Senior Cybersecurity Operations Engineer - AI
$97.9k - $177.4kAlliance Data Systems, Inc.
Every career journey is personal. That's why we empower you with the tools and support to create your own success story.Be challenged. Be heard. Be valued. Be you ... be here.Job SummaryThe Senior Cybersecurity Operations Engineer - AI serves as a senior technical leader within the Cybersecurity Operations Center, focused on advancing detection engineering, automated response, and threat intelligence capabilities to defend critical information assets. This role is responsible for designing, developing, and continuously improving high-fidelity detections across enterprise telemetry, as well as engineering automated response workflows that reduce response times and operational burden.Building on a strong foundation in security engineering, this individual will champion modern CSOC practices including detection-as-code, threat-informed defense, and the integration of AI and agentic workflows to optimize alert triage, enrichment, and incident response. The Sr. Engineer partners closely with cross-functional teams across infrastructure, cloud, identity, and application domains to ensure visibility, coverage, and coordinated response to evolving threats.As a subject matter expert, this role drives innovation in CSOC operations, translates threat intelligence into actionable detections and hunts, and continuously measures and improves detection effectiveness. The position also serves as a mentor to junior engineers and analysts, fostering technical growth and promoting scalable, repeatable security operations processes..Essential Job FunctionsProcess and Project Management: Own the design and the implementation of key IT projects and initiatives as they pertain to the organization's long-term security strategy. Identify areas of improvement where processes do not currently exist and drive the development and delivery of new processes to address these gaps. Ability to manage ambiguity and deliver quality results with minimal supervision in coordinating projects and other deliverables. Willingness to escalate identified issues as necessary and the ability to identify when to partner with leadership to resolve issues, risks or obstacles. Builds consensus for delivering results while finding common ground for collaboration and partnership.Documentation, Metrics and Presentations: Understand the various tools and technologies commonly associated with Information Security. Lead the creation of and the maintenance of relevant documentation including the ability to deliver run books, project updates, process documentation, architecture and technical requirements and presentations. Develop and deliver Key Performance Indicators (KPIs) through the understanding of the tools and deliverables by helping to develop, maintain and mature the associated reporting structure. Ability to produce meaningful and actionable metrics through data analysis. Conduct data analysis exercises using Excel Pivot Tables, database queries, and other data driven analysis tools. Produces presentations at various levels of abstraction dependent on intended audience using Microsoft Power Point, Microsoft Visio, or equivalent tools.Leadership and Development: Ability to work in a team-fostered, fast-paced, multi-threaded environment. Serve as the subject matter expert in various technical Information Security disciplines and mentoring junior staff. Demonstrate self-learning in gaining knowledge of new technical developments and ensure they are shared appropriately and applied within the department. Comprehensive understanding of the InfoSec team’s strategy and vision and actively works as a change agent to support these initiatives both within the InfoSec team and the broader organization. Identifies and understands drivers for change and will act as an individual champion or partner with leadership to deliver those changes. Effectively partners with peers within the department to include them in key projects, risks or issues. Intermediate to expert interpersonal, negotiation and oral communication skills expected.Human Relations: Ability to maintain the highest level of confidentiality and professionalism. Ability to proactively identify potential issues and deliver well-reasoned solutions. Ability to diffuse problematic situations and manage through conflict resolution. Ability to decompose complex topics and break them down into laymen’s terms or analogies that help drive clarity and understanding. Viewed as an enabling partner that provides alternative options or supporting information when saying no to business or IT requests. Seen by leadership and peers as creditable, trustworthy and respectful.Reports to: Manager, Information SecurityWorking Conditions/ Physical Requirements:Normal office environment. (Remote or Hybrid), 3 to 4 days per month are required in office if within 60 miles of a posted Bread Financial location.Some travel may be required.As the need of the business continue to evolve, this role may be asked to work an on-call rotation to include evenings or weekends.Direct Reports: NoneMinimum Qualifications:Four or more years experience in Information Security or Infrastructure.Intermediate to expert level knowledge of IT tools and practices including, but not limited to: Networking, LDAP Directories, Vulnerability/Patch Management, Change Management, Incident