Systems Engineer- Security

Randstad
Malvern, PA, United States
14 days ago

Role details

Contract type
Contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Compensation
$113,339.0 - $123,739.0
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Systems Engineering Automation of Tests Bioinformatics Cyber Security Data Deduplication Information Engineering Data Integration Electronic Data Interchange (EDI) Intrusion Detection and Prevention JSON
+17 more
Python (Programming Language) Network Security Open Source Technology Security Information and Event Management Software Engineering Systems Integration Software Vulnerability Management Workflow Management Systems Extensible Markup Language (XML) Cloud Platform System Delivery Pipeline Cyber Threat Analysis Cybercrime Enterprise Integration Restful APIs Webhooks Devsecops

Job description

job summary: Responsibilities

This role sits at the intersection of threat intelligence, security engineering, automation, and software development. You will work closely with Threat Intelligence, Incident Response, Detection Engineering, Threat Hunting, Vulnerability Management, and Security Operations teams to develop scalable solutions that transform intelligence into action while enhancing Client’s ability to anticipate, detect, and respond to cyber threats.

Threat Intelligence Automation

Design, develop, and maintain automation workflows that support intelligence collection, enrichment, analysis, dissemination, and reporting.

Build integrations between the Threat Intelligence Platform (TIP), SOAR platforms, SIEMs, cloud environments, and security tooling.

Design and maintain automated workflows for ingestion, enrichment, deduplication, scoring, validation, and dissemination of indicators of compromise (IOCs).

Integrate commercial, open-source, industry, internal, and government intelligence sources into the TIP and related security platforms.

Automate delivery of intelligence to security controls, including SIEM, EDR, email security, network security, and detection engineering platforms.

Threat Intelligence Platform Engineering

Serve as a primary technical owner of the Threat Intelligence Platform, responsible for automation development, data quality, platform integrations, workflow design, and capability maturation.

Identify opportunities to improve platform performance, scalability, and user experience.

Vulnerability Intelligence Automation

Develop automation pipelines that collect, normalize, enrich, and correlate vulnerability intelligence from sources including NVD, CISA KEV, vendor advisories, ISACs, security research, and internal telemetry.

Build workflows that correlate vulnerabilities with threat actor activity, exploit availability, malware campaigns, and enterprise technology exposure.

Security Operations Integration

Partner with Incident Response, Detection Engineering, Threat Hunting, Vulnerability Management, and Security Operations teams to automate intelligence-driven workflows.

Develop integrations that improve information sharing, operational collaboration, and workflow efficiency across security teams.

Translate intelligence requirements and analyst use cases into scalable automation and engineering solutions.

Collections and Data Engineering

Develop and maintain data ingestion, normalization, transformation, and enrichment processes that support intelligence operations.

Serve as a technical leader for intelligence collections engineering and data integration initiatives.

Innovation and Continuous Improvement

Identify opportunities to eliminate manual processes and improve efficiency through automation and orchestration.

Evaluate and implement emerging technologies, including AI-enabled capabilities, that enhance intelligence collection, enrichment, analysis, and operational effectiveness.

Establish metrics and reporting to measure automation effectiveness, analyst efficiency gains, intelligence delivery speed, and operational outcomes.

location: Malvern, Pennsylvania job type: Contract salary: $54.49 - 59.49 per hour work hours: 8am to 5pm education: Bachelors

responsibilities: Responsibilities

This role sits at the intersection of threat intelligence, security engineering, automation, and software development. You will work closely with Threat Intelligence, Incident Response, Detection Engineering, Threat Hunting, Vulnerability Management, and Security Operations teams to develop scalable solutions that transform intelligence into action while enhancing Client’s ability to anticipate, detect, and respond to cyber threats.

Threat Intelligence Automation

  • Design, develop, and maintain automation workflows that support intelligence collection, enrichment, analysis, dissemination, and reporting.
  • Build integrations between the Threat Intelligence Platform (TIP), SOAR platforms, SIEMs, cloud environments, and security tooling.
  • Design and maintain automated workflows for ingestion, enrichment, deduplication, scoring, validation, and dissemination of indicators of compromise (IOCs).
  • Integrate commercial, open-source, industry, internal, and government intelligence sources into the TIP and related security platforms.
  • Automate delivery of intelligence to security controls, including SIEM, EDR, email security, network security, and detection engineering platforms.

Threat Intelligence Platform Engineering

  • Serve as a primary technical owner of the Threat Intelligence Platform, responsible for automation development, data quality, platform integrations, workflow design, and capability maturation.
  • Identify opportunities to improve platform performance, scalability, and user experience.

Vulnerability Intelligence Automation

  • Develop automation pipelines that collect, normalize, enrich, and correlate vulnerability intelligence from sources including NVD, CISA KEV, vendor advisories, ISACs, security research, and internal telemetry.
  • Build workflows that correlate vulnerabilities with threat actor activity, exploit availability, malware campaigns, and enterprise technology exposure.

Security Operations Integration

  • Partner with Incident Response, Detection Engineering, Threat Hunting, Vulnerability Management, and Security Operations teams to automate intelligence-driven workflows.
  • Develop integrations that improve information sharing, operational collaboration, and workflow efficiency across security teams.
  • Translate intelligence requirements and analyst use cases into scalable automation and engineering solutions.

Collections and Data Engineering

  • Develop and maintain data ingestion, normalization, transformation, and enrichment processes that support intelligence operations.
  • Serve as a technical leader for intelligence collections engineering and data integration initiatives.

