Description
Location: EU (remote)
Role: AI Forward Deployed Engineer
Focus: Agentic AI, Autonomous SOC, AI Agents & Customer Deployments
About the Role
Imperum is building an Autonomous SOC powered by Agentic AI, where AI agents don't just generate recommendations - they investigate alerts, reason across security data, interact with security technologies, execute workflows, and collaborate with human analysts.
We are looking for an AI Forward Deployed Engineer (FDE) who can take these capabilities into real customer environments.
This is a highly technical, hands-on role at the intersection of AI engineering, software engineering, cybersecurity, and customer deployment.
You will work directly with customers, SOC teams, MSSPs, Imperum engineering, and our AI team to design, deploy, integrate, troubleshoot, and improve Agentic AI solutions in production environments.
You should be equally comfortable writing Python, building an agent graph, integrating an API, debugging a deployment, and sitting with a SOC team to understand why an AI investigation is not producing the expected result.
Think of Imperum as a LEGO Set for Agentic AI
Imperum provides the building blocks for the Autonomous SOC: AI agents, integrations, tools, workflows, data, security actions, LLMs, automation, and orchestration.
Think of Imperum as a LEGO set for Agentic AI.
Your role as a Forward Deployed Engineer is to take those building blocks and build what the customer actually needs.
One customer may need an autonomous phishing investigation agent.
Another may need AI-driven alert triage across Microsoft and CrowdStrike.
An MSSP may need a multi-tenant investigation workflow coordinating multiple specialized agents.
Another customer may need an entirely new agentic use case that does not exist yet.
Understand the customer's problem and operational environment.
Select the right Imperum capabilities, agents, tools, integrations, and data.
Design the required agentic workflow.
Build missing components in Python when necessary.
Connect agents to customer technologies and APIs.
Test, deploy, evaluate, and continuously improve the solution.
Turn successful customer-specific implementations into reusable building blocks for the Imperum platform.
Imperum gives you the Agentic AI building blocks.
Your job is to assemble them into solutions that solve real customer problems.
This means you are not simply deploying a predefined product.
You are combining AI + cybersecurity + software engineering + customer knowledge to build new Autonomous SOC capabilities directly in the field.
What You Will Do
Build & Deploy Agentic AI
Design and implement production-grade AI agents and multi-agent workflows.
Build agents using LangChain, LangGraph, and similar agentic frameworks.
Implement agent orchestration, routing, planning, reasoning, tool use, memory, state management, and human-in-the-loop workflows.
Connect LLMs and AI agents with real cybersecurity tools and customer infrastructure.
Build and optimize AI workflows for alert triage, investigation, case prioritization, threat hunting, incident response, detection engineering, forensics, and security automation.
Forward Deployment
Work directly inside complex enterprise and MSSP environments to turn customer requirements into working AI systems.
Use Imperum as a modular Agentic AI building platform: assemble existing capabilities, create what is missing, and deliver the solution the customer needs.
Deploy Imperum Autonomous SOC capabilities in customer environments.
Configure and customize AI agents for specific customer use cases.
Build customer-specific tools, integrations, prompts, workflows, and agent graphs.
Troubleshoot production AI behavior and analyze why an agent made a particular decision.
Integrate customer security technologies, APIs, data sources, and internal systems.
Take customer requirements back to the core engineering team and help turn them into scalable product capabilities.
This is not a pure research or prompt-engineering position.
You will own the path from idea -> code -> integration -> deployment -> production outcome.
Technical Requirements
Strong Python Engineering
Excellent hands-on knowledge of Python is mandatory.
Async Python REST APIs and WebSockets SDK development Data processing and Pydantic FastAPI Testing and debugging Authentication and API integrations Production-quality error handling and observability
Agentic AI
LangChain and LangGraph Tool/function calling and structured outputs Multi-agent architectures Agent state and memory Agent orchestration, planning, and reasoning workflows Human-in-the-loop architectures Agent evaluation and guardrails Context engineering and prompt engineering Model routing and retry/fallback strategies Experience with LlamaIndex, CrewAI, AutoGen, or similar frameworks is valuable.
