AI SecOps & Detection Lead
Job Location:
Blue Bell, PA - USA
Monthly Salary:
Not provided by the employer
Posted:
16 September 2026 (6 hours ago)
Application Deadline:
14 December 2026
Vacancies:
1 Vacancy
Job Summary
This role builds and operates the AI security lifecycle across the organization structured around three core questions: do we have full visibility into AI in use across our environment can we effectively react and respond when something goes wrong and are we feeding what we learn back into preventative measures. The lead integrates AI-specific findings from tools like Wiz and AIM into existing SOC workflows so that AI-related events are detected and triaged alongside everything else not sitting in a separate queue. This person stands up shadow AI discovery so the organization is not relying on self-reporting to know what is out there and develops the AI-specific incident response playbooks and tabletop exercises that ensure the SOC is ready when an AI-related incident hits. On the prevention side this role closes the loop translating discovery findings and incident patterns into actionable remediation requests and tighter controls in partnership with teams across the organization. This person also supports the operational governance that keeps the program auditable maintaining the AI tool inventory risk assessments and documentation trail in coordination with internal leadership. To perform all of these tasks the role will partner closely with the SOC engineering compliance and security leadership Required Skills - Enterprise Security Operations (SecOps): Deep hands-on expertise in SIEM/SOAR platforms detection engineering alert triage and incident response within complex enterprise environments. Asset Discovery & Telemetry Mapping: Proven ability to build and operationalize asset discovery programs specifically creating visibility into cloud and on-prem AI tools workloads and integrations. AI Threat Landscape Expertise: Strong working knowledge of AI-specific vectorssuch as prompt injection model poisoning agent credential abuse and data exfiltrationand how to turn them into actionable detection logic. Workflow Integration & Optimization: Skill in embedding specialized security findings (e.g. from Wiz/AIM) into existing unified SOC workflows rather than creating inefficient parallel processes. Metrics-Driven Risk Management: Ability to quantify and improve detection efficacy identify coverage gaps and track risk posture trends to influence executive prioritization and investment decisions. Job Duties - Unify SOC Workflows: Integrate AI-specific alerts and findings from tools like Wiz and AIM directly into existing SOC pipelines so they are triaged alongside standard security events. Implement Shadow AI Discovery: Build and operate automated telemetry-driven discovery mechanisms to locate unauthorized AI usage without relying on user self-reporting. Develop Incident Response Playbooks: Create tailored AI incident response procedures and lead tabletop exercises to ensure the SOC is equipped to handle live AI-related threats. Drive Preventative Remediation: Translate discovery insights and incident patterns into actionable remediation requests partnering with broader teams to implement tighter security controls. Maintain Operational Governance: Manage the organizations AI tool inventory execute risk assessments and maintain a robust documentation trail to ensure the program remains auditable. Job Requirements - Cross-Functional Collaboration: Ability to partner closely and communicate effectively with diverse stakeholders across the SOC engineering compliance and security leadership teams. Telemetry-Driven Execution: Experience managing visibility across hybrid environments (both cloud and on-premises) to maintain a continuous inventory of AI workloads. Strategic Continuous Improvement: A mindset focused on closing the security lifecycle loopensuring that response lessons are actively fed back into prevention and risk reduction strategies. Job Responsibilities Unify SOC Workflows: Integrate AI-specific alerts and findings from tools like Wiz and AIM directly into existing SOC pipelines so they are triaged alongside standard security events. Implement Shadow AI Discovery: Build and operate automated telemetry-driven discovery mechanisms to locate unauthorized AI usage without relying on user self-reporting. Develop Incident Response Playbooks: Create tailored AI incident response procedures and lead tabletop exercises to ensure the SOC is equipped to handle live AI-related threats. Drive Preventative Remediation: Translate discovery insights and incident patterns into actionable remediation requests partnering with broader teams to implement tighter security controls. Maintain Operational Governance: Manage the organizations AI tool inventory execute risk assessments and maintain a robust documentation trail to ensure the program remains auditable.
Required Skills:
RISK ASSESSMENTSENTERPRISE SECURITY