Quantum Sky is searching for a Principal AI SOC Engineer to drive efficiency, velocity, and operational effectiveness across Security Operations Centers supporting federal missions. This is a hands-on engineering role for someone who has worked inside a federal watch floor, has built and integrated SOC tooling at enterprise scale, and knows how to turn analyst pain points into production-grade automated capability.
The ideal candidate is a builder and a leader: an engineer who writes production Python daily, is deeply fluent in Splunk, and has carried AI/ML and GenAI capabilities through a real software development lifecycle — versioned, tested, evaluated, monitored, and governed — inside a federal agency's accreditation and oversight regime. The role blends technical execution with engineering leadership, including backlog ownership in Jira, design documentation in Confluence, delivery oversight, code review, and mentoring.
Responsibilities:
AI Capability Engineering
- Design and engineer AI-powered SOC capabilities that improve analyst efficiency, reduce alert fatigue, and accelerate detection and response.
- Apply AI/ML and GenAI techniques to concrete SOC problems: alert enrichment, triage and prioritization, entity and campaign correlation, investigation summarization, phishing and insider-threat triage, and automated response recommendation.
- Own the full AI SDLC for delivered capabilities — problem framing, data curation and labeling, model or prompt development, evaluation harness design, CI/CD integration, ATO-compatible deployment, monitoring for drift and regression, and rollback.
- Build evaluation and test methodology for AI-enabled workflows: golden datasets, regression suites, precision/recall and false-positive measurement, and human-in-the-loop review gates before any capability influences analyst action or containment.
- Implement guardrails, output validation, prompt and response logging, and decision traceability so AI-assisted findings are auditable and defensible to agency leadership, oversight bodies, and assessors.
- Engineer AI capabilities consistent with federal AI governance expectations — current OMB AI guidance, agency Chief AI Officer requirements, AI use case inventory reporting, and NIST AI RMF — including the additional practices that apply when a capability is designated high-impact.
- Ensure AI capabilities handle sensitive government data appropriately, including PII and law enforcement sensitive material, with data minimization, retention controls, and model-training exclusions.
SOC Engineering and Automation
- Build and evolve detection and response pipelines across SIEM, SOAR, EDR, email security, identity, and cloud security platforms, with Splunk as the primary analytic platform.
- Engineer Splunk content and infrastructure: advanced SPL, data models and CIM normalization, correlation searches and notable event tuning in Enterprise Security, ingest and index architecture, and performance tuning for high-volume telemetry.
- Build and maintain SOC automation in Python — SOAR playbooks, custom microservices, API-driven integrations, and AI-driven decisioning across security and infrastructure controls.
- Engineer onboarding and normalization pipelines for telemetry from organizationally distinct components with heterogeneous tooling, ownership models, and data-sharing constraints.
- Support enterprise event logging maturity requirements, including log source coverage, retention tiering, and log integrity.
- Build and maintain integrations supporting federal reporting and directive compliance, including CISA sensor and CDM data flows, Binding Operational and Emergency Directive response, and incident notification timelines.
- Improve SOC velocity and throughput by automating repetitive analyst tasks and standardizing response patterns into reusable, tested components.
- Support design of scalable SOC architectures for high-volume telemetry and real-time workflows in a 24/7 operations environment.
- Maintain a tool-agnostic engineering mindset; integrate Elastic, Microsoft Sentinel and Defender, or cloud-native services where the mission calls for it.
Delivery and Technical Leadership
- Own and groom the engineering backlog in Jira; prioritize, decompose, estimate, and ship production-ready increments on a predictable cadence against contract deliverables.
- Translate analyst user stories and operational requirements into concrete technical designs; document architecture decisions, runbooks, SOPs, and capability documentation in Confluence.
- Set engineering standards and patterns for AI-enabled SOC capabilities — code review expectations, testing requirements, repository structure, CI/CD pipelines, and secure development practices aligned to NIST SSDF.
- Partner with government stakeholders, analysts, and fellow engineers to deliver solutions, setting a high technical bar through hands-on contribution and shared ownership.
- Mentor engineers on Python, Splunk, and AI engineering practice.