runs against live customer environments with real service commitments attached.
About The Role
You would join a small AI engineering team as its third member. Early systems are running in production, and much more has been decided than built. There is no legacy platform to inherit and no established playbook, which means you will have genuine influence over what this team becomes.
The work is highly collaborative by design. You will spend real time with SOC analysts, firewall engineers, and architects, sitting in their queues and learning how they actually work before writing a line of code. Translating their expertise into systems that scale is the core of the job, and it only works if you enjoy that partnership. You will report into operations leadership with a short path to decisions.
The problems are hard and largely unsolved. Alert triage that a senior analyst will trust. Firewall policy reasoning that holds up in a live change window. Retrieval across inconsistent ticket and telemetry data. There is no reference implementation to copy, so you will be testing ideas, shipping them, and finding out quickly whether you were right.
We are looking for someone earlier in their career who is capable, curious, and moving fast. If you have been building AI systems on your own time because the problems interest you, and you want a role where that becomes the work, we would like to talk.
What You Will Build
-
Agentic alert triage. Multi-step agents that enrich, correlate, and reason over SIEM detections, then close, hold, or escalate based on narrow, expert-approved criteria. This includes the guardrails, confidence handling, and human review design that makes it safe to run overnight.
-
Expert knowledge systems. Frameworks that allow analysts and engineers to encode runbooks, detection logic, and escalation rules into AI workflows without writing code, and to update them as tradecraft changes.
-
Retrieval over operational security data. Retrieval systems spanning ticketing platforms, SIEM and EDR telemetry, vulnerability scan output, firewall configurations, and customer documentation.
-
Network and firewall automation. AI-assisted policy review, change validation, configuration drift detection, and rule cleanup across multi-vendor firewall environments.
-
Evaluation infrastructure. Test harnesses, regression suites, and feedback loops that let our domain experts measure whether a system is actually improving, using analyst verdicts as ground truth.
-
Platform integrations. The infrastructure connecting AI systems to the platforms our delivery teams use every day, including SIEM, EDR, ITSM, vulnerability management, and firewall management.
What You Will Bring
Software engineering
-
Two or more years building production software, or a shorter record with work that clearly demonstrates the ability. We are more interested in what you have shipped than how long you have been shipping.
-
Strong Python and TypeScript. You can build a service, a data pipeline, and a usable internal interface without waiting on someone else.
-
Solid fundamentals in API design, data modeling, asynchronous processing, testing, and CI/CD. You write code that holds up in production.
-
Comfort deploying and troubleshooting your own work on cloud infrastructure, ideally AWS, with containers and infrastructure as code.
AI systems
-
Experience building LLM-powered systems that other people relied on, including the practical problems of latency, cost, inconsistent output, and failure modes that only appear at scale.
-
Working depth in prompt and context design, tool use, agent orchestration, and retrieval architecture.
-
A clear point of view on how to measure whether a change improved a system, backed by something you have built to test it.
-
Familiarity with the current tooling landscape, including agent frameworks, MCP, hybrid search, and model routing, along with the judgment to know when a simpler approach is better.
Security and infrastructure exposure
-
Meaningful exposure to security operations, network security, or infrastructure work, either through direct experience or by building tools for teams doing that work.
-
Enough grounding to read a firewall rule, follow an alert investigation, or reason about a network path and hold a substantive conversation with the engineer beside you. We will teach the rest and expect you to learn quickly.
-
Real curiosity about how attacks work and how defenders respond.
How you work
-
You are comfortable with ambiguity. Requirements here are discovered through collaboration.
-
You communicate clearly with engineers and non-engineers alike, and you are willing to tell a senior analyst when a runbook does not hold up.
-
You take ownership of outcomes rather than tasks, and you follow through without being managed.
Nice To Haves
-
Experience within or alongside an MSSP, MDR provider, or enterprise SOC.
-
Hands-on work with SIEM platforms such as Sentinel, Rapid7, or Crowdstrike, or with EDR and vulnerability management tooling.
-
Firewall and network engineering exposure across Palo Alto, Fortinet, or Checkpoint, including policy management, change workflows, or automation.
-
Open source contributions, a side project with real users, or internal developer platform work.
How We Work
Three things define how we operate:
We get it done. We ship, we measure, and we adjust. We would rather put something useful in front of an analyst this week than spend a quarter designing the perfect version.
We work as a team. Nothing here gets built in isolation. Our best work comes from engineers, analysts, and architects solving problems in the same room, and we expect people to ask for help early and offer it freely.
We are customer obsessed. Every system we build is measured by whether it makes a customer safer or a service better. That is the standard, and it applies to internal tooling as much as anything a customer sees.
Compensation:
Base salary is commensurate with experience, with a discretionary performance bonus, health and dental coverage, and fully remote work within the United States. We will be direct about the number early in the process.
Beyond compensation, the opportunity here is scope. This is a small team inside a 40-year-old security company that has committed to rebuilding how it delivers services, with real budget, live customers, and enough runway to build things properly. What you ship in your first year will shape what this practice becomes.
Apply for this job by reaching out to ai@compuquip.com with your resume and cover letter.