Haystack
← Back to Jobs
Remote
Administrative
DR

Lead Security Operations and Detection Engineer (Only 15+ Years Exp)

Drevol LLCUnited States🇺🇸United StatesPosted 15 Sept 2026

Quick Overview

Seniority
Mid Senior
Work mode
Remote
Location
United States
Posted
18 hours ago

Job Description

Hello Kirk,

Greetings from Drevol !!

My name is Nooruddin and I am reaching out to you regarding a potential opportunity with one of our clients. Please see the job description below. If interested in the position, please reply with your updated resume and linkedIn address.

Position: AI SecOps & Detection Lead Location: Remote

Job Description:

This role builds and operates the AI security lifecycle across the organization, structured around three core questions: do we have full visibility into AI in use across our environment, can we effectively react and respond when something goes wrong, and are we feeding what we learn back into preventative measures. The lead integrates AI-specific findings from tools like Wiz and AIM into existing SOC workflows so that AI-related events are detected and triaged alongside everything else, not sitting in a separate queue. This person stands up shadow AI discovery so the organization is not relying on self-reporting to know what is out there, and develops the AI-specific incident response playbooks and tabletop exercises that ensure the SOC is ready when an AI-related incident hits. On the prevention side, this role closes the loop, translating discovery findings and incident patterns into actionable remediation requests and tighter controls in partnership with teams across the organization. This person also supports the operational governance that keeps the program auditable, maintaining the AI tool inventory, risk assessments, and documentation trail in coordination with internal leadership. To perform all of these tasks the role will partner closely with the SOC, engineering, compliance, and security leadership

  • Strong background in security operations including hands-on experience with SIEM/SOAR platforms, detection engineering, alert triage, and incident response in enterprise environments
  • Experience building and operationalizing asset discovery and inventory programs, with the ability to stand up telemetry-driven visibility into AI tools, workloads, and integrations across cloud and on-premises environments
  • Working understanding of AI-specific attack vectors including prompt injection, model poisoning, credential abuse for AI agents, and data exfiltration through AI prompts, with the ability to translate these into detection logic and response procedures
  • Ability to integrate AI-specific findings into existing operational workflows rather than standing up parallel processes
  • Able to quantify and work improve coverage gaps, detection efficacy, and risk posture trends that drive investment and prioritization decisions

Similar jobs