5+ years in supporting large IT environments and security systems.
Bachelor's in IT, Computer Science, Software Engineering, Information Security, or equivalent experience.
Advanced proficiency in Python development for security automation.
Proficient in scripting with PowerShell and Bash.
Experience in Integration of cybersecurity technologies via APIs and SDKs.
Hands-on experience with key security platforms such as SIEM, SOAR, and EDR.
Solid knowledge of enterprise security architecture and incident response protocols.
Responsibilities
Plan and deploy custom security automations and tools using Python and other technologies.
Build automated workflows for incident management and response processes.
Develop tools for vulnerability tracking and security decision support.
Test and maintain security workflows and scripts to ensure reliability.
Integrate security systems with enterprise infrastructure and ticketing systems.
Monitor performance and availability of automation applications and systems.
Support SOC analysts through troubleshooting and technical escalation.
Benefits
100% remote work opportunity with a VPN requirement.
Participation in a monthly on-call rotation for 24x7 SOC support.
Preference for local candidates for occasional on-site maintenance tasks.
Full Job Description
Primary Responsibilities
Plan, design, develop, deploy, and support enterprise security automations and custom tools, including Python-based automations, internal web applications, APIs, SDKs, scripts, dashboards, command-line utilities, and system integrations.
Build automated workflows for alert enrichment, triage, incident response, case management, notifications, containment, escalation, and reporting.
Develop custom tools for CVE vetting, vulnerability enrichment, prioritization, tracking, and security decision support.
Develop, test, deploy, and maintain security workflows and scripts using Python, PowerShell, Bash, REST APIs, JSON, YAML, and vendor SDKs.
Secondary Responsibilities
Support a broad range of security platforms, including DSPM, ASM, IAM, vulnerability management, email security, endpoint security, SIEM, XDR, SOAR, logging, monitoring, network security, cloud security, and threat intelligence.
Integrate security tools with ticketing, case management, notification, identity, and other enterprise systems.
Support technologies such as Palo Alto Networks, Proofpoint, Tenable, Cribl, and WhatsUp Gold.
Assist with IAM functions including provisioning/deprovisioning, access reviews, RBAC, service accounts, API credentials, authentication, and authorization.
Deploy, configure, patch, monitor, and troubleshoot Linux systems supporting security sensors, collectors, connectors, containers (Docker), and data-processing services.
Monitor and report on automation health, application availability, system performance, sensor status, integration failures, and API errors.
Ensure high availability, backup, recovery, patching, lifecycle management, secure configuration, and controlled change processes.
Support SOC analysts, incident responders, and agency customers through troubleshooting, technical escalation, knowledge transfer, and documentation.
Required Skills
Broad, hands-on security engineering experience across multiple cybersecurity technologies, systems, and integrations.
Advanced Python development, including workflow design, error handling, and building automations that integrate multiple systems end to end.
Strong experience integrating technologies via APIs, SDKs, and web services, including handling API throttling/rate limits, authentication methods, and data ingestion.
Scripting proficiency in Python, PowerShell, and Bash, with a clear understanding of how each runs across Linux and Windows environments.
Linux deployment, configuration, patching, scripting, service management, monitoring, and troubleshooting.
Hands-on experience with IAM, DSPM, ASM, vulnerability management, email and endpoint security, SIEM, SOAR, logging, and cloud security.
Solid knowledge of DNS security (e.g., Cisco Umbrella / Cisco Secure Access).
Strong understanding of enterprise security architecture, incident response, networking, access control, secure software development, and industry-standard cybersecurity frameworks.
Preferred Skills
Experience as a security engineering generalist in a large, multi-tenant, shared-services, or managed-service environment.
Hands-on Docker, security sensor, and platform administration experience.
Experience developing internal web applications, dashboards, databases, and CLI tools, with familiarity in full-stack development, source control, testing, and deployment practices.
Familiarity with Palo Alto Networks, Proofpoint, Tenable, Cribl, or WUG.
Experience writing playbooks, runbooks, procedures, and technical documentation.
Education & Experience
Bachelor's degree in Information Technology, Computer Science, Software Engineering, Information Security, or a related field (8 years of relevant experience may substitute for a degree).
5+ years supporting large IT environments, security systems, software development, and/or system deployments.
Preferred Certifications
CISSP, Security+, GIAC, or another relevant cybersecurity certification
Linux, Python, Cloud, or IAM certifications
Work Environment
100% remote via VPN; all work must be performed within the contiguous United States.
Monthly on-call rotation supporting a 24x7 SOC, with after-hours maintenance and incident escalation as needed.
Preference for South Carolina-based candidates who can occasionally assist with on-site equipment and hardware maintenance.