Remote job
Principal Software Engineer - Agentic SOC
Job details
About this role
Role overview
A principal engineering role leading the architecture of an agentic security operations platform that uses LLM-based agents to investigate signals across thousands of customer environments. The system offloads high-volume, repetitive triage from human analysts so they can focus on complex intrusions, with the technical lead owning architecture, evaluation strategy, and the boundary between automated decisions and human handoff.
Responsibilities
- Own the end-to-end architecture of agentic investigations, including how signals flow from detection into investigation, how state is managed, and how tools are exposed to agents. - Define what a finished investigation contains: verdict, timeline, scope, and the evidence behind each claim. - Work alongside SOC analysts and product researchers to model experienced triage behavior in agent logic, including when to dig deeper and when to escalate. - Reduce repetitive toil by using LLMs to pre-process analyst tooling output into clearer summaries. - Build evaluation systems for non-deterministic behavior, including labeled datasets, offline evals, and regression gates that measure quality over time. - Mentor engineers, set technical direction, and partner with engineering management to raise team-wide quality and judgment.
Requirements
- Fifteen or more years of experience developing complex software products, including significant time as technical lead on production systems. - Hands-on experience designing, shipping, and operating LLM-based agents in production, covering tool use, context management, structured output, guardrails, and evaluation, plus a clear-eyed view of how they fail. - Strong backend expertise in distributed systems, queues, durable workflows, and concurrency, with a record of designing for throughput and correctness under load. - Proficiency in one or more backend languages and the ability to become fluent in Ruby on Rails; experience with AWS, Azure, or other public clouds, plus data stores such as Postgres and Redis. - Experience building systems that handle untrusted input, enforce multi-tenant isolation, and produce audit trails fit for scrutiny. - Comfort with AI coding tools such as Claude Code; BS or MS in Computer Science or Engineering, or equivalent experience.
Nice to have
- Experience in or building for a SOC, incident response, threat hunting, or detection engineering. - Familiarity with endpoint and identity telemetry and attacker tradecraft. - Experience attacking or adversarially testing ML or LLM systems.
Benefits and work setup
- 100% remote within the United States. - Base compensation of $215,000 to $240,000 plus bonus and equity. - Generous paid time off, 12 weeks paid parental leave, comprehensive medical, dental, and vision coverage, 401(k) with a 5% employer contribution, life and disability insurance, and stock options for full-time employees. - Home office setup reimbursement, monthly digital stipend, and an annual allowance for education and professional development.