Title: AI Agent Developer
Location: Houston, TX/Hybrid
Job Overview
We are looking for an AI Agent Developer with hands-on experience building AI/LLM-powered agents and automation solutions for cybersecurity use cases. The candidate will develop AI agents using AWS and Amazon Bedrock and integrate them with security data sources such as CrowdStrike, Splunk, and Cribl. The role will focus on automating security investigations, alert analysis, threat hunting, incident response, and security operations workflows
Key Responsibilities
Design, develop, and deploy AI agents / Agentic AI solutions using Amazon Bedrock and AWS.
Build AI-driven workflows for security alert investigation, threat hunting, and incident response.
Integrate AI agents with CrowdStrike, Splunk, and Cribl using APIs and SDKs.
Develop Python-based automation for security data collection, analysis, correlation, and response.
Use LLMs, prompt engineering, RAG, and tool/function calling to build intelligent security agents.
Develop agents that can query CrowdStrike Falcon, Splunk, and Cribl and correlate security information.
Automate repetitive SOC activities such as alert enrichment, investigation, incident summarization, and reporting.
Develop secure agent workflows with appropriate authentication, authorization, permissions, and human approval controls.
Implement AI security controls against prompt injection, data leakage, excessive permissions, and unauthorized tool access.
Integrate agents with existing security and cloud environments through REST APIs.
Test, troubleshoot, monitor, and optimize AI agents for accuracy, performance, and reliability.
Work with SOC, threat hunting, incident response, and security engineering teams to identify and automate security use cases.
Create documentation, workflows, and runbooks for AI-based security automation.
Required Skills
AI Agents / Agentic AI, Amazon Bedrock, AWS, LLMs, RAG, Prompt Engineering, and Tool/Function Calling
Python, REST APIs, SDKs, JSON, Git, and CI/CD
CrowdStrike Falcon, Splunk/SPL, and Cribl
Security Automation, Threat Detection, Threat Hunting, and Incident Response
SIEM, EDR/XDR, SOAR, and cybersecurity operations
AWS services: Lambda, API Gateway, IAM, S3, CloudWatch, EventBridge, and Step Functions
Understanding of AI/LLM Security, Prompt Injection, Data Protection, and Access Controls