Quick Overview
Seniority
Mid Senior
Work mode
Hybrid
Location
United States
Posted
2 days ago
DockerBashPowerShellPythonREST
Job Description
Primary Responsibilities:
Primarily assist in the planning, design, development, deployment, administration and operational support of enterprise security automations and custom security tools, including:
- Python-based automations, internal web applications, APIs, SDKs, scripts, dashboards, command-line utilities and system integrations
- Automated workflows for alert enrichment, triage, incident response, case management, notifications, containment, escalation and reporting
- Custom tools to assist with CVE vetting, vulnerability enrichment, prioritization, tracking and security decision support
Secondary Responsibilities:
- Secondarily assist in the planning, design, deployment and operational support of a broad range of security platforms, including: DSPM, ASM, IAM, vulnerability management, email security, endpoint security, SIEM, XDR, SOAR, logging, monitoring, network security, cloud security and threat intelligence technologies integrations with ticketing, case management, notification, identity, data sources, APIs, SDKs and other enterprise systems as needed support for technologies such as Palo Alto Networks, Proofpoint, Tenable, Cribl, WhatsUp Gold and other current or future security products.
- Develop, test, deploy and maintain automated security workflows, applications and scripts using Python, PowerShell, Bash, REST APIs, JSON, YAML, vendor SDKs and other appropriate technologies.
- Assist with identity and access management functions, including user provisioning, deprovisioning, access reviews, role-based access control, service accounts, API credentials, authentication, authorization and identity-based system integrations.
- Deploy, configure, patch, monitor, optimize and troubleshoot Linux systems supporting security sensors, collectors, connectors, applications, containers and data-processing services, including Docker-based environments.
- Support Security Architects, Engineers, SOC Analysts, Incident Responders and agency customers through platform troubleshooting, automation development, system integration, technical escalation, knowledge transfer and operational handoffs.
- Monitor and report on automation health, application availability, system performance, sensor status, integration failures, API errors, vulnerability status, platform issues and other security engineering and operational metrics.
- Ensure high availability, resilience, backup, recovery, patching, lifecycle management, secure configuration and controlled change processes for security tools, Linux systems, applications, automations and supporting services.
- Collaborate with Security Architects, Engineers, Analysts, Incident Responders and agency stakeholders to align solutions with business goals, industry-standard frameworks, regulatory requirements and organizational risk tolerance.
Required Skills
(Ranked by Importance):
- Broad hands-on security engineering experience supporting multiple cybersecurity technologies, systems, integrations and operational functions.
- Experience integrating enterprise technologies using APIs, SDKs, web services, structured data formats, authentication methods and vendor-supported interfaces.
- Strong experience troubleshooting complex technical issues across applications, security platforms, operating systems, networks, identity services and integrations.
- Linux system deployment, configuration, patching, scripting, service management, monitoring, troubleshooting and lifecycle management
Preferred Skills
(Ranked by Importance):
- Hands-on experience serving as a security engineering generalist in a large, multi-tenant, shared-services or managed-service environment.
- Hands-on Linux, Docker, security sensor, monitoring, scripting and platform administration experience.
- Experience supporting SOC analysts, security engineers, incident responders, agency customers and rapidly changing operational priorities.
- Familiarity with Palo Alto Networks, Proofpoint, Tenable, Cribl, WUG or other enterprise security technologies and experience developing playbooks, runbooks, procedures and technical documentation
- Strong understanding of enterprise security architecture, incident response, networking, access control, secure software development, systems administration and industry-standard cybersecurity frameworks.
Required Education:
- Bachelor's degree in an Information Technology, Computer Science, Software Engineering or Information Security related field
- Eight years of relevant work experience (experience may be substituted in lieu of education)
- Five years of experience in supporting large IT environments, security systems, software development and/or system deployments
Preferred Certifications:
- CISSP, Security+, GIAC or other relevant cybersecurity certification
- Linux, Python, cloud, IAM or other relevant security engineering or platform certification
Similar jobs
- MA
Information System Security Officer
NewMANTECH
Chantilly, Virginia🇺🇸On-site1 hour agoTechnology - MA
Cyber Network Threat Analyst
NewMANTECH
Springfield, Virginia🇺🇸Hybrid1 hour agoTechnology - AC
Director of Security
NewAccorHotel
San Francisco, CA🇺🇸On-site2 days ago - CO
Chief Information Security Officer
City of Philadelphia
Philadelphia, PA🇺🇸$200k/yrOn-site3 days agoRailsAdministrative - EV
AI Security Engineer I
NewEVERSANA
Overland Park, KS🇺🇸$103.5k - $124.4k/yrRemote2 days agoAWSMLOpsMachine Learning+7Technology - SE
Sr Safety & Security Manager
NewServiceNow
Santa Clara, California🇺🇸HybridYesterdayRisk ManagementFinance