Full Job Description
Job Summary
The Senior Cyber Security Engineer / Security Automation Engineer will support enterprise security engineering, automation, custom tool development, system integration, and operational security functions. The role requires strong hands-on experience with security automation, Python development, identity and access management, Linux systems, enterprise security technologies, APIs, SDKs, dashboards, and command-line tools. The engineer will design, develop, implement, troubleshoot, and continuously improve security tools, automations, systems, and services while supporting security operations and engineering teams in a rapidly evolving environment.
Key Responsibilities
• Plan, design, develop, deploy, administer, and provide operational support for enterprise security automations and custom security tools.
• Develop Python-based automations, internal web applications, APIs, SDK integrations, scripts, dashboards, command-line utilities, and system integrations.
• Develop automated workflows for alert enrichment, triage, incident response, case management, notifications, containment, escalation, and reporting.
• Develop custom tools to support CVE vetting, vulnerability enrichment, prioritization, tracking, and security decision-making.
• Support the planning, design, deployment, and operation of security platforms including DSPM, ASM, IAM, vulnerability management, email security, endpoint security, SIEM, XDR, SOAR, logging, monitoring, network security, cloud security, and threat intelligence technologies.
• Develop, test, deploy, and maintain automated security workflows, applications, and scripts using Python, PowerShell, Bash, REST APIs, JSON, YAML, vendor SDKs, and other appropriate technologies.
• Integrate security platforms with ticketing, case management, notification, identity, data sources, APIs, SDKs, and other enterprise systems.
• Assist with identity and access management functions, including user provisioning, deprovisioning, access reviews, role-based access control, service accounts, API credentials, authentication, authorization, and identity-based integrations.
• Deploy, configure, patch, monitor, optimize, and troubleshoot Linux systems supporting security sensors, collectors, connectors, applications, containers, and data-processing services.
• Support Docker-based environments and other containerized security services.
• Support security architects, engineers, analysts, and incident responders through platform troubleshooting, automation development, system integration, technical escalation, knowledge transfer, and operational handoffs.
• Monitor and report on automation health, application availability, system performance, sensor status, integration failures, API errors, vulnerability status, and other security engineering metrics.
• Ensure high availability, resilience, backup, recovery, patching, lifecycle management, secure configuration, and controlled change processes for security tools, Linux systems, applications, automations, and supporting services.
• Collaborate with security and technology stakeholders to align solutions with business objectives, industry-standard frameworks, regulatory requirements, and organizational risk tolerance.
• Participate in an on-call rotation supporting security operations and respond to after-hours technical issues as required.
Required Qualifications
• Bachelor's degree in Information Technology, Computer Science, Software Engineering, Information Security, or a related field, or equivalent relevant work experience.
• 8+ years of relevant professional experience, with experience substituting for education where applicable.
• 5+ years of experience supporting large IT environments, security systems, software development, and/or system deployments.
• Broad hands-on security engineering experience supporting multiple cybersecurity technologies, systems, integrations, and operational functions.
• Strong experience developing security automation and response workflows using Python, PowerShell, Bash, REST APIs, JSON, YAML, and vendor SDKs.
• Advanced Python development experience, including experience with internal web applications, APIs, databases, source control, testing, and software deployment practices.
• Strong hands-on experience designing, implementing, and troubleshooting workflow automation.
• Experience implementing error handling, exception management, retry mechanisms, and workflow optimization in automation solutions.
• Strong understanding of API integrations, including authentication, API throttling, rate limiting, data ingestion, and error handling.
• Strong Linux administration experience, including deployment, configuration, patching, scripting, service management, monitoring, troubleshooting, and lifecycle management.
• Strong understanding of Identity and Access Management concepts, including authentication, authorization, RBAC, SSO, MFA, and privileged access management.
• Hands-on experience with security engineering, security automation, and secure system design.
• Experience developing or supporting internal web applications, APIs, dashboards, databases, command-line tools, and related software components.
• Experience troubleshooting complex technical issues across applications, security platforms, operating systems, networks, identity services, and integrations.
• Experience implementing enterprise-scale automation and security solutions in production environments.
• Strong knowledge of DNS security, DNS filtering, threat intelligence, malware protection, and secure internet access controls.
• Experience with secure web gateway and DNS-layer security technologies.
• Strong ability to communicate technical concepts clearly and provide solution-oriented approaches to integration, automation, and security challenges.
• Strong engineering mindset with demonstrated hands-on technical experience.
Preferred Qualifications
• Experience with Cisco Umbrella, Cisco Secure Access, or comparable DNS-layer security and secure web gateway technologies.
• Experience supporting DSPM, ASM, IAM, vulnerability management, email security, endpoint security, SIEM, XDR, SOAR, logging, monitoring, network security, cloud security, and threat intelligence platforms.
Certifications
• CISSP, Security+, GIAC, or another relevant cybersecurity certification is preferred.
• Linux, Python, cloud, IAM, or another relevant security engineering or platform certification is preferred.