Principal Software Engineer - Agentic SOC
New
H
HuntressCybersecurity
Remote US, OnlyFull-TimePrincipal
Salary$215,000 to $240,000 base plus bonus and equity
Apply NowOpens the employer's application page
Job Details
- Experience
- 15+ years of experience developing complex software products, including significant time as the technical lead on production systems
- Required Skills
- AWSRuby on RailsAzurePostgresRedisDistributed Systems
Requirements
- 15+ years developing complex software products, including significant time as a technical lead on production systems.
- Hands-on experience designing, shipping, and operating production LLM-based agents, including tool use, context management, structured output, guardrails, and evaluation.
- Experience building evaluation for non-deterministic systems, such as labeled datasets, offline evaluations, and regression gates.
- Experience building systems that handle untrusted input, enforce multi-tenant isolation, and produce auditable records.
- Experience with automated decisions that have real consequences and judgment about what to automate versus leave to people.
- Deep backend expertise in distributed systems, queues, durable workflows, and concurrency.
- Strong skills in one or more backend languages and ability to learn new languages; willingness to become fluent in Ruby on Rails.
- Experience with AWS, Azure, or other public cloud environments.
- Experience with data stores such as Postgres and Redis.
- Experience with AI coding tools, such as Claude Code.
- BS or MS in Computer Science or Engineering, or equivalent experience.
- SOC, incident response, threat hunting, or detection engineering experience is a bonus, as is familiarity with endpoint and identity telemetry, attacker tradecraft, adversarial testing of ML or LLM systems, and Ruby on Rails.
Responsibilities
- Own the architecture of agentic investigations, including signal flow, investigation state, agent tools, and investigation outputs.
- Work with SOC analysts and product researchers to translate analyst investigation practices into agent behavior.
- Build LLM-powered preprocessing that summarizes, correlates, and highlights relevant information from analyst tools and data sources.
- Design trust boundaries, tenant isolation, and auditability for agents handling attacker-influenced data and taking customer-environment actions.
- Define evaluation methods for investigation correctness, reasoning, and documentation, and require evidence for prompt, model, and tool changes.
- Use measured performance to determine which decisions are autonomous and which require human review.
- Design production systems for reliability, latency, and cost at scale, including when models are slow, incorrect, unavailable, or changed.
- Design agent-to-analyst handoffs that provide useful investigation work and context.
- Prototype uncertain approaches, assess risk, and hand validated work off clearly.
- Provide technical leadership through decision-making, alignment, code review, pairing, and collaboration with engineering, SOC, product, and executive stakeholders.
View Full Description & ApplyYou'll be redirected to the employer's site