About the role
You are the blue team. You harden the Snaga AI platform and the hosts it runs on, watch the audit log for what should not be there, run incident response, and track the actors who target investigators and newsrooms. Svitlo gives you the information-operations side of a campaign; the platform's agents triage and enrich under your signature.
Working with AI — your co-executors
Your SOC has agents in it. Platform agents triage alerts, enrich indicators and draft incident timelines under your signature; Svitlo shows you the information-operations side of the same campaign. You hunt, decide, contain and write the post-mortem — and you define which actions the agents may take on their own and which always wait for you.
You are not using AI tools; you are working in a team where AI agents are co-executors. Every role at Snaga has its own pod of agents on the Snaga AI platform: a Planning agent that turns a brief into a plan, Builder agents that do the first pass of the work, a QA agent that checks it, and a Knowledge agent that answers with citations from our documents. Agents plan and execute; the person sets the goal, reviews the result, signs every action that leaves the sandbox, and teaches the agents where they were wrong. Every step is in an immutable audit log, so you always see what the agents did and why.
Our tools, exclusively
All work and all training happen on Snaga's own instruments: the Quark browser, the Snaga AI orchestration platform and the Svitlo agent. Quark delegates work by conversation — to the Snaga Code agent for development and to Svitlo for information research — keeps every account in its own isolated profile, and asks for your explicit approval before anything touches passwords, e-mail, payments or deletions. On the platform your work runs as agent teams (Planning, Builder, QA, Knowledge) in a Plan→Build→QA→Deliver→Learn loop; every action that leaves the sandbox waits for a human signature, every step is in an immutable audit log, and knowledge agents answer with citations. You will be trained on these tools in your first weeks and you will help make them better.
How we work
Remote-first, async by default, with a weekly review. Tooling is ours; equipment is on us.
What you will do
- Run detection and response for the platform, hosts and endpoints
- Harden Docker, Caddy, SSH and the deployment pipeline; own the firewall rules
- Hunt threats against our investigators and the newsrooms we work with
- Produce threat-intelligence reports linking cyber and information operations
- Lead incident post-mortems and turn them into controls
- Work with AI agents every day as co-executors: brief them, review their output, sign what matters, and teach them where they were wrong
What we expect
- 4+ years in security operations, incident response or threat intelligence
- Linux, Docker and network security hands-on
- SIEM or log analysis, IOC handling, MITRE ATT&CK
- Secure handling of sensitive case data
- Readiness to work and train exclusively on Snaga's tools: Quark, the Snaga AI platform and the Svitlo agent
- Comfort working alongside AI agents as co-executors: delegating, reviewing their output critically, and taking responsibility for the signed result
- English B2 or higher
Nice to have
- OSCP, GCIH, GCTI or equivalent
- Experience protecting journalists or NGOs
What you get
- Remote, flexible hours
- Equipment and tooling budget
- Paid training and certifications
Skills
- Incident response
- Threat intelligence
- Linux
- Docker
- SIEM
- MITRE ATT&CK
- Svitlo