Senior AI Engineer - Cybersecurity
Come join us to create what’s next. Let’s define tomorrow, together.
Description
United's Digital Technology team is comprised of many talented individuals all working together with cutting-edge technology to build the best airline in the history of aviation. Our team designs, develops and maintains massively scaling technology solutions brought to life with innovative architectures, data analytics, and digital solutions.
Job Overview and Responsibilities
The Sr. Engineer – Cybersecurity supports efforts to mature agentic AI development capabilities for United Airlines Cybersecurity and Digital Risk. You will be part of a cross-disciplinary Cyber team responsible for building, deploying, and continuously improving AI agents and agentic frameworks that automate complex cybersecurity workflows across identity and access management, application security, cloud security, governance, risk, compliance, and security operations. This role will focus on developing modular AI skills, secure integrations, reusable agentic workflows, and production-ready automation that enable AI-driven tools to operate accurately, safely, and securely across the enterprise. This role will help improve automated cyber controls, architecture reviews, security playbooks, workflows, processes, and overall security posture.
- Design, build, and deploy intelligent AI agents capable of executing complex cybersecurity workflows across IAM, application security, GRC, cloud security, and security operations.
- Create and manage modular AI instructions, skills, prompts, and workflows that enable large language models and agentic frameworks to perform domain-specific cybersecurity tasks accurately and safely.
- Develop AI-assisted workflows to accelerate secure code reviews, infrastructure-as-code analysis, threat modeling, control validation, and compliance reporting for enterprise applications and platforms.
- Write robust integration code to connect custom AI agents with enterprise tools including identity providers, CI/CD pipelines, SIEM platforms, vulnerability management tools, ticketing systems, cloud platforms, and APIs.
- Code safety guardrails, logic checkpoints, access controls, logging, and human-in-the-loop approval features into agentic frameworks to ensure automated actions are accurate, traceable, and do not negatively impact business operations.
- Monitor performance, accuracy, security, and reliability of deployed AI agents; actively debug code, refine logic, tune prompts, and maintain clear technical documentation for engineering and cybersecurity teams.
- Partner collaboratively with cybersecurity, product, platform, engineering, and IT operations teams to integrate agentic AI and AI security controls into enterprise workflows while maintaining security standards, playbooks, and continuous improvement of cyber controls.
This position is offered on local terms and conditions. Expatriate assignments and sponsorship for employment visas, even on a time-limited visa status, will not be awarded. This position is for United Airlines Business Services Pvt. Ltd - a wholly owned subsidiary of United Airlines Inc.
Qualifications
What’s needed to succeed (Minimum Qualifications):
- Bachelor's degree
- Computer Science, Cybersecurity, Engineering, Information Technology, Artificial Intelligence, Machine Learning, Data Science, or related technical field.
- 4+ years of technical experience directly related to cybersecurity domains.
- 3+ years of experience writing production-level code in Python; experience with Go or JavaScript is highly preferred.
- 1–2+ years of experience building tools with large language models, AI/ML systems, automation, or agentic AI frameworks.
- Deep knowledge of large language model operations, prompt engineering, context management, retrieval patterns, and how modern AI agents operate.
- Strong programming skills in Python; ReactJS and modern AI frameworks is highly preferred.
- Experience coding with agentic frameworks such as LangChain, AutoGen, Semantic Kernel, CrewAI, or similar libraries to build custom multi-agent systems.
- Experience designing, deploying, and securing AI agents using Amazon Bedrock AgentCore capabilities such as Runtime, Memory, Gateway, Identity, and Observability to support production-grade agentic workflows.
- Broad understanding of core security principles spanning Identity and Access Management, Application Security, Cloud Security, Governance, Risk, Compliance, and Security Operations.
- Understanding of AI-specific risks such as prompt injection, data leakage, data poisoning, model misuse, tool misuse, unauthorized shadow AI, and unsafe automated actions.
- Understanding of how diverse systems interact, including identity providers, CI/CD pipelines, SIEMs, cloud platforms, vulnerability management tools, ticketing systems, and APIs.
- Skill in writing programmatic safety mechanisms, enforcing least-privilege access within code, and building human-in-the-loop fallback workflows.
- Knowledge of secure software development practices including code review, testing, dependency management, threat modeling, logging, monitoring, and production release controls.
- Ability to translate cybersecurity requirements into scalable AI-enabled workflows, reusable components, technical documentation, and engineering playbooks.
Ability to work independently and self-motivate. Excellent problem solving, critical thinking, interpersonal, collaboration, written and verbal communication skills.
What will help you propel from the pack (Preferred Qualifications):
- Master's Degree
- Computer Science, Cybersecurity, Artificial Intelligence, Machine Learning, secure software engineering, or related technical field.
- 5+ years of technical experience in cybersecurity domains.
- 4+ years of hands-on experience writing production-level code, preferably with strong Python expertise and additional experience in Go, JavaScript, TypeScript, or API-driven development.
- Experience with open-source agentic frameworks like LangChain, AutoGen, Semantic Kernel, CrewAI, or similar orchestration tools.
- Experience building or securing LLM-based applications, RAG pipelines, AI agents, API integrations, or AI-enabled cybersecurity workflows.
- CISSP, CCSP, ISSAP, ISSEP, ISSMP, CISM, CRISC, CEH, GIAC Family, or equivalent cybersecurity certification.
- AI, cloud, or secure software development certifications are preferred.
- Knowledge of AI security standards and guidance such as OWASP Top 10 for LLM Applications, NIST AI RMF, or similar guidance.