Quzara LLC

Quzara LLC

2 open positions available

1 location
1 employment type
Actively hiring
Full-time

Latest Positions

Showing 2 most recent jobs
Quzara LLC

Senior Full-Stack AI Engineer (Agentic Systems)

Quzara LLC•Anywhere•Full-time
View Job
Compensation$90K - 150K a year

Design, build, and ship full-stack software features including AI services focused on agentic workflows and LLM integration. | 7+ years experience with Python, JavaScript, TypeScript, production AI systems, cloud development, and ability to work independently remotely. | Job Title: Senior Full-Stack AI Engineer (Agentic Systems) Pay Type: SALARIED EXEMPT  Location: Remote What We’re Looking For: We're looking for an AI-native, hands-on engineer who builds and ships production-ready software across the full stack, not just AI prototypes. You use tools like Claude Code, Codex, GitHub Copilot, and Cursor to work faster, and you back them with sound engineering judgment, rigorous testing, and strong security practices. This is an engineering role, not a data science or research position. Summary of Position Role/Responsibilities The Senior Full-Stack AI Engineer – Agentic Systems will build and scale NISTCompliance.ai, Quzara's AI-enabled cybersecurity compliance platform. This senior, hands-on role designs, codes, tests, and ships production software across the full stack. It also covers building AI capabilities with leading large language models, including agentic workflows, retrieval-augmented generation (RAG), and document intelligence. The ideal candidate is an AI-native engineer who uses AI-assisted development tools to deliver secure, reliable, production-ready software, not prototypes.  Essential Functions of the Job * Design, build, test, and ship production features across frontend, backend, APIs, databases, and AI services. * Build AI-powered product capabilities using leading large language models and generative AI platforms. * Design and implement agentic workflows involving tool use, structured outputs, multi-step tasks, and human oversight. * Develop and improve retrieval-augmented generation (RAG), semantic search, document intelligence, and knowledge-retrieval capabilities. * Integrate AI capabilities into existing application workflows and enterprise systems. * Build reliable evaluation, testing, monitoring, and observability for AI-powered functionality. * Develop secure, scalable APIs and backend services supporting AI-enabled applications. * Use AI-assisted coding tools extensively for repository analysis, development, testing, debugging, refactoring, and code review. * Diagnose complex engineering problems across application, AI, data, and cloud layers. * Contribute to architecture, engineering standards, code reviews, and technical mentoring. * Evaluate emerging AI technologies and rapidly determine which capabilities are suitable for production use. Marginal Functions of the Job * Other duties as assigned Normal Work Schedule This is a full-time position. Standard business hours are Monday through Friday 8:30 AM to 5:30 PM. Additional time outside of these hours may be needed to complete the essential functions of the job. Education, Training, and Experience * 7+ years of professional software engineering experience. * Demonstrated experience owning complex software features or systems from design through production. * Strong full-stack development experience. * Advanced proficiency in Python. * Strong proficiency with JavaScript/TypeScript and modern web application development. * Experience building and integrating REST APIs and production backend services. * Experience with relational databases such as PostgreSQL or equivalent. * Hands-on experience integrating commercial LLMs such as Anthropic Claude, OpenAI models, or comparable platforms into production applications. * Practical experience with agentic AI, tool/function calling, structured model outputs, and multi-step AI workflows. * Experience building RAG or similar retrieval-based AI applications. * Significant hands-on experience with AI-assisted development environments such as Claude Code, Codex, GitHub Copilot, Cursor, Windsurf, or similar tools. * Strong understanding of software engineering fundamentals including testing, source control, CI/CD, observability, security, and maintainable application architecture. * Experience with Docker and modern cloud application development. * Ability to independently take ambiguous product requirements and turn them into production software. * U.S. citizenship required. Preferred Qualifications * Experience designing AI agents or multi-agent systems. * Familiarity with Model Context Protocol (MCP) or comparable agent/tool integration approaches. * Experience with AI orchestration frameworks and agent SDKs. * Experience with LLM evaluation, observability, benchmarking, or LLMOps platforms. * Experience with vector search, embeddings, document processing, or enterprise knowledge systems. * Experience building multi-tenant enterprise SaaS applications. * Experience with Microsoft Azure or other major cloud platforms. * Cybersecurity, compliance, GRC, or federal technology experience is helpful but not required. * Experience mentoring other software engineers. EEO Statement The Company is an Equal Employment Opportunity (EEO) employer and does not discriminate based on race, color, religion, sex, sexual orientation, national origin, age, marital status, disability, veteran's status, or any other basis protected by applicable discrimination laws.