Management, Server and Desktop Management, Mainframe Technologies, Encryption and Key Management, Cloud Architecture and Computing, Software Application General Computing Controls, Business Continuity/Disaster Recovery, Software Development Lifecycle, Access Management, and Cyber Security Tools (Security Incident Event Management (SIEM), Security Orchestration, Automation and Response (SOAR), Data Loss Prevention (DLP) , Intrusion Detection System (IDS), Intrusion Prevention System (IPS), End User Behavioral Analytics (EUBA), Web Application Firewall (WAF), Network Access Control (NAC), Privileged Access Management (PAM), Endpoint Detection Response (EDR). Broad range of skills with different technical platforms (firewalls, servers, workstations, networks, storage, security, Internet and cloud (SaaS / IaaS / PaaS) technologies). Working understanding of NIST security standards, PCI - DSS and SOX controls.Preferred Experience:Bachelor’s or equivalent experience in Computer Science, Networking or Information TechnologyCertification: Security +, Network+, CISSP, SSCP, CCSPFive or more years experience in Information Security or Infrastructure experience.5+ years in SOC, detection engineering, threat detection, or security engineering rolesDemonstrated ownership of detection lifecycle: ideation, development, tuning, deployment, validation, and continuous improvement.Hands-on experience building and maintaining detections in one or more SIEM platforms (Splunk, CrowdStrike Next-Gen SIEM, Palo Alto XSIAM).Proven experience onboarding and normalizing logs across endpoint, identity, cloud, network, and application sources.Experience managing detections using Git-based workflows, code review, branching strategies, and CI/CD principles.Familiarity with testing frameworks for detections (unit testing logic, regression testing, synthetic event generation, and controlled replay).3+ years designing and implementing SOAR playbooks and response automations (Cortex XSOAR, Splunk SOAR).Demonstrated success reducing mean time to detect and respond through automation and orchestration.Experience translating intelligence into practical outcomes such as detections, hunts, enrichment, and response actions.Familiarity with TI platforms and standards (MISP, OpenCTI, STIX/TAXII) and integrating TI into SIEM and SOAR workflows.Strong experience mapping detections and response playbooks to MITRE ATT&CK.Experience building behavior-based detections that reduce reliance on static indicators.Experience applying AI to detection engineering or SOC operations such as alert summarization, triage enrichment, incident clustering, case routing, and knowledge retrieval.Experience designing guardrails for AI usage: human-in-the-loop approvals, audit logging, data handling controls, and prompt or workflow governance.Skills:Detection Engineering and AnalyticsWriting high-signal detections using SPL, KQL, EQL, Lucene, Sigma, or equivalent query languagesBehavior-based detection design, including correlation, baselining, anomaly, and sequence detectionAlert tuning, suppression, allowlisting, and noise reductionData modeling, normalization, field extraction, parsing, and enrichment strategiesDetection coverage mapping to MITRE ATT&CK and kill chain conceptsAutomation, SOAR, and Response EngineeringBuilding SOAR playbooks and automated response actions with approval gates and safe failure modesIntegrations via REST APIs, webhooks, message queues, and event-driven designsCase management, ticketing integration, and automated evidence collectionAutomated containment actions: disable accounts, revoke sessions, isolate endpoints, block indicators, quarantine email, update firewall rulesThreat Intelligence and HuntingConverting TI into actionable detections, hunts, enrichment, and prioritized response stepsIOC lifecycle management, confidence scoring, and expiration handlingFamiliarity with STIX/TAXII, MISP, OpenCTI, and TI feedsThreat hunting methodologies, hypothesis-driven hunting, and translating hunts into detectionsAI and Agentic SOC OperationsDesigning AI-assisted workflows for triage, summarization, correlation, and recommendationBuilding agentic workflows with human approvals, audit trails, and policy guardrailsPrompt engineering fundamentals for security workflows and retrieval-augmented approachesEvaluating AI outputs for accuracy, bias, and safety, including fallback proceduresPlatforms and TelemetrySIEM administration fundamentals and search performance optimizationEndpoint telemetry and EDR concepts: process trees, persistence, lateral movement, and malware tradecraftIdentity telemetry: authentication events, conditional access, privilege changes, and OAuth abuseCloud telemetry: audit logs, IAM events, workload signals, and network flow logsEngineering PracticesScripting and automation using Python and PowerShellInfrastructure as code concepts and configuration management practicesGit, version control, code review, and CI/CD for detection and automation contentDocumentation practices for runbooks, playbooks, and detection intent and testingCommunication and OperationsIncident handling and escalation judgmentWriting clear, analyst-friendly detection documentation and response instructionsOperational maturity mindset: continuous improvement, post-incident reviews, and backlog prioritizationCross-functional collaboration and influencing without authorityOther