Security Engineer — Detection & Agentic AI
Solidigm- Location
- Zapopan, , Mexico
- Workplace
- —
- Employment
- Full Time
- Salary
- —
Posted 2mo ago
The Agentic SOC Developer is Solidigm's embedded security builder — a Senior Engineer (IC7) who owns detection coverage strategy, builds and ships production agentic detection and response, and directly expands the capability of the SOC and managed-services partner. This role defines and enforces detection standards grounded in MITRE ATT&CK, operationalizes AI agents and automation pipelines, and governs the non-human identity and delegation lifecycle for security AI agents. This is an engineering role, not an analyst role: the person writes and deploys working code in the live environment.
KEY RESPONSIBILITIES
Define and own detection coverage strategy — establish and maintain detection standards, naming conventions, and quality criteria for the SOC. Map the threat landscape to MITRE ATT&CK TTP coverage; prioritize detection development against real adversary behaviors and threat intelligence; track coverage targets, mean-time-to-detect (MTTD), and false positive rates as operational KPIs.
Build and ship agentic detection and response — own the full lifecycle from threat use case through detections-as-code, automated triage, and production agentic response workflows. Ship working code, not designs.
Embed forward-deployed — work alongside the SOC, IR, and platform/engineering teams; deliver directly in their environment; coach MSP analysts and Solidigm engineers on agentic patterns, detection best practices, and operational hygiene.
Model IC7 technical leadership
drive decisions, synthesize inputs, and mentor toward measurable growth.
Design and govern AI agent identity and delegation — architect the end-to-end lifecycle for non-human identities operating in the security environment — scoped delegation, audit logging, and kill-switch controls. Own guardrails, safety controls, and human-oversight mechanisms for production security AI agents; apply MITRE ATLAS adversarial ML techniques to threat-model agent deployments.
Architect and evolve the security data platform — own collector/forwarder architecture, log pipeline design, SIEM strategy, and detection-content portability that enable an adaptive, resilient SOC. Contribute to the technical roadmap for security data infrastructure.
Validate through adversary emulation and framework coverage — run or support purple team and adversary emulation exercises to verify detection efficacy systematically; close coverage gaps identified through testing and operational feedback. All detection work is grounded in MITRE ATT&CK (TTP mapping, kill chain coverage, gap analysis). All AI/agent security work is grounded in MITRE ATLAS (adversarial ML, AI-agent attack vectors including v5.4 agent-specific techniques). Operate within and strengthen the NIST AI RMF, OWASP Top 10 for LLM Applications, and OWASP Top 10 for Agentic AI governance gate.
Force-multiply the managed services partner — build supervised automations that expand analyst capacity under oversight — replacing L1 toil with agents and lowering cost-to-serve while maintaining Solidigm governance and visibility.
- B.S. Degree in Information Security, Cybersecurity, Computer Science, Software Engineering, or related fields.
- Advanced English level (mandatory).
- Software development proficiency — Python preferred; API integration; infrastructure-as-code; CI/CD. This is a development role. Expected experience: 4–6+ years of relevant hands-on work.
- Security operations fluency — detection engineering, SIEM/SOAR platforms, and incident response workflows. Comfortable owning the detection lifecycle end-to-end.
- MITRE ATT&CK depth — TTP mapping, kill chain coverage analysis, and detection-to-technique alignment. Ability to build and maintain ATT&CK coverage heatmaps, prioritize detection development against real threat intelligence, and report on TTP coverage gaps and MTTD.
- MITRE ATLAS depth — adversarial ML threat modeling for AI systems and agents — mapping attack techniques such as model evasion, data poisoning, prompt injection, AI supply-chain compromise, and agent-specific vectors (e.g., Publish Poisoned AI Agent Tool, Escape to Host, LLM jailbreaking). Ability to apply ATLAS to threat-model security AI agent deployments and validate guardrails against the framework's technique catalog.
- AI/agent development experience — hands-on building with agent frameworks, RAG pipelines, or agentic orchestration in production.
- AI security governance knowledge — NIST AI RMF; OWASP Top 10 for LLM Applications (LLM01–LLM10: prompt injection, insecure output handling, training data poisoning, model denial of service, supply chain vulnerabilities, etc.); OWASP Top 10 for Agentic AI Applications; and AI safety control design including guardrails, human oversight mechanisms, and secure orchestration.
- Field mindset — comfortable embedding with operational teams, shipping in partner-controlled environments, and coaching across technical levels.
PREFERRED QUALIFICATIONS
- Microsoft security stack — Defender XDR, Microsoft Sentinel (+ Data Lake), Security Copilot, Logic Apps; KQL; Azure.
- Splunk — SPL, log forwarding, content/detection management, and index administration.
- Agentic tooling — Model Context Protocol (MCP), Security Copilot plugins, or comparable security-native agent orchestration and connector frameworks.
- Non-human identity (NHI) & workload identity — Entra Workload Identities, Okta, or comparable; service principal and managed-identity lifecycle.
- SIEM migration & content portability — platform-to-platform detection migration, collector/forwarder architecture at scale.
- Prior FDE, solutions-engineering, or detection-engineering role — embedded delivery model in enterprise security environments.
Powered by SmartRecruiters - Candidate Privacy Policy
Skills
- Machine Learning
- SIEM
- NIST
- OWASP Top 10
- LLM
- Python
- Retrieval-Augmented Generation
- GitHub Copilot
- Azure Logic Apps
- Azure
- Splunk
- Model Context Protocol
- Okta
More jobs at Solidigm
All 192027 Undergraduate Software Development Engineering Internships – Mexico
Solidigm · Guadalajara, Jal., Mexico · 6d ago
Talent Acquisition Data Engineering & Analytics Graduate Intern
Solidigm · Rancho Cordova, CA, United States · 8d ago
Senior NAND Product Development Engineer (for Validation)
Solidigm · Minhang District, , China · 8d ago
Security Firmware Engineer
Solidigm · Gdańsk, , Poland · 8d ago
Security Firmware Engineer
Solidigm · Rancho Cordova, CA, United States · 8d ago
Similar roles
Controls Engineer
International Automotive Components · Monterrey North Plant, NL, Mexico · today
Senior Workforce Identity & Access Analyst II
The Nielsen · Guadalajara, Mexico · today
Junior Data Scientist
Roland Berger · Mexico City, CDMX, Mexico · 8d ago
Factory Operations Manager
Sola Wood Flowers · Monterrey, Mexico · MXN 650,000–1,500,000/yr · 1mo ago
Senior Security Application Engineer - Automation & Detection
Solidigm · Zapopan, , Mexico · 2mo ago
Lead Application Analyst - IT WMS - Blue Yonder
Fortune Brands · NOGALES, SONORA, Mexico · 2mo ago