Job Title: Automation Lead
Location: Dallas, Texas, United States
Type: Direct Hire
Responsibilities
- Lead the development and maintenance of automation pipelines for vulnerability management, including OS patching, image updates, SSL/TLS configurations, and infrastructure changes.
- Create and sustain automation scripts for vulnerability intake, deduplication, and routing across multiple scan sources such as Archer, Tanium, Sysdig, SecurityCenter, and Imperva.
- Implement and support CI/CD pipeline integrations utilizing Jenkins and GitHub Actions, including automated pull request generation for container images and version updates.
- Develop and maintain automation for RITM generation in ServiceNow, enabling trigger-based routing and status updates without manual intervention.
- Apply policy-as-code rules using OPA/Conftest to enforce security policies within development pipelines.
- Build and manage automated vulnerability scanning integrations including SAST, DAST, SCA, container, and IaC scanning tools.
- Collaborate with AI/ML teams to integrate AI triage engines, including vulnerability deduplication, risk-based routing, and AI co-pilot PR generation tools.
- Create dashboards and reports for SLA compliance, vulnerability status, MTTR, and operational metrics using Archer, Jira, and other tools.
- Identify opportunities to automate manual tasks, monitor system performance, and optimize automation workflows for efficiency and reliability.
- Document scripts, runbooks, and processes, and facilitate knowledge transfer to operations teams.
Requirements
- 8+ years of experience in DevSecOps, automation engineering, or infrastructure automation.
- Proven proficiency in Python scripting, Ansible, and Terraform for automation and data pipelines.
- Hands-on experience with Jenkins and GitHub Actions for pipeline development, maintenance, and troubleshooting.
- Experience implementing CI/CD security integrations with at least two tools such as SAST, DAST, SCA, container scanning, or IaC scanning in production.
- ServiceNow API integration, including RITM creation and status tracking via REST API.
- Docker container management, security scanning, and image optimization experience.
- Policy-as-code implementation experience with OPA/Conftest or similar tools.
- Experience with vulnerability management platforms such as Archer, Qualys, or Tenable.
- Strong REST API development and multi-system automation pipeline experience.
- Jira administration and workflow automation familiarity.
- Excellent verbal and written communication skills with solid technical documentation experience.
- High attention to detail to identify discrepancies and ensure accuracy in transactions and data.
System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.
#M-
#LI-
Ref: #404-IT Pittsburgh