Manager — Secops / AI Fde (forward Deployed Engineer)

Manager-level Forward Deployed Engineer for Deloitte's Cyber team, focusing on integrating AI and automation into Security Operations (SecOps) for clients. The role involves designing and implementing SIEM, SOAR, detection engineering, and AI-enabled workflows to improve analyst efficiency, alert fidelity, and response speed. Responsibilities include client-facing embedded engineering, rapid solution prototyping, leading log ingestion pipelines, developing threat detection content, automating SOC processes, building integrations, and optimizing case management. A key aspect is applying AI/automation to use cases like triage assistance, alert summarization, knowledge retrieval, and workflow orchestration, while also defining guardrails and evaluation criteria for these AI-enabled security workflows.

What you'd actually do

  1. Apply AI and automation engineering techniques to enhance SecOps use cases such as triage assistance, alert summarization, knowledge retrieval, workflow orchestration, analyst copilots, and response recommendations.
  2. Serve as a Forward Deployed Engineer, embedding with client teams to understand operational workflows, rapidly prototype solutions, and productionize capabilities in client environments.
  3. Design and implement secure, scalable, and resilient security operations solutions across SIEM, SOAR, telemetry, case management, and response platforms in alignment with enterprise security policies and regulatory requirements.
  4. Translate SOC processes into automation playbooks and orchestration workflows to reduce alert fatigue, improve analyst productivity, and accelerate response.
  5. Help define guardrails, testing approaches, and evaluation criteria for AI-enabled security workflows to ensure they are secure, reliable, and operationally useful.

Skills

Required

  • Python or similar scripting languages
  • SIEM, SOAR, detection, telemetry, and response workflows
  • Security operations concepts
  • MITRE ATT&CK, Cyber Kill Chain, or similar frameworks
  • Log parsing, normalization, data transformation

Nice to have

  • AI/automation skills
  • Cloud environments

What the JD emphasized

  • client-facing
  • embedded engineering
  • rapidly design, build, and deploy solutions
  • AI-enabled workflows
  • practical AI/automation skills
  • translating ambiguous requirements into production-ready workflows
  • work side by side with SOC teams
  • regulatory requirements
  • rapidly prototype solutions
  • productionize capabilities
  • log ingestion, normalization, enrichment, and routing pipelines
  • threat detection content
  • automation playbooks and orchestration workflows
  • integrations between third-party enterprise systems
  • automated ingestion, enrichment, triage, investigation, and response
  • case management and analyst workflow solutions
  • AI and automation engineering techniques
  • triage assistance, alert summarization, knowledge retrieval, workflow orchestration, analyst copilots, and response recommendations
  • guardrails, testing approaches, and evaluation criteria
  • secure, reliable, and operationally useful
  • 10+ years of experience
  • Hands-on experience designing, implementing, and optimizing SIEM, SOAR, detection, telemetry, and response workflows
  • Experience building and maintaining integrations, automations, and engineering workflows using Python or similar scripting languages
  • Strong understanding of security operations concepts
  • Strong knowledge of security frameworks and attacker behavior models

Other signals

  • AI-enabled workflows
  • AI and automation engineering techniques
  • analyst copilots
  • response recommendations