Location: Austin, United States of America Thales people architect identity management and data protection solutions at the heart of digital security. Business and governments rely on us to bring trust to the billions of digital interactions they have with people. Our technologies and services help banks exchange funds, people cross borders, energy become smarter and much more. More than 30,000 organizations already rely on us to verify the identities of people and things, grant access to digital services, analyze vast quantities of information and encrypt data to make the connected world more secure.
Position Summary: Austin, Hybrid Thales is looking for a Security AI Operations Engineer who bridges automated AI systems and human security operations. This role is responsible for the day-to-day supervision, quality control, and execution of AI-assisted security workflows. Working alongside the Security Automation & AI Engineering team, the Specialist manages "Human-in-the-Loop" (HITL) triage queues, maintains and updates knowledge bases feeding generative models, audits AI outputs for accuracy, and ensures prioritized investigation tasks are routed seamlessly to front-line security analysts and consultants. Key Areas of ResponsibilityAI Workflow Supervision & Human-in-the-Loop (HITL) Routing Review and validate low-confidence alert enrichments, threat summaries, and triage recommendations generated by AI agents. Assign, dispatch, and track complex security investigations, policy changes, and incident response playbooks to appropriate Tier 2/3 analysts and consultants. Serve as the operational escalation point when automated pipelines encounter exceptions, edge cases, or platform integration errors. Knowledge Base & Prompt Lifecycle Management Curate, clean, and organize internal runbooks, standard operating procedures (SOPs), threat intelligence, and product documentation stored in Amazon Bedrock Knowledge Bases and Amazon OpenSearch Service. Audit AI retrieval quality and document gaps in knowledge coverage that lead to model hallucinations or poor responses. Perform routine prompt adjustments and template maintenance, submitting structured enhancement tickets to engineering when underlying code changes are required. Quality Assurance & Performance Auditing Regularly audit AI-generated outputs (incident summaries, triage context, customer reports) against human analyst benchmarks to ensure high fidelity and operational safety. Identify recurring false positives or hallucination patterns, collaborating directly with automation engineers to refine model guardrails and prompt evaluation datasets. Track and report on operational KPIs, including Mean Time to Respond (MTTR), task assignment velocity, and analyst AI adoption. Team Enablement & Operational Feedback Train security analysts and services teams on prompt best practices, effective use of internal AI copilots, and feedback submission workflows. Gather front-line feedback and feature requests from security practitioners to help shape the automation engineering roadmap. Sales Partner with the Sales Engineering team to develop and deliver Value-Added Services (VAS) proof-of-values (POVs), clearly demonstrating the business value and impact of these services. Collaborate with Account teams to accelerate time-to-value for Thales solutions among non-VAS customers, strengthening customer adoption, retention, and renewal outcomes.
Minimum Qualifications: Bachelor's degree, in Computer Science, Cybersecurity, Information Technology, Engineering, or a related field. 8+ years in a Security Operations Center (SOC), Managed Security Services (MSSP), IT Service Management (ITSM), or technical workflow coordination role, including 2+ years working with AI/Gen AI-enabled tools or workflows. Cybersecurity Foundation: Working knowledge of security operations, threat lifecycle, alert triage, WAF, API security, and common security frameworks (e.g., MITRE ATT&CK, NIST). AI & Workflow Tooling: Practical experience interacting with generative AI tools, prompt workflows, and enterprise ticketing/orchestration platforms (e.g., Jira, ServiceNow, PagerDuty, or SOAR platforms). Cloud & Search Interface Familiarity: Working comfort navigating the AWS Management Console (specifically Amazon Bedrock, Amazon OpenSearch Dashboards, and CloudWatch metrics). Communication & Documentation: Strong technical writing skills with experience authoring security runbooks, SOPs, and structured process documentation. Applicants must be legally authorized to work in the United States for any employer at the time of hire. This position is not eligible for visa sponsorship or for assuming sponsorship of an employment visa now or in the future.
Preferred Qualifications: Data & Query Skills: Basic scripting ability in Python or experience writing search queries (OpenSearch / Elasticsearch queries, SQL, or Lucene). Workflow Aut

Also on the board Same function, level within a rung

Level

Lead

Location

Austin, TX

Occupation

Information Security Engineers

Industry

Computer Systems Design Services

Posted

yesterday

Apply for this role →