Cyber Security AI Engineer, Security Operations Center
About NCR VOYIX
NCR Voyix Corporation (NYSE: VYX) is a global platform-powered leader in unified commerce for shopping and dining. Combining a flexible, intelligent platform with end-to-end payments capabilities and services developed through its deep industry experience, NCR Voyix empowers retailers and restaurants to accelerate new possibilities for their operations, experiences and business outcomes. NCR Voyix is headquartered in Atlanta, Georgia, and serves customers in more than 35 countries worldwide.
Title: Cyber Security AI Engineer, Security Operations Center (SOC)
Location: Atlanta, GA
Overview
The Cyber Security AI Engineer is a member of the Global Information Security team responsible for designing, developing, and operationalizing AI-driven cybersecurity capabilities that enhance Security Operations Center (SOC) effectiveness. This role combines expertise in cybersecurity, threat detection, automation, data science, machine learning, and security engineering to improve the organization's ability to identify, investigate, and respond to cyber threats at scale.
The Cyber Security AI Engineer will partner closely with Threat Intelligence, Incident Response, Security Engineering, Detection Engineering, and IT Operations teams to develop intelligent detection models, automate security workflows, improve investigations through AI-assisted analytics, and create scalable solutions that reduce analyst workload while increasing detection accuracy.
This role supports the organization's mission to protect the confidentiality, integrity, and availability of information assets through innovative use of artificial intelligence, machine learning, automation, and advanced analytics.
Key Responsibilities
AI-Driven Security Operations
- Design, develop, and maintain AI and machine learning solutions to improve threat detection, incident triage, and security investigations.
- Build predictive models to identify malicious activity, anomalous user behavior, insider threats, and emerging attack patterns.
- Develop and operationalize AI-assisted threat hunting capabilities across enterprise environments.
- Integrate Large Language Models (LLMs), Generative AI, and advanced analytics into SOC workflows to accelerate investigations and response activities.
- Create AI-powered copilots to assist analysts with investigation, enrichment, summarization, and incident response recommendations.
Incident Response Support
- Support investigation and response efforts for cybersecurity incidents.
- Leverage AI analytics to accelerate root cause analysis and incident containment.
- Assist incident responders with automated evidence gathering and forensic data analysis.
- Participate in major incident investigations and contribute to post-incident reviews.
Security Detection Engineering
- Develop and optimize detection logic using SIEM, XDR, EDR, cloud security, and log analytics platforms.
- Build automated detection pipelines leveraging threat intelligence, MITRE ATT&CK mappings, and behavioral analytics.
- Create AI-generated detection rules and continuously validate detection effectiveness.
- Develop methods to reduce false positives and improve alert prioritization using machine learning techniques.
Threat Intelligence & Threat Hunting
- Utilize internal and external threat intelligence sources to train and improve detection models.
- Conduct proactive threat hunting exercises utilizing AI-enhanced analytics and behavioral indicators.
- Develop automated intelligence ingestion, correlation, and enrichment processes.
- Translate intelligence findings into actionable detection and response capabilities.
Security Automation & Orchestration
- Design and implement security automation using SOAR platforms, APIs, scripting, and AI workflows.
- Automate repetitive SOC tasks including alert enrichment, triage, investigation, reporting, and containment recommendations.
- Develop integrations between AI tools, SIEM platforms, threat intelligence systems, and case management tools.
- Improve SOC operational efficiency through continuous process optimization and automation.
Required Qualifications
Technical Skills
- 3+ years of experience in Cybersecurity, Security Operations, Security Engineering, Detection Engineering, or Incident Response.
- 2+ years of experience developing automation, analytics, AI, or machine learning solutions.
- Strong understanding of SOC operations, incident response, threat hunting, and threat intelligence.
- Experience with SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, or Elastic.
- Experience with EDR/XDR platforms such as Microsoft Defender, CrowdStrike, SentinelOne, or Palo Alto Cortex.
- Experience with Python, PowerShell, SQL, and API development.
- Knowledge of machine learning concepts including anomaly detection, classification, clustering, and behavioral analytics.
- Experience integrating and leveraging Large Language Models (OpenAI, Azure OpenAI, Microsoft Security Copilot, Anthropic, or comparable technologies).
- Experience building automation using SOAR platforms and workflow orchestration tools.
Cybersecurity Knowledge
- Strong understanding of:
- MITRE ATT&CK Framework
- NIST Cybersecurity Framework
- NIST SP 800-61 Incident Response
- Threat Intelligence Lifecycle
- Detection Engineering
- Cloud Security (Azure, AWS, GCP)
- Identity and Access Management
- Vulnerability Management
Preferred Skills
- Experience implementing AI security use cases in enterprise SOC environments.
- Experience with Security Copilot, Azure AI Services, Azure OpenAI, Microsoft Sentinel AI capabilities, or comparable technologies.
- Knowledge of MLOps, Data Engineering, and AI governance principles.
- Experience with data platforms such as Databricks, Snowflake, Azure Data Lake, or Azure Machine Learning.
- Familiarity with adversarial machine learning and AI security risks.
- Experience developing Retrieval Augmented Generation (RAG) solutions for security operations.
Preferred Certifications
- Certified Information Systems Security Professional (CISSP)
- GIAC Certified Incident Handler (GCIH)
- GIAC Cyber Threat Intelligence (GCTI)
- Microsoft Certified: Cybersecurity Architect Expert
- Microsoft Certified: Security Operations Analyst (SC-200)
- Microsoft Certified: Azure AI Engineer Associate (AI-102)
- Microsoft Certified: Azure Security Engineer (AZ-500)
- Security+
- Splunk Cybersecurity Defense Analyst
Offers of employment are conditional upon passage of screening criteria applicable to the job
EEO Statement
Integrated into our shared values is NCR Voyix’s commitment to equal employment opportunity. All qualified applicants will receive consideration for employment without regard to sex, age, race, color, creed, religion, national origin, disability, sexual orientation, gender identity, veteran status, military service, genetic information, or any other characteristic or conduct protected by law. NCR Voyix is committed to being a globally inclusive company where all people are treated fairly, recognized for their individuality, promoted based on performance and encouraged to strive to reach their full potential. We believe in understanding and respecting differences among all people. Every individual at NCR Voyix has an ongoing responsibility to respect and support a globally diverse environment.
Statement to Third Party Agencies
To ALL recruitment agencies: NCR Voyix only accepts resumes from agencies on the preferred supplier list. Please do not forward resumes to our applicant tracking system, NCR Voyix employees, or any NCR Voyix facility. NCR Voyix is not responsible for any fees or charges associated with unsolicited resumes
“When applying for a job, please make sure to only open emails that you will receive during your application process that come from a @ncrvoyix.com email domain.”