JavaScript
TypeScript
API Design
Observability
Mentorship
Direct Apply
Posted 3 days ago
Quzara LLC

Principal Splunk Threat Detection & Integration Engineer

Quzara LLC•Anywhere•Full-time
View Job
Compensation$85K - 150K a year

Design, develop, and manage complex Splunk detection content and integrations across multiple security domains. | 8+ years security engineering with 5+ years Splunk ES experience, mastery of SPL, RBA design, CIM fluency, scripting, and senior-level detection engineering. | Job Title: Principal Splunk-Threat Detection & Integration Engineer Pay Type: SALARIED EXEMPT Location: Remote Summary of Position Role/Responsibilities We are hiring a Principal Splunk Threat Detection & Integration Engineer to own the detection content lifecycle in Splunk. This is a senior individual-contributor role: you build and review the most complex correlation searches and Risk-Based Alerting (RBA) logic, run the full Splunk Enterprise Security feature set (findings and intermediate findings, Risk Framework and Risk Factor Editor, Asset & Identity, and Threat Intelligence), and deliver custom integrations and automation across the security stack. You will create vendor-agnostic detections that remain effective across EDR, identity, NDR, email, and cloud platforms, mentor junior engineers, raise the bar in peer review, and act as the technical authority for the toughest cross-domain detection challenges. You will drive programs, not tickets. Essential Functions of the Job • Own the detection content lifecycle in Splunk Enterprise Security - design, SPL prototyping, validation, peer review, production deploy, tuning, and decommission. • Architect and govern the Risk-Based Alerting program - risk signals, risk notables, findings and intermediate findings, risk factor design, asset and identity-aware risk modifiers, throttling and deduplication strategies, and aggregate-score notable thresholds combining risk score, distinct detection sources, and distinct MITRE ATT&CK techniques. • Write, review, and optimize complex SPL - performance-conscious search design across accelerated data models, lookup and KV-store patterns, and REST-based content introspection. • Engineer the Splunk CIM normalization layer across the security-relevant data models - building base searches, calculated fields, and custom CIM mappings for non-standard log sources. • Design and operate the Asset & Identity framework - multiple authoritative data sources merged with priority-based logic, hostname normalization, time-bound IP-to-host resolution, and enrichment macros injected into every detection. • Operationalize the Threat Intelligence Framework - consolidating IOC feeds into the native ES intel KV-store collections, configuring TAXII/STIX ingestion, integrating vulnerability intelligence and CVE data, and operationalizing IOC matching into the RBA model rather than as standalone notables. • Develop custom integrations and automation across the security stack - bidirectional sync via REST APIs and HEC, custom Python connectors, modular inputs, and SOAR playbook authorship where automation is genuinely needed. • Build cross-domain detection coverage - identity, endpoint, network, cloud, web, email, SaaS, vulnerability/exposure, and insider/data - mapped to MITRE ATT&CK techniques and sub-techniques. • Onboard new log sources end-to-end when required - TA evaluation, custom extraction and parsing, CIM mapping, and ingest hardening - for the cases where new sources need to be added to the SIEM. • Manage Splunk license capacity through index-time filtering and routing, eliminating low-value telemetry without compromising detection coverage. • Build custom dashboards for the SOC integrated with detection workflows. • Document and peer-review every detection - every shipped detection has a structured wiki page with logic, MITRE mapping, exclusions, known false positives, and changelog. • Operate against tight delivery deadlines across multiple concurrent workstreams - translate requirements into deployable Splunk content under time pressure, coach Tier 1/2 analysts and Senior detection engineers, and