DutiesThis job description is illustrative of the types of duties typically performed by this job. It is not intended to be an exhaustive listing of each and every essential function of the job. Because job content may change from time to time, the Company reserves the right to add and/or delete essential functions from this job at any time.Salary Range (unless otherwise noted below):$97,900.00 - $177,400.00Full Salary Range for position:California: $112,600.00 - $221,800.00 Colorado: $97,900.00 - $186,300.00 New York: $107,700.00 - $221,800.00 Washington: $102,800.00 - $204,000.00 Maryland: $102,800.00 - $195,200.00 Washington DC: $112,600.00 - $204,000.00 Illinois: $97,900.00 - $195,200.00 New Jersey: $112,600.00 - $204,000.00 Vermont: $97,900.00 - $177,400.00 Ohio: $97,900.00 - $177,400.00Maine: $97,900.00 - $177,400.00The actual base pay within this range may be dependent upon many factors, which may include, but are not limited to, work location, education, experience, and skills.Bread Financial offers medical, prescription drug, dental, vision, and other voluntary benefits (including basic and optional life insurance, supplemental medical plans, and short and long-term disability) to eligible associates (regular full-time associates scheduled to work 30 hours per week or more) and their spouses/domestic partners, and child(ren) under the age of 26. New associate elected coverage begins on date of hire (with the exception of disability coverage which has a 6-month waiting period). Six weeks of 100% paid parental leave for eligible parents is available after a 180-day waiting period. Hired associates can immediately enroll in Bread Financial’s 401(k) plan.All associates receive 11 paid holidays. Associates have discretion in managing their time away from work through the Flexible Time Off (FTO) program and may need to notify and receive approval from their manager prior to taking the time off. Associates (except those located in Illinois) receive 80 hours of Paid Sick and Safe Time (“PSST”) upon hire and at the beginning of each subsequent calendar year. Illinois associates receive 40 hours of Illinois PSST upon hire and at the beginning of each subsequent calendar year and 40 hours of Illinois Paid Leave upon hire and at the beginning of each subsequent calendar year. Illinois Paid Leave must be used before associates in Illinois will be approved to take FTO.Hired associates will be able to elect the purchase company stock during offering periods in June and December. You will be eligible for an annual incentive bonus based on individual and company performance.Click here for more Benefits information.About Bread FinancialAt Bread Financial, you’ll have the opportunity to grow your career, give back to your community, and be part of our award-winning culture. We’ve been consistently recognized as a best place to work nationally and in many markets and we’re proud to promote an environment where you feel appreciated, accepted, valued, and fulfilled—both personally and professionally. Bread Financial supports the overall wellness of our associates with a diverse suite of benefits and offers boundless opportunities for career development and non-traditional career progression.Bread Financial (NYSE: BFH) is a tech-forward financial services company that provides simple, personalized payment, lending and saving solutions to millions of U.S. consumers. Our payment solutions deliver growth for some of the most recognized brands in travel & entertainment, health & beauty, technology, electronics, jewelry, home and specialty apparel through our co-brand and private label credit cards and pay-over-time products providing choice and value to our shared customers. Additionally, we offer Bread Financial general purpose credit cards and saving products that empower our customers and their passions for a better life.Bread Financial proudly marks 30 years of success in 2026. To learn more about our global associates, our performance and our sustainability progress, visit breadfinancial.com or follow us on Instagram and LinkedIn.Bread Financial offers competitive pay, a comprehensive selection of benefit options including 401(k).The Company is an Equal Opportunity Employer.Any applicant offered employment will be required to establish that they are legally authorized to work in the United States for the Company.The Company participates in E-Verify.The Company will consider for employment all qualified applicants, including those with a criminal history, in a manner consistent with the requirements of all applicable federal, state, and local laws, including the Los Angeles Fair Chance Initiative for Hiring Ordinance, the San Francisco Fair Chance Ordinance, and the New York City Fair Chance Act. Applicants with criminal histories are encouraged to apply.The Company complies with the Americans with Disabilities Act (ADA), as amended, and all applicable state/local laws. The Company will provide accommodations to applicants needing accommodations to complete the application process. Applicants with disabilities may contact the Company to request and arrange for accommodations. If you need assistance to accommodate a disability, you may request an accommodation at any time. Please contact the Recruiting Team at View email address on click.appcast.io Family:Information TechnologyJob Type:Regular #J-18808-Ljbffr Alliance Data Systems, Inc.
