Design and implement AI-powered security workflows to reduce manual intervention and response times (detection, alert triage, compliance reporting, etc.)
Leverage generative AI tools (ChatGPT, Claude, etc.) to enhance incident response, threat detection, and compliance operations
Create intelligent systems for continuous compliance monitoring and reporting using existing security tools
Develop and maintain security automation for onboarding/offboarding, access controls, and device compliance
Orchestrate vulnerability management: scanning, triage, remediation and tracking
Use AI tools to analyze security metrics, identify trends, and generate actionable intelligence
Manage and optimize the security stack
Support cloud security posture in cloud infrastructure and SaaS environments
Manage corporate identity and access management systems with a security-first approach
Ensure secure device configuration and lifecycle management
Provide escalated technical support for infrastructure and endpoint issues
Ensure secure configuration and monitoring of corporate IT infrastructure
Act on privacy breaches and malware threats
Analyze IT specifications to assess security risks and collaborate with internal teams to ensure closure of security vulnerabilities
Write comprehensive reports including assessment-based findings, outcomes, and propositions for further system security enhancement
Develop and maintain incident response playbooks and procedures
Lead internal security awareness efforts, from phishing tests to trainings
Develop and carry out information security plans and policies
Requirements
BSc/BA in Computer Science, Information Technology, or a related field
Professional certification (e.g. CompTIA Security+, CISSP) is a plus
Demonstrated experience with AI tools and automation platforms
Hands-on experience with vulnerability scanners, endpoint protection, and security monitoring tools
Proven track record automating security and IT workflows using APIs, webhooks, and cloud-native tooling
Proficiency in Python, Bash, or similar scripting languages for automation
Strong grasp of network security, endpoint protection, and cloud security
Experience with endpoint management, user support, and IT infrastructure
Experience with log analysis and SIEM platforms (experience with budget-conscious solutions a plus)
Proven work experience as a System Security Engineer or Information Security Engineer
Understanding of OWASP, NIST, CSF, MITRE ATT&CK, and common security frameworks
Detailed technical knowledge of database and operating system security
Familiarity with web related technologies (web applications, web services, service oriented architectures) and of network/web-related protocols
An analytical mind with excellent problem-solving ability
Excellent written and verbal communication skills for both technical and business audiences
Decision-making skills and ability to manage multiple initiatives simultaneously with minimal supervision