Description
Description:
Job Requisition ID: 41776
Be part of market-leading projects with global scale and complexity Mentoring, coaching and leadership programs to help you make an impact that matters Reimbursements for professional development and subsidised qualifications
What will your typical day look like?
Reporting to the Director of SOC Engineering, you will own the engineering of our agentic SOC platform: a multi-agent system where a supervisor agent orchestrates a team of specialist agents to triage security alerts end to end, from the moment an alert lands to a reasoned disposition an analyst can trust.
On a given day, you might design a new specialist agent and wire it into the orchestration graph, harden an agent against prompt injection, tune a Bedrock Guardrail so it stops the bad input without tripping on legitimate SOC content, extend the evaluation set that gates every deploy, or ship an infrastructure change through the pipeline as code.
You will move comfortably between hands-on building, reviewing other engineers' work, and stepping back to make the design call that keeps the platform coherent.
Alongside the platform, you will lend a hand to the team's wider AI work: helping our other agents along, and lifting the team's AI fluency, from practical skills to getting the most out of tools like Claude Code.
This is a role for someone who can pick up a slice of the platform and deliver it independently, from first commit to a deployed, evaluated, observable agent running in production.
About The Team
You will join a small, high-impact engineering team that builds and runs the internal platforms behind our managed security services.
We treat agents as software: version controlled, typed, tested, peer reviewed, and shipped through CI.
Our culture is straightforward and down to earth, more t-shirts and jeans than suits, and we care a lot about getting the engineering right.
The platform sits at the centre of our AI agenda, so you will work closely with the Cyber AI team, the SOC that consumes what the agents produce, and the infrastructure pod that runs the cloud underneath it.
You will also help level up other engineers as they move from writing automation scripts into building real agents, so a genuine interest in mentoring matters here.
What will your typical day look like?
Agent Platform Engineering Design, build and maintain production-grade AI agents, orchestration workflows and integrations that automate end-to-end security alert triage and investigation.
LLM, Agent & Security Architecture Make sound design decisions across models, agents, workflows and security controls, ensuring systems are reliable, secure and resilient to adversarial input.
Evaluation & Observability Develop evaluation frameworks, quality gates, tracing and monitoring capabilities that ensure agent behaviour is measurable, explainable and continuously improving.
Platform Engineering & Operations Own the AWS infrastructure underpinning the platform, delivering and operating it through infrastructure as code, CI/CD and production monitoring.
Technical Leadership Mentor engineers, review code, establish engineering standards and help grow agent engineering capability across the team.
Stakeholder Collaboration Work closely with SOC analysts, Cyber AI teams and platform engineers to deliver solutions that meet operational and business needs.
AI Enablement Support broader AI initiatives and contribute to the adoption of AI engineering best practices across the organisation.
Documentation, Risk & Compliance Maintain clear documentation and ensure security, privacy and compliance requirements are embedded throughout the platform lifecycle.
Enough About Us, Let's Talk About You
You are an engineer first.
You write real, tested, typed Python and you are at home in a modern toolchain.
You have moved beyond wiring agents together and can reason about the trade-offs: when to use an agent, how to make it reliable, how to prove it works, and how to run it safely in production.
You can take a body of work from idea to deployed reality on your own, and you raise the people around you as you go.
Required Skills
5+ years of relevant engineering experience, with demonstrable experience building and shipping production software, and hands-on experience building AI agents or LLM-powered applications.
Strong Python engineering practices, with type hints, sensible use of classes and dataclasses, decorators and context managers, and clean project structure.
Comfortable with the modern toolchain (uv, ruff, mypy, pytest, pre-commit).
Experience writing tests, including mocking external services, and you build and maintain CI pipelines (Azure DevOps).
Practical understanding of how LLMs and agents work (tokens, context, prompting, structured output, tool use, RAG and multi-agent patterns) and hands-on experience building agent runtimes, orchestration frameworks and production AI agents, ideally with Strands or a comparable framework.
Solid experience with AWS, including Bedrock.
Experience with AgentCore, or the ability to get there quickly, is a strong plus.
Proven ability to define and ship infrastructure as code, ideally with AWS CDK in Python and Terraform.
Awareness of prompt injection and the risks of untrusted input, and practical experience defending against them with guardrails, input validation, and least privilege design.
Experience evaluating non-deterministic systems (eval sets, LLM as judge) and instrumenting them so their behaviour can be traced and understood.
A track record of owning and delivering complex technical work end to end, with sound judgement on design trade-offs.
Ability to mentor engineers, review code constructively, and explain technical decisions clearly to both technical and non-technical audiences.
Desirable skills
Experience in a SOC, MDR, or wider cyber security context, and familiarity with frameworks such as MITRE ATT&CK.
Experience with PostgreSQL (SQLAlchemy, Alembic) and NoSQL database Exposure to building typed API clients and services (FastAPI), including auth, pagination, and graceful failure handling.
Familiarity with Microsoft Graph, Defender, or Sentinel, and with Azure alongside AWS.
Relevant AWS, Azure, or security certifications
Why Deloitte?
At Deloitte, we focus our energy on interesting and impactful work.
We’re always learning, innovating and setting the standard; making a positive difference to our clients and our society.
We putcoaching at the heart of what we do, helping our people grow their careers in any direction – whether it be up, moving into something new, or even moving across the world.
We embrace diversity, equity and inclusion.
We have a diverse collection of people from different backgrounds, with different experiences, gender identities, abilities and thinking styles.
What binds us together is a shared commitment to value everyone’s perspective and to cultivate inclusion; so that our work environment is a safe space we can all belong.
We value in-person connection with our clients and our colleagues.
We offer several ways for you to work flexibly so that you can serve your clients, stay connected with your team, and manage your personal priorities.
We help you live and work well.
To support your personal and professional life, we offer a range of perks and benefits , including retail discounts, wellbeing leave, paid volunteering days, twelve flexible working options, market-leading parental leave and return to work support package.
Next Steps
Sound like the sort of role for you? Apply now, we’d love to hear from you!
By applying for this job, you’ll be assessed against the Deloitte Talent Standards.
We’ve designed these standards so that you can grow in your career, and we can provide our clients with a consistent and exceptional Deloitte employee experience globally.
The preferred candidate will be subject to background screening by Deloitte or by their external third-party provider.