Automation Lead - DevSecOps & Vulnerability ManagementJob ID: J0526-2181
Location: Cleveland, OH / Pittsburgh, PA / Dallas, TX
Work Model: Onsite at Client Site
Employment Type: Permanent Full-Time
Position Overview We are seeking an experienced
Automation Lead to support the development of a dedicated
vulnerability management and security automation practice within a large U.S. banking environment.
This is a highly hands-on role focused on automating vulnerability remediation processes, building scalable
DevSecOps automation pipelines, implementing
policy-as-code, integrating enterprise security platforms, and enabling AI-driven vulnerability triage and remediation.
The Automation Lead will work closely with Solution Architects, AI/ML Engineers, security teams, and execution teams to build and maintain automation frameworks across vulnerability intake, remediation, CI/CD security, reporting, and intelligent automation.
Key Skills - DevSecOps
- Automation Engineering
- Vulnerability Management
- Python
- Ansible
- Terraform
- Jenkins
- GitHub Actions
- CI/CD
- ServiceNow REST API
- RITM Automation
- Docker
- Container Security
- OPA / Conftest
- Policy-as-Code
- SAST / DAST / SCA
- Container Scanning
- IaC Scanning
- REST APIs
- Archer
- Qualys / Tenable
- Tanium
- Sysdig
- SecurityCenter
- Imperva
- Jira
- LangChain
- Azure OpenAI
- AI/ML Automation
- Vulnerability Triage
- Infrastructure Automation
Automation Pipeline Development & Maintenance - Build, maintain, and enhance runbooks for L1 and L2 vulnerability remediation.
- Automate OS patching, base image updates, SSL/TLS configuration, infrastructure configuration changes, and middleware updates.
- Develop Python-based automation for vulnerability intake, deduplication, normalization, and routing.
- Integrate vulnerability data from Archer, Tanium, Sysdig, SecurityCenter, and Imperva.
- Build and maintain integrations with Jenkins and GitHub Actions.
- Develop automated pull-request generation for container base image and library version updates.
- Build automated ServiceNow RITM generation, routing, and status tracking.
- Monitor automation pipelines and implement proactive alerting and self-healing mechanisms.
Policy-as-Code & Security Automation - Implement policy-as-code using OPA / Conftest or equivalent technologies.
- Build automated security policy enforcement and risk-based gating within CI/CD pipelines.
- Develop security scanning integrations including:
- SAST
- DAST
- SCA
- Container scanning
- IaC scanning
- Secrets detection
- Build automated vulnerability feedback and retesting mechanisms.
- Implement compliance automation and audit-ready evidence generation.
AI & Intelligent Automation - Integrate vulnerability feeds with a LangChain-based AI triage and scoring engine.
- Build vulnerability deduplication and normalization across multiple security platforms.
- Develop automated vulnerability routing based on risk score, asset criticality, and remediation pathway.
- Build AI co-pilot integrations for automated L3 simple-fix PR generation.
- Develop Python-based AI agent pipelines using LangChain and Azure OpenAI.
- Build feedback loops to improve AI triage accuracy using remediation closure data.
Reporting & Dashboard Development - Build and maintain an Archer-based SLA compliance dashboard.
- Track vulnerability status, MTTR, backlog burn-down, severity, and remediation progress.
- Develop automated weekly SLA burn-down reports and monthly executive summaries.
- Build Jira-based tracking and workflow integrations.
- Develop data pipelines integrating Archer, ServiceNow, Jira, and vulnerability scanning platforms.
- Build operational dashboards for automation efficiency, runbook execution rates, PR throughput, and AI triage accuracy.
Continuous Improvement - Identify recurring manual processes suitable for automation.
- Monitor and optimize runbook execution performance.
- Improve automation throughput and reduce failure rates.
- Provide technical recommendations for continuous improvement of the automation framework.
- Document automation scripts, runbooks, and integration patterns in Confluence.
- Support knowledge transfer and adoption of new automation capabilities.
Required Qualifications - 8+ years of hands-on experience in DevSecOps, automation engineering, or infrastructure automation.
- Strong hands-on Python scripting experience.
- Strong Ansible and Terraform experience.
- Experience building automation scripts, API integrations, and data pipelines.
- Hands-on Jenkins and GitHub Actions experience, including pipeline development, maintenance, and troubleshooting.
- Production experience with at least two security scanning areas:
- SAST
- DAST
- SCA
- Container scanning
- IaC scanning
- Strong ServiceNow REST API integration experience.
- Experience automating ITSM workflows, RITM creation, routing, and status tracking.
- Strong Docker and container operations experience.
- Experience with base image management, Dockerfile optimization, and container security scanning.
- Hands-on OPA / Conftest or equivalent policy-as-code experience.
- Experience with vulnerability management or GRC platforms such as Archer, Qualys, or Tenable.
- Strong REST API development and integration experience.
- Strong Jira administration and workflow automation experience.
- Excellent verbal and written communication skills.
- Strong technical documentation and analytical skills.
- Strong attention to detail.
Preferred / Valuable Experience - Vulnerability remediation automation
- AI-driven vulnerability triage
- LangChain
- Azure OpenAI
- AI agents / intelligent automation
- Security orchestration
- AIOps
- Banking or financial-services environments
- Vulnerability SLA management
- Compliance automation
- Automated PR generation
- Multi-platform vulnerability normalization and deduplication
#M1
#DI-CB2
#L1 - KB1
Ref: #404-IT Pittsburgh