Arch Capital Group logo
Arch Capital GroupPosted 1 month ago

Senior Security Engineer (Remote - North Carolina, Florida, or South Carolina preferred)

On-siteGreensboro, North Carolina, United States

Full TimeSenior LevelLarge

Job Summary

Design, build, and deploy agentic AI workflows and intelligent autonomous playbooks to automate Tier-1/2 alert triage, context enrichment, and incident response. Develop and tune complex detection logic across SIEM, EDR/XDR, and cloud platforms, focusing on behavioral analytics and anomaly detection. Utilize Python to build custom security tools, integrate disparate security APIs, and maintain high-quality, reusable codebases for security orchestration (SOAR). Lead threat hunting initiatives and serve as a Tier-3 escalation resource for complex, high-severity security incidents. Secure cloud environments (AWS, Azure, or GCP), with a specific focus on auditing, monitoring, and protecting production AI/LLM pipelines and workloads. Mentor junior team members, conduct code reviews for automation scripts, and promote robust software engineering best practices within the security team.

Required Qualifications

  • 7+ years of cybersecurity experience with a focus on security or detection engineering
  • 3+ years in a Sr. Security Engineer role
  • Deep technical knowledge of incident response, threat hunting, and adversary TTPs
  • Experience implementing and managing detection logic across enterprise SIEM, EDR/XDR, or cloud-native security tools
  • Experience securing and monitoring cloud infrastructure (AWS, Azure, or GCP)
  • Demonstrated experience building functional tools in Python/Powershell, interacting with REST APIs, and writing clean, structured code
  • Bachelor's degree in Computer Science, Cybersecurity, or Engineering

Desired Qualifications

  • Practical understanding of building or implementing LLM-based agents, prompt engineering, and integrating AI models into automated workflows and custom API integrations
  • Familiarity with AI/LLM-specific security vulnerabilities (e.g., OWASP Top 10 for LLMs, prompt injection, data poisoning, model evasion)
  • Experience with SIEM, EDR/XDR, SOAR, or identity security platforms
  • Advanced certifications (e.g., CISSP, GIAC GCIA/GCIH, or cloud security certifications)
  • Master's degree in Computer Science, Cybersecurity, IT Management with an emphasis on AI/Automation

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce