Senior ML Engineer Cyber Security
Norwalk, CA - USA
Job Summary
Are you looking to Optimize your life Start your exciting path to a rewarding career today!
We are Optimum a leader in the fast-paced world of connectivity and were seeking driven and enthusiastic professionals to join our team empower lives fuel businesses and drive innovation. Connectivity is now longer a luxury but a necessity. A career at Optimum means youll be enabling progress and enhancing lives by providing reliable high-speed connectivity solutions that keep the world connected. Our successes now and in the future are powered by our amazing product a commitment to our people and culture and the connections we make in our communities.
If you are resourceful collaborative and passionate about delivering consistent excellence Optimum is for you!
As a Senior SOC Engineer (AI & Automation) you will design build and operate the AI automation and detection-engineering capabilities that power our Security Operations Center. Bridging security operations and software engineering you will develop AI-driven detection triage and response tooling integrate large language model (LLM) and agentic workflows into analyst operations and ensure those capabilities are accurate safe measurable and continuously improved. As a senior member of the team you will also serve as a technical leader during major security incidents leading investigations and turning lessons learned into stronger detections automations and playbooks.
Design build and maintain AI/ML- and automation-driven capabilities for alert enrichment correlation summarization triage and prioritization.
Develop and maintain SOAR automations and detection-as-code pipelines that are version-controlled tested and peer-reviewed.
Integrate LLM and agentic AI tooling into SOC workflows (copilots auto-triage agents); engineer prompts guardrails and evaluation harnesses.
Evaluate benchmark and tune AI models and tools for security use cases measuring precision and recall false-positive reduction and impact on mean time to detect and respond (MTTD/MTTR).
Build data pipelines and feature engineering from security telemetry to support detection and machine-learning use cases.
Apply MLOps practices including model versioning monitoring drift detection and retraining to security models running in production.
Ensure responsible and secure AI use including data governance prompt-injection and model-abuse defenses privacy and output validation.
Partner with detection engineers SOC analysts and incident responders to operationalize tooling and feed lessons learned back into models and automations.
Serve as a senior escalation point and incident commander for complex and major incidents coordinating cross-functional response and directing technical workstreams.
Lead investigations and forensic analysis for escalated incidents and provide hands-on incident response support across on-premises and cloud environments.
Own post-incident reviews and root cause analyses translating lessons learned into new detections automations and playbook improvements.
Develop run and mature incident-response playbooks and tabletop exercises (TTX) to validate and improve organizational readiness.
Define and report detection and incident-response metrics (e.g. MTTD MTTR) to measure and continuously improve SOC effectiveness.
Mentor analysts and engineers fostering a culture of continuous learning across AI-augmented and incident-response workflows and promote an AI-first operating model across the SOC.
Bachelors degree in Computer Science Engineering or related field or equivalent years of experience
7 years of combined experience across security operations incident response and software engineering
Hands-on incident response and digital forensics experience including leading or coordinating response to complex and major incidents preffered
Strong programming skills (e.g. Python) and sound software-engineering practices including version control CI/CD and automated testing
Hands-on experience building with AI/ML including large language models prompt engineering retrieval-augmented generation (RAG) and/or agentic frameworks
Experience with SOAR/automation and detection engineering (detection-as-code)
Data engineering skills including working with large security datasets APIs and pipelines
Working knowledge of SOC operations and the incident lifecycle including the MITRE ATT&CK framework the NIST incident response lifecycle (NIST SP 800-61) the Cyber Kill Chain and SANS PICERL
Cloud security and cloud-platform experience
Awareness of AI and LLM security risks such as prompt injection and the OWASP LLM Top 10
Ability to translate fluently between security and engineering stakeholders.
Preferred Qualifications
MLOps experience deploying and maintaining models in production
Relevant security and/or AI/ML certifications including incident-response and forensics credentials (e.g. GCIH GCFA GCFE GNFA) or CISSP/CISM
At Optimum every action and interaction we take part in is driven by our three Guiding Principles: Do Whats Right Drive One Optimum and Make It Happen. These arent just words they help us build trust create real community and embrace new ways of thinking. Our employees are empowered to do the right thing for our customers and co-workers and to recognize and reward these behaviors when we see them. Its all part of the bigger picture of Be The Difference where each employee knows they have the power to enact real change share new ideas and understand that learning never stops.
If you have the drive to succeed and are ready to embark on a thrilling career seize this opportunity today and join our winning team. Together well shape the future of connectivity.
All job descriptions and required skills qualifications and responsibilities for a particular position are subject to modification by the Company from time to time in the Companys discretion based on business necessity.
We are an Equal Opportunity Employer committed to recruiting hiring and promoting qualified people of all backgrounds regardless of gender race color creed national origin religion age marital status pregnancy physical or mental disability sexual orientation gender identity military or veteran status or any other basis protected by federal state or local law.
The Company collects personal information about its applicants for employment that may include personal identifiers professional or employment related information photos education information and/or protected classifications under federal and state law. This information is collected for employment purposes including identification work authorization FCRA-compliant background screening human resource administration and compliance with federal state and local law.
Applicants for employment with The Company will never be asked to provide money (even if reimbursable) as part of the job application or hiring process. Please review our Fraud FAQ for further details.
Pay is competitive and based on a number of job-related factors including skills and experience. The starting pay rate/range at time of hire for this position in the posted location is $100246.00-$164689.00 / year. The rate/range provided herein is the anticipated pay at the time of hire and does not reflect future job opportunity.
We appreciate your interest in this opportunity. Applicants must be authorized to work for ANY employer in the U.S. Please note that at this time we do not provide visa sponsorship for employment.
Required Experience:
Senior IC
About Company
Stay connected with Optimum Fiber-powered Internet starting at $25/mo. with a 5-year price lock. Explore internet, TV, mobile & bundle deals today.