Forward Deployed Engineer

Forward Deployed Engineer

The next evolution of AI-powered cyber defense is here. Organizations struggle with the volume of data and alerts their security tools generate, and attacks are getting harder to find among the false positives. AiStrike's platform uses AI and machine learning to adopt an attacker mindset, prioritizing and automating threat investigation and response. It cuts alert volume from 100 to 5, gives analysts the context and link analysis to investigate what remains, and adds collaborative workflow and no - code automation to shorten response time.

The role

We are looking for a Forward Deployed Engineer to build what customers need to run AiStrike in their environment, and to keep it running. You will write connectors, data pipelines, automations and custom agents inside real customer environments. You will take proofs of concept into production, and turn what you build for one customer into something the product offers the next. You will work alongside Solutions Architects, Product, Engineering and Customer Experience. Solutions Architects shape how AiStrike fits a customer's security program; you make it work. This is a hands-on engineering role that sits with the customer.

Responsibilities

  • Onboard customer data end to end: connect SIEM, EDR/XDR, identity, cloud and email sources, normalize them to our common schema, and confirm data is arriving complete and on time.
  • Build the connectors, APIs, scripts and webhooks a customer's use case needs, and troubleshoot integrations, pipelines and authentication when they break.
  • Build custom agents and automations on the platform, from ingestion and enrichment through investigation to outputs such as reports, Slack notifications, approvals and containment actions.
  • Integrate AiStrike with the customer's response tooling: SOAR, ticketing, and the EDR, identity and firewall controls that carry out actions.
  • Configure the environment context the analytics depend on: privileged and service accounts, VIP users and critical assets.
  • Own the technical build of proofs of concept and the move from a successful PoC to production, across SaaS and single-tenant deployments in the customer's own cloud.
  • Turn one-off customer builds into reusable connectors and product capabilities, and bring field evidence back to Product and Engineering to shape the roadmap.

Requirements

  • 3+ years in software engineering, security engineering, solutions engineering, forward deployed engineering or a similar role, including code that customers ran in production.
  • Strong Python. You have built integrations against REST APIs, SDKs and webhooks, and handled what makes them fail: OAuth and service-principal authentication, pagination, rate limits and retries.
  • Hands-on experience building with LLMs: prompting, tool use, structured output, and checking whether the output is actually right.
  • Working experience with AWS, Azure or GCP, and with containers and Kubernetes.
  • Familiarity with security telemetry from several of: SIEM (Microsoft Sentinel, Splunk, Google SecOps, Elastic), EDR/XDR (CrowdStrike, Microsoft Defender), identity (Entra ID, Okta), CNAPP (Wiz) and SOAR.
  • Comfortable querying data in SQL and at least one SIEM query language (KQL, SPL).
  • A methodical debugger in systems you didn't build, across logs, data pipelines, networking and authentication.
  • Experience working directly with customers: you can take a loosely stated requirement to a working solution, and explain the trade-offs to an engineer or a SOC lead.
  • Comfortable in a high-growth startup with high ownership and ambiguity, and willing to travel domestically.

Nice to have

  • Ability to normalize logs from different security tools into a common schema such as OCSF, and to build ETL pipelines for high-volume security data.
  • Experience with SOAR playbook development on platforms such as Palo Alto XSOAR, Splunk SOAR, Tines or Torq.
  • Experience with agent frameworks or tool protocols such as Model Context Protocol, and with running self-hosted models (vLLM, Ollama) for private deployments.
  • Experience with infrastructure as code, using Terraform or Helm.
  • Experience at an MSSP, or with multi-tenant security platforms.

Why join AiStrike

  • Shape the future of autonomous cyber defense.
  • Be part of a high-growth company at the forefront of AI and cybersecurity.
  • Competitive compensation. Equity available for the right candidate.
Uploading...
fileuploaded.jpg
Upload failed. Max size for files is 10 MB.
Submit
For information about how AiStrike handles your personal data, please see our Privacy Policies
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.