Remote job
Senior Software Engineer- Agentic SOC
Job details
About this role
Role overview A senior software engineer is needed to build and ship core components of an agentic Security Operations Center (SOC) platform where LLM-based agents investigate signals end-to-end across millions of endpoints and identities. The role owns significant pieces from ambiguous idea to production feature, partnering closely with engineers, SOC analysts, product researchers, and product managers.
Responsibilities - Design and build the investigation system: agent tools for querying telemetry, investigation logic, and structured, evidence-backed outputs for analysts and customers. - Translate analyst triage and investigation workflows into agent behavior by working side-by-side with SOC analysts and product researchers. - Build LLM-powered features that pre-process tool output, correlate activity, and summarize findings so analysts focus on judgment rather than assembly. - Develop and extend evaluations that measure whether the system is improving, backing changes with evidence rather than anecdotal wins. - Build with a security mindset: handle attacker-influenced data, multi-tenant separation, and the possibility of adversarial inputs. - Write observable, cost-aware production code, operate what you ship, and help keep the system healthy as new detections and products come online.
Requirements - 6+ years of professional software development experience, including building and operating production backend systems. - Hands-on experience building applications with LLMs, including tool use, structured output, prompt and context design, and evaluation; shipping agents to production is a strong plus. - Understanding of how LLM-based systems fail, plus habits for testing and debugging non-deterministic behavior. - Solid backend fundamentals: APIs, background jobs and queues, concurrency, relational databases such as Postgres, and stores such as Redis. - Strong skills in one or more backend languages with the ability to pick up new ones quickly; the primary stack is Ruby on Rails and prior Rails experience is welcomed but not required. - Security awareness including untrusted input handling, access control, and tenant isolation, plus experience with AWS, Azure, or another public cloud.
Nice to have - Experience working in or building for a SOC, incident response, threat hunting, or detection engineering. - Familiarity with endpoint, identity, and Microsoft 365 telemetry, plus attacker tradecraft such as MITRE ATT&CK. - Experience building evaluation pipelines or datasets for ML or LLM systems.
Benefits and work setup - 100% remote within the US. - Base compensation of $165,000–$190,000 plus bonus and equity. - Generous paid time off, 12 weeks of paid parental leave, and 14 paid holidays. - Comprehensive medical, dental, and vision benefits, 401(k) with a 5% employer contribution, life and disability insurance, and stock options for all full-time employees. - One-time $500 home office reimbursement, annual professional development allowance, $75/month digital reimbursement, and access to a coaching and growth platform.