Innovation and Continuous Improvement

  • Identify opportunities to eliminate manual processes and improve efficiency through automation and orchestration.
  • Evaluate and implement emerging technologies, including AI-enabled capabilities, that enhance intelligence collection, enrichment, analysis, and operational effectiveness.
  • Establish metrics and reporting to measure automation effectiveness, analyst efficiency gains, intelligence delivery speed, and operational outcomes.

qualifications: Qualifications

Minimum of three years of cybersecurity experience with at least one year focused on security engineering, automation, DevSecOps, software development, or related technical disciplines.

Robust proficiency in Python and experience developing and maintaining automation workflows and APIs.

Experience integrating systems using REST APIs, webhooks, and modern data exchange methodologies.

Experience working with structured and unstructured security data, including JSON, XML, CSV, and related formats.

Experience with threat intelligence concepts, methodologies, and operational workflows

Experience implementing or supporting Threat Intelligence Platforms (TIPs) and intelligence standards such as STIX, TA

Equal Opportunity Employer: Race, Color, Religion, Sex, Sexual Orientation, Gender Identity, National Origin, Age, Genetic Information, Disability, Protected Veteran Status, or any other legally protected group status.

At Randstad Digital, we welcome people of all abilities and want to ensure that our hiring and interview process meets the needs of all applicants. If you require a reasonable accommodation to make your application or interview experience a great one, please contact HRsupport@randstadusa.com.

Pay offered to a successful candidate will be based on several factors including the candidate’s education, work experience, work location, specific job duties, certifications, etc. In addition, Randstad Digital offers a comprehensive benefits package, including: medical, prescription, dental, vision, AD&D, and life insurance offerings, short-term disability, and a 401K plan (all benefits are based on eligibility).

This posting is open for thirty (30) days.

Any consideration of a background check would be an individualized assessment based on the applicant or employee’s specific record and the duties and requirements of the specific job.

,

Responsibilities

This role sits at the intersection of threat intelligence, security engineering, automation, and software development. You will work closely with Threat Intelligence, Incident Response, Detection Engineering, Threat Hunting, Vulnerability Management, and Security Operations teams to develop scalable solutions that transform intelligence into action while enhancing Client’s ability to anticipate, detect, and respond to cyber threats.

Threat Intelligence Automation

  • Design, develop, and maintain automation workflows that support intelligence collection, enrichment, analysis, dissemination, and reporting.
  • Build integrations between the Threat Intelligence Platform (TIP), SOAR platforms, SIEMs, cloud environments, and security tooling.
  • Design and maintain automated workflows for ingestion, enrichment, deduplication, scoring, validation, and dissemination of indicators of compromise (IOCs).
  • Integrate commercial, open-source, industry, internal, and government intelligence sources into the TIP and related security platforms.
  • Automate delivery of intelligence to security controls, including SIEM, EDR, email security, network security, and detection engineering platforms.

Threat Intelligence Platform Engineering

  • Serve as a primary technical owner of the Threat Intelligence Platform, responsible for automation development, data quality, platform integrations, workflow design, and capability maturation.
  • Identify opportunities to improve platform performance, scalability, and user experience.

Vulnerability Intelligence Automation

  • Develop automation pipelines that collect, normalize, enrich, and correlate vulnerability intelligence from sources including NVD, CISA KEV, vendor advisories, ISACs, security research, and internal telemetry.
  • Build workflows that correlate vulnerabilities with threat actor activity, exploit availability, malware campaigns, and enterprise technology exposure.

Security Operations Integration

  • Partner with Incident Response, Detection Engineering, Threat Hunting, Vulnerability Management, and Security Operations teams to automate intelligence-driven workflows.
  • Develop integrations that improve information sharing, operational collaboration, and workflow efficiency across security teams.
  • Translate intelligence requirements and analyst use cases into scalable automation and engineering solutions.

Collections and Data Engineering

  • Develop and maintain data ingestion, normalization, transformation, and enrichment processes that support intelligence operations.
  • Serve as a technical leader for intelligence collections engineering and data integration initiatives.

Innovation and Continuous Improvement

  • Identify opportunities to eliminate manual processes and improve efficiency through automation and orchestration.
  • Evaluate and implement emerging technologies, including AI-enabled capabilities, that enhance intelligence collection, enrichment, analysis, and operational effectiveness.
  • Establish metrics and reporting to measure automation effectiveness, analyst efficiency gains, intelligence delivery speed, and operational outcomes.

Requirements

Qualifications Minimum of three years of cybersecurity experience with at least one year focused on security engineering, automation, DevSecOps, software development, or related technical disciplines. Robust proficiency in Python and experience developing and maintaining automation workflows and APIs. Experience integrating systems using REST APIs, webhooks, and modern data exchange methodologies. Experience working with structured and unstructured security data, including JSON, XML, CSV, and related formats. Experience with threat intelligence concepts, methodologies, and operational workflows Experience implementing or supporting Threat Intelligence Platforms (TIPs) and intelligence standards such as STIX, TA

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.randstadusa.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:47 min

Exploring JSON, CBOR, and JOSE for data serialization

Aaron Russell · LIVE

1:28 min

Synchronizing database webhook triggers with pipeline webhooks

Bobur Umurzokov · LIVE

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

2:03 min

Distinguishing type definition constructs from data validation routines

Clemens Vasters Clemens Vasters · WWC 2025

Videos

See all

Related articles

See all