- Job Summary The Senior Cybersecurity Operations Engineer - AI is a senior technical leader within the Cybersecurity Operations Center. The role focuses on advancing detection engineering, automated response, and threat intelligence. Responsibilities include designing, developing...SeniorLocal area
$106.8k - $194.8k
...build a better working world. WAF Operations Solution Engineer PRACTICE DESCRIPTION: As a WAF... .... You will work within a team of cybersecurity professionals to establish effective... ...capital markets. Enabled by data, AI and advanced technology, EY teams help...SeniorSummer holidayFlexible hours- Alliance Data Systems, Inc. is seeking a Senior Cybersecurity Operations Engineer to enhance detection engineering and automated response capabilities. This... ...detections and optimizing incident responses with AI integration. The ideal candidate will have strong experience...Senior
- Koitecc Solutions seeks a Senior Lead Security Engineer in Columbus, Ohio, to drive significant business impact in cybersecurity technology. You will design and implement robust software... ...product design decisions, and enhance operational security protocols while utilizing...Senior
- .... Join EY and help to build a better working world. WAF Operations Solution Engineer Practice Description As a WAF Operations Solution Engineer... ...from cyber threats. You will work within a team of cybersecurity professionals to establish effective security measures that...SeniorFlexible hours
- ...technology delivery, and leading the implementation of cutting-edge AI tools. The ideal candidate will excel in building high-... ...applications using modern technologies and have a strong background in cybersecurity. A competitive rewards package and valuable benefits will be...Senior
- Worthington Enterprises, Inc. in Columbus, Ohio is looking for a Senior IT Security Engineer to advance cybersecurity across IT systems and manufacturing. This hybrid role involves collaborating on security strategies, overseeing incident responses, and ensuring the safety...Senior
- A leading financial services company seeks a Senior Lead AI Security Engineer for its Cybersecurity team. The role involves designing secure AI solutions for critical cyber use cases and collaborating with various teams to drive innovation. Candidates need at least 7 years...Senior
- TwinThread is seeking a Senior Lead AI Security Engineer to design and deliver secure AI solutions for cybersecurity. This role involves leading projects, mentoring engineers, and establishing engineering standards. Candidates must have a minimum of 7 years in software...Senior
- A leading cybersecurity firm is looking for a Senior Director of Channel Sales to develop and scale their global channel program. In this remote role, you will execute strategic partnerships and drive significant revenue growth. The ideal candidate has over a decade of...SeniorRemote job
$152.68k - $199.85k
...lives. Position Summary Reporting to the Director of AI Engineering, the Senior Software Engineer - Automation designs, builds, and maintains the internal automation systems that support pharmacy operations across Gifthealth's business lines. This position...SeniorFull timeRemote workMonday to FridayShift workNight shiftWeekend work- ...leading data analytics company is seeking a Senior Individual Contributor to lead the design of AI workflows that enhance engineering productivity. The ideal candidate will... ...development of intelligent agents to optimize operations. Join the team to shape the future of AI-...Senior
- ...Job Summary As a Senior Lead AI Security Engineer in our Cybersecurity team, you will design and deliver secure artificial intelligence solutions that support... ..., or cloud security. Minimum 3 years building and operating applied ML/LLM systems in production (RAG pipelines...SeniorWork at office
- ...influential companies. As a Senior Principal Software Engineer at JPMorganChase within... ..., testing, and operational stability Demonstrated prior... ...Deep expertise with Agentic AI Experience with mentoring... ...implementing industry standard cybersecurity & technology controls...SeniorBank staff
- ...Senior Principal Cybersecurity Architect Come on board with an iconic financial institution and take your career to the next level. You have found... ...expertise to bring together talent that will consistently create AI-enabled solutions, processes, and reusable proof-of-concept...Senior
- ...industries to improve the hybrid cloud and AI journey for the most innovative and... ...portfolio. Your Role And Responsibilities As a senior managing SAP consultant, you will serve... ...budget, and required quality standards. AI & Cybersecurity Knowledge: Familiarity with Artificial...Senior
