Bachelor's degree in Computer Science, Cybersecurity, or related field (or equivalent experience)
Proficiency in scripting/programming languages such as Python, PowerShell, Bash, or Go
Experience with Microsoft Defender APIs, Palo Alto Networks SCM/Panorama APIs, and cloud security APIs (Azure, AWS, or GCP)
Solid understanding of cloud security principles, IAM, network segmentation, and compliance frameworks
Familiarity with infrastructure-as-code (IaC) and automation tools (e.g., Terraform, Hugo, GitHub)
Experience with SIEM and SOAR platforms
Responsibilities
Develop and maintain automation scripts and applications to support security operations, configuration management, and policy enforcement across various platforms.
Integrate APIs from Microsoft Defender XDR, Palo Alto Panorama/SCM, and cloud-native security tools into internal systems and dashboards.
Build and maintain data pipelines for ingesting and normalizing logs into SIEM platforms like Microsoft Sentinel and Splunk.
Collaborate with cloud and security engineers to implement secure configurations and monitor compliance in hybrid environments.
Automate remediation workflows and support SOAR integrations for incident response.
Monitor platform health, performance, and configuration drift across cloud and on-prem environments.
Document code, integration processes, and platform configurations for operational transparency.
Benefits
Potential for career advancement in a growing cybersecurity field
Opportunity to work with leading cloud security technologies and tools
Collaborative environment with cloud and security engineers
Focus on automation and innovative security solutions
Exposure to a range of cloud platforms and cybersecurity frameworks
Full Job Description
Key Responsibilities:
Develop and maintain automation scripts and applications to support security operations, configuration management, and policy enforcement across Microsoft Defender, Palo Alto SCM, and cloud platforms (Azure, AWS, GCP).
Integrate APIs from Microsoft Defender XDR, Palo Alto Panorama/SCM, and cloud-native security tools (e.g., Azure Security Center, AWS Security Hub) into internal systems and dashboards.
Build and maintain data pipelines for ingesting and normalizing logs into SIEM platforms (e.g., Microsoft Sentinel, Splunk).
Collaborate with cloud and security engineers to implement secure configurations, monitor compliance, and respond to threats in hybrid environments.
Automate remediation workflows and support SOAR integrations for incident response.
Monitor platform health, performance, and configuration drift across cloud and on-prem environments.
Document code, integration processes, and platform configurations for operational transparency and audit readiness.
Qualifications:
Bachelor's degree in Computer Science, Cybersecurity, or related field (or equivalent experience).
Proficiency in scripting/programming languages such as Python, PowerShell, Bash, or Go.
Experience with Microsoft Defender APIs, Palo Alto Networks SCM/Panorama APIs, and cloud security APIs (Azure, AWS, or GCP).
Solid understanding of cloud security principles, IAM, network segmentation, and compliance frameworks.
Familiarity with infrastructure-as-code (IaC) and automation tools (e.g., Terraform, Hugo, GitHub).
Experience with SIEM and SOAR platforms.
Preferred Qualifications:
Certifications such as Microsoft Certified: Azure Security Engineer Associate, PCNSE, AWS Certified Security - Specialty, or CISSP.
Experience with hybrid cloud environments and multi-cloud security architectures.
Knowledge of MITRE ATT&CK, CIS Benchmarks, and NIST frameworks.
Experience with DevSecOps pipelines and CI/CD security integration.