> Markdown version of [/jobs/ext/1506958-python-developer-cybersecurity-automation-nist-800-53](https://www.wearedevelopers.com/jobs/ext/1506958-python-developer-cybersecurity-automation-nist-800-53). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Python Developer - Cybersecurity Automation (NIST 800-53) - **Company:** Advanced Industrial Technologies, LLC - **Location:** Washington, DC, United States - **Experience:** Expert - **Salary:** $125,000.0 - $143,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Airflow, Amazon Web Services, Data Analysis, Application Frameworks, Automation of Tests, Microsoft Azure, Cloud Computing, CompTIA Security+, Cyber Security, Cron, Information Security Management, Python (Programming Language), Machine Learning, Natural Language Processing, Kusto Query Language, Security Information and Event Management, Systems Integration, Azure Automation, Scripting, Cloud Platform System, Information Technology, Microsoft Sentinel, Machine Learning Operations, Restful APIs, Splunk, Devsecops, Api Management, Microservices - **Published:** July 30, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=4de9061a97246753 ## About the Role * Bachelor's degree in Computer Science, Cybersecurity, or related field (or equivalent experience) * 5+ years of Python development experience in enterprise environments * Strong understanding of: * NIST 800-53 Rev. 5 and 5A * Security controls and assessment methodologies * Experience integrating with APIs and data sources across security tools * Familiarity with: * SIEM platforms (e.g., Microsoft Sentinel, Splunk) * Cloud environments (Azure, AWS, or GCP) * Identity and access management systems * Experience writing scripts for automation, data collection, and analysis * Understanding of DevSecOps principles and CI/CD pipelines * Strong problem-solving skills and ability to work directly with non-developer stakeholders (e.g., ISSOs), * Experience implementing Continuous Monitoring or Continuous ATO (cATO) * Familiarity with FedRAMP, FISMA, or CMMC frameworks * Experience with Azure OpenAI or AI/ML integration in security workflows * Knowledge of: * KQL (Kusto Query Language) * REST APIs and microservices architecture * Experience working in federal or regulated environments * Security certifications (e.g., Security+, CISSP, CEH) Key Skills * Python (automation, scripting, API integrations) * Cybersecurity frameworks (NIST 800-53) * Data analysis and evidence correlation * Automation and orchestration * AI-assisted workflows (nice to have) * Communication with security and compliance stakeholders, * Python development: 5 years (Required) * worked in enterprise environments: 5 years (Required) * NIST SP 800-53 Rev. 5 or 5A controls: 5 years (Required) * cybersecurity control testing or validation: 5 years (Required) * Azure, AWS, or GCP cloud environment: 5 years (Required) License/Certification: * CISSP (Preferred) * CompTIA Security+ (Preferred) ## Description We are seeking an experienced Python Developer to support the automation of cybersecurity control testing aligned with NIST SP 800-53 Rev. 5 and 5A. This role will focus on designing and implementing automated scripts that assess the effectiveness of security controls across multiple enterprise systems.The developer will work closely with Information System Security Officers (ISSOs), security engineers, and compliance teams to translate control requirements into automated test procedures. The goal is to reduce manual testing, improve consistency, and enable continuous monitoring through scalable, AI-assisted automation.Key Responsibilities * Design, develop, and maintain Python-based automation scripts to test and validate cybersecurity controls (NIST 800-53 Rev. 5 / 5A) * Integrate with enterprise systems (e.g., cloud platforms, SIEMs, endpoint tools, identity systems) to collect evidence for control validation * Collaborate with ISSOs and cybersecurity teams to: * Interpret control requirements * Define measurable testing criteria * Assess control effectiveness * Implement automated, scheduled testing capabilities using orchestration tools (e.g., cron, Airflow, Azure Automation) * Develop reusable frameworks for continuous control monitoring (CCM) * Leverage AI/ML technologies (e.g., Azure OpenAI, anomaly detection, natural language processing) to: * Assist in control analysis * Automate evidence review and classification * Improve testing efficiency and insights * Create dashboards and reporting outputs that clearly demonstrate compliance status and risk posture * Ensure scripts are secure, well-documented, and aligned with DevSecOps best practices * Support integration into CI/CD pipelines for security validation * Maintain traceability between controls, test procedures, and system evidence ## Related Videos - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [From Messy Queries to Scalable Systems - How Data Engineering actually works](https://www.wearedevelopers.com/videos/100203-from-messy-queries-to-scalable-systems-how-data-engineering-actually-works) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [From clicks to cribs - How to find your dream home with web scraping](https://www.wearedevelopers.com/videos/767-from-clicks-to-cribs-how-to-find-your-dream-home-with-web-scraping) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [AI Model Management Life Circles: ML Ops For Generative AI Models From Research to Deployment](https://www.wearedevelopers.com/videos/1152-ai-model-management-life-circles-ml-ops-for-generative-ai-models-from-research-to-deployment) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 13 Best Python Libraries for Developers in 2025](https://www.wearedevelopers.com/magazine/371-the-13-best-python-libraries-for-developers-in-2025) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)