LLM Engineering
OpenAI-compatible APIs and Anthropic/Claude models Open-source LLMs and the Hugging Face ecosystem Local/on-premise LLM deployment Embeddings, RAG, and vector search Context management and token optimization Model selection and routing Structured generation LLM evaluation and benchmarking Model distillation, fine-tuning, SLMs, LoRA/QLoRA, quantization, or ML models such as LightGBM/XGBoost are a strong advantage.
AI Agent Infrastructure
MCP (Model Context Protocol) Tool calling / function calling REST and GraphQL APIs, Webhooks, OpenAPI / Swagger OAuth2, API keys, and service accounts Event-driven architectures, queues, and asynchronous processing Agent permissions and access control You should understand that production agents need more than intelligence - they need identity, permissions, observability, auditability, deterministic controls, and safe execution boundaries.
Data & Infrastructure
Docker and Kubernetes Linux and Git CI/CD OpenSearch / Elasticsearch Vector databases Kafka / Redpanda Redis and SQL Azure, AWS, or GCP GPU and CPU inference On-premise and air-gapped deployments
Cybersecurity Knowledge
You don't need to have spent your entire career in a SOC, but you must understand - or be able to rapidly learn - how modern security operations work.
SOC operations SIEM EDR / XDR SOAR / Hyperautomation Detection engineering Incident response Threat hunting DFIR MITRE ATT&CK Sigma Security alerts and telemetry False-positive reduction Case management Previous experience integrating platforms such as Microsoft Sentinel/Defender, CrowdStrike, Splunk, Palo Alto, Fortinet, Elastic, OpenSearch, or similar technologies is a strong advantage.
Production AI Mindset
We are particularly interested in engineers who understand that a successful AI system is not simply: Prompt -> LLM -> Answer
Production Agentic AI requires:
Data -> Context -> Model -> Reasoning -> Tools -> Actions -> Validation -> Human Feedback -> Learning
Why an agent reached a decision and whether that decision can be trusted.
How actions are authorized and agent behavior is evaluated.
How hallucinations and incorrect actions are contained.
How agent execution is logged and audited.
How systems recover when models or tools fail.
How latency and token consumption are controlled.
How AI performance improves from real-world feedback.
What Makes a Great Candidate
Excellent Python engineer.
Has built real LLM or Agentic AI applications.
Hands-on experience with LangGraph and/or LangChain.
Understands APIs, integrations, and distributed systems.
Enjoys solving difficult problems directly with customers.
Can independently debug unfamiliar environments.
Can rapidly prototype while writing production-quality code.
Understands that AI agents must interact safely with real systems.
Communicates clearly with both engineers and security teams.
Prefers building and shipping over producing endless architecture diagrams.
Nice to Have
Autonomous or multi-agent systems Cybersecurity products SOC/SIEM/SOAR platforms MCP servers Local and air-gapped LLMs RAG architectures LLM observability and evaluation Model distillation Detection-as-Code Machine learning for security telemetry Enterprise SaaS MSSP / multi-tenant environments Customer-facing engineering Integrations against undocumented or difficult APIs
Why This Role Is Different
At Imperum, AI agents are being applied to real security operations, not isolated chatbot use cases.
Observe -> Investigate -> Reason -> Decide -> Collaborate -> Act -> Learn
You will help deploy AI into environments containing thousands of endpoints, millions of security events, multiple security technologies, SOC analysts, and complex enterprise processes.
Your work will directly influence how the Imperum Autonomous SOC investigates threats, reduces analyst workload, automates security operations, and evolves toward increasingly autonomous cyber defense.
What we offer
Compensation package combining competitive base salary and RSUs (Restricted Stock Units).Top-tier hardware and a generous budget for AI tools, courses, conferences, and model API creditsFlexible remote setupA team that treats AI engineering as a craft worth mastering – you will ship real, hard, meaningful work, fast.