serve as the named escalation point for the hardest cross-domain detection problems. Marginal Functions of the Job • Other duties as assigned Normal Work Schedule This is a full-time position. Standard business hours are Monday through Friday 8:30 AM to 5:30 PM. Additional time outside of these hours may be needed to complete the essential functions of the job. Education, Training, and Experience • 8+ years in security engineering, SOC/IR, or detection content development, including 5+ years' operating Splunk Enterprise Security in production. • Demonstrable mastery of SPL - performance-conscious search design, complex multi-value handling, lookup and KV-store patterns, and REST API introspection. • Production experience with the full Splunk ES framework set: correlation searches, findings and intermediate findings, adaptive response, the Risk Framework and Risk Factor Editor, Asset & Identity Management, and Threat Intelligence Management. • Senior-level Risk-Based Alerting practice - you have designed RBA from risk rules through risk notables, calibrated scoring across endpoint, identity, network, and cloud detection portfolios, and tuned aggregate scoring strategies. • Splunk CIM fluency across the security-relevant data models, including building base searches, diagnosing acceleration drift, and writing custom CIM mappings for non-conforming sources. • Hands-on detection engineering across all major security domains - identity, endpoint, network, cloud, web, email, SaaS, vulnerability/exposure, and insider/data - with MITRE ATT&CK mapping discipline. • End-to-end log onboarding capability - TA evaluation, custom extraction and parsing, CIM mapping, and ingest hardening - for the cases where new sources need to be added to the SIEM. • Custom integration and automation experience - REST APIs, HEC, modular inputs, and SOAR playbook/connector authorship in Python or equivalent. • Threat intelligence operationalization experience - bringing commercial and open-source IOC feeds into a SIEM detection workflow with proper enrichment and risk-scoring integration. • Strong scripting/automation in Python (or equivalent) for REST API automation and custom security tool integration. • At least one current Splunk certification: Power User, Enterprise Security Certified Admin (legacy), Cybersecurity Defense Analyst (SPLK-5001), Cybersecurity Defense Engineer (SPLK-5002), or Enterprise Certified Architect. • Comfortable working against tight delivery deadlines across multiple concurrent workstreams. Preferred Qualifications • Detection-as-Code experience successfully operating in production - Git-versioned detection content, schema-validated definitions, and CI/CD deployment pipelines into a SIEM. • Relevant GIAC certifications in detection and incident response (GCDA, GCFA, GCFE, GCIH, GREM, GNFA, IA). • Prior detection engineering experience in a complex SOC or SIEM-anchored security operations team. • Public detection contributions - pull requests to community detection repositories, published detection content, or open-source security tooling contributions. • Conference talk history at major security conferences. • Familiarity with industry schema and detection-rule standards beyond Splunk CIM. • Hands-on home-lab or personal detection engineering work - public detection blog, public repo, or other demonstrable portfolio. EEO Statement The Company is an Equal Employment Opportunity (EEO) employer and does not discriminate based on race, color, religion, sex, sexual orientation, national origin, age, marital status, disability, veteran's status, or any other basis protected by applicable discrimination laws.

Splunk Enterprise Security
Detection Engineering
SOAR Automation
Verified Source
Posted 2 months ago

Ready to join Quzara LLC?

Create tailored applications specifically for Quzara LLC with our AI-powered resume builder

Get Started for Free

Ready to have AI work for you in your job search?

Sign-up for free and start using JobLogr today!

Get Started »
JobLogr badgeTinyLaunch BadgeJobLogr - AI Job Search Tools to Land Your Next Job Faster than Ever | Product Hunt