- ...Senior Lead AI Security Engineer As a Senior Lead AI Security Engineer in our Cybersecurity team, you will design and deliver secure artificial intelligence solutions that support... .... Minimum 3 years building and operating applied ML/LLM systems in production (RAG...SeniorWork at office
$125k
...delivery. Recent contract awards in cybersecurity and operational readiness underscore Maximus' role as... ...in specialty areas. Shall perform engineering tasks for back-end design and development... ...machine learning technologies or AI capabilities. #techjobs #clearance...SeniorContract workRemote work- Senior Director of Channel Sales, AI cybersecurity, Remote About the Company We are a fast-growing, venture-backed cybersecurity company building the next-generation autonomous data security platform. Our solution automates data loss prevention (DLP) and insider risk...SeniorRemote job
$148k - $222k
...Senior ML Ops Engineer Overview As a Senior ML Ops Engineer at Mimecast... ...a technical leader on the AI Enablement Platform (AIP)... ...infrastructure, and operational best practices that enable... ...relevant to AI systems in the cybersecurity domain. Technical Leadership...SeniorWork at officeLocal areaImmediate startWorldwideRotating shift2 days per week- ...what’s possible. As a Lead Software Engineer at JPMorgan Chase within the Cybersecurity Technology and Controls team, you... ...scalable, reliable, and efficient AI solutions. The ideal candidate... ...processes to support the seamless operation of machine learning models. In this...Senior
- ...designed for top performers. As a Senior Lead Security Engineer at JPMorgan Chase within the Cybersecurity Technology & Controls, you are... ...functionality, and technical operations and processes, including the... ...scalable backend development, AI‑powered agents, and data...SeniorFor contractors
$170.6k - $390k
...working world. Join EY’s Cybersecurity consulting practice –... ...opportunity The Senior Network Security... ...application, and security operations teams. Join our dynamic... ...in Cybersecurity Engineering, where you will play a... ...Enabled by data, AI and advanced technology...SeniorSummer holidayRemote workFlexible hours- JPMorgan Chase is seeking a Senior Principal Software Engineer in Columbus, Ohio to lead product and technology strategy within the Consumer & Community Bank Technology team. You will enhance and build trusted market-leading technology products using your deep expertise...SeniorBank staff
- A recruitment agency is seeking a degreed Process Engineer in Ohio. This position requires Aseptic Process Experience and over 10 years in Operations within automation systems. Responsibilities include analyzing processes for improvements, defining quality standards, and...SeniorFull time
- ...Senior AI/ML Engineer Anywhere Type: Contract-to-Hire Category: Development Industry: Government Workplace Type: Remote... ...LangGraph. Develop end-to-end AI/ML/NLP plans compliant with cybersecurity policies. Apply software engineering best practices for...SeniorHourly payPermanent employmentContract workLocal areaRemote work
- ...Senior Cybersecurity Analyst Anywhere Type: Contract-to-Hire Category: Security Industry... ...decisions. Identify gaps in cyber operations and implement improvements. Design... ...Group utilizes artificial intelligence (AI) tools as part of its initial application...SeniorHourly payPermanent employmentContract workLocal areaRemote work
$109k - $182.4k
Shoptalk is seeking a Senior Cybersecurity Data Engineer in Columbus, Ohio. You'll manage and optimize data pipelines and architectures, working with stakeholders to resolve data-related challenges. You'll need at least 10 years of IT experience and strong knowledge of...Senior- ...Job Requisition ID # 26WD98377 Senior Machine Learning Test Engineer Location: United States East Coast Position Overview As a Senior Machine... ...experience in software engineering or QA for ML/AI systems ~ Strong programming skills in Python, with experience...SeniorFor contractorsWork at officeRemote work
- Rogue Fitness in Columbus, Ohio is seeking a Senior Industrial Engineer to enhance manufacturing efficiency and lead process improvement initiatives. This role directly impacts plant layout and utilizes AI/ML tools to optimize production. Candidates should have a B.S....Senior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Cybersecurity Operations Engineer - AI. Be the first to apply!
- application operations engineer Columbus, OH
- data center operations engineer Columbus, OH
- production network engineer Columbus, OH
- remote operation drilling engineer Columbus, OH
- senior security operations engineer Columbus, OH
- production operations engineer Columbus, OH
- security operations center engineer Columbus, OH
- production control engineer Columbus, OH
- post production engineer Columbus, OH
- operations quality engineer Columbus, OH

