The Agentic SOC Developer is Solidigm's embedded security builder — a Senior Engineer (IC7) who owns detection coverage strategy, builds and ships production agentic detection and response, and directly expands the capability of the SOC and managed-services partner. This role defines and enforces detection standards grounded in MITRE ATT&CK, operationalizes AI agents and automation pipelines, and governs the non-human identity and delegation lifecycle for security AI agents. This is an engineering role, not an analyst role: the person writes and deploys working code in the live environment.
KEY RESPONSIBILITIES
Define and own detection coverage strategy — establish and maintain detection standards, naming conventions, and quality criteria for the SOC. Map the threat landscape to MITRE ATT&CK TTP coverage; prioritize detection development against real adversary behaviors and threat intelligence; track coverage targets, mean-time-to-detect (MTTD), and false positive rates as operational KPIs.
Build and ship agentic detection and response — own the full lifecycle from threat use case through detections-as-code, automated triage, and production agentic response workflows. Ship working code, not designs.
Embed forward-deployed — work alongside the SOC, IR, and platform/engineering teams; deliver directly in their environment; coach MSP analysts and Solidigm engineers on agentic patterns, detection best practices, and operational hygiene. Model IC7 technical leadership: drive decisions, synthesize inputs, and mentor toward measurable growth.
Design and govern AI agent identity and delegation — architect the end-to-end lifecycle for non-human identities operating in the security environment — scoped delegation, audit logging, and kill-switch controls. Own guardrails, safety controls, and human-oversight mechanisms for production security AI agents; apply MITRE ATLAS adversarial ML techniques to threat-model agent deployments.
Architect and evolve the security data platform — own collector/forwarder architecture, log pipeline design, SIEM strategy, and detection-content portability that enable an adaptive, resilient SOC. Contribute to the technical roadmap for security data infrastructure.
Validate through adversary emulation and framework coverage — run or support purple team and adversary emulation exercises to verify detection efficacy systematically; close coverage gaps identified through testing and operational feedback. All detection work is grounded in MITRE ATT&CK (TTP mapping, kill chain coverage, gap analysis). All AI/agent security work is grounded in MITRE ATLAS (adversarial ML, AI-agent attack vectors including v5.4 agent-specific techniques). Operate within and strengthen the NIST AI RMF, OWASP Top 10 for LLM Applications, and OWASP Top 10 for Agentic AI governance gate.
Force-multiply the managed services partner — build supervised automations that expand analyst capacity under oversight — replacing L1 toil with agents and lowering cost-to-serve while maintaining Solidigm governance and visibility.
PREFERRED QUALIFICATIONS
Powered by SmartRecruiters - Candidate Privacy Policy
Job details are sourced from the employer's original posting.
Open job postingAbout the company
Join a multibillion-dollar global company that brings together amazing technology, people, and operational scale to become a powerhouse in the memory industry. Headquartered in Rancho Cordova, California, Solidigm combines elements of an established, successful technology company with the spirit, agility, and entrepreneurial mindset of a start-up.