19 часов назад
Security Automation Architect
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Automation Architect (Python/Linux): Designing and operating automated security workflows, custom tools, APIs, and Linux-based security infrastructure with an accent on IAM, vulnerability management, and enterprise security platforms. Focus on building incident-response automation, integrating SIEM/SOAR and vendor technologies, and supporting resilient 24x7 SOC operations through Tier 3 escalation and on-call work.
Location: Fully remote within the US; local residency in South Carolina is preferred for occasional physical hardware and sensor maintenance.
Company
is a technology and professional services firm specializing in innovative technology management for clients nationwide.
What you will do
- Design, develop, deploy, and maintain custom security tools, internal web applications, APIs, SDK integrations, dashboards, and command-line utilities in Python.
- Build automation for alert enrichment, triage, incident response, case management, notifications, containment, reporting, and vulnerability risk prioritization.
- Deploy, configure, patch, optimize, and troubleshoot Linux systems and Docker-based environments supporting security sensors and data-processing services.
- Maintain enterprise security platforms covering DSPM, ASM, vulnerability management, email security, endpoint security, SIEM, SOAR, logging, and monitoring.
- Support IAM operations, platform integrations, system health monitoring, and Tier 3 escalations for SOC analysts and incident responders.
- Participate in a monthly on-call rotation supporting 24x7 SOC operations across multiple public sector agencies.
Requirements
- Senior-level experience: 5+ years in enterprise IT, security systems, software development, or system deployments, or 8+ years of relevant experience in lieu of a degree.
- Bachelor’s degree in IT, computer science, software engineering, information security, or a related field, unless replaced by qualifying experience.
- Strong hands-on experience with security automation and custom tool development using Python, PowerShell, Bash, REST APIs, JSON, YAML, and vendor SDKs.
- Experience deploying, configuring, patching, scripting, and troubleshooting Linux systems.
- Experience with IAM, vulnerability management, SIEM, SOAR, endpoint security, cloud security, enterprise security architecture, incident response, networking, and access controls.
- Must pass comprehensive background checks and obtain CJIS certification.
Nice to have
- Experience with Docker, security sensors, monitoring tools, and platform administration.
- Familiarity with Palo Alto Networks, Proofpoint, Tenable, Cribl, and WhatsUp Gold.
- Security, Linux, Python, or cloud certifications such as CISSP, Security+, or GIAC.
- Local residency in South Carolina for physical hardware and sensor maintenance.
Culture & Benefits
- Fully remote work within the US.
- Collaboration with architects, engineers, SOC analysts, incident responders, and stakeholders across multiple agencies.
- Work combines development projects with operational support and on-call escalations.
- Competitive salary.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
CrowdStrike
18 часов назад
Associate Security Engineer
70 000 - 95 000$
7 часов назад
Staff Security Engineer - SecOps & Threats
231 089 - 265 931$
22 часа назад
Security Operations Lead (AI)
180 000 - 210 000$
2 дня назад
Senior Security Engineer (AI)
2 дня назад
Principal Security Engineer (AI Cybersecurity)
3 дня назад