Security Automation Architect

The Smart
United States
5 days ago
Apply on www.wayup.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Backup Devices Bash Shell Command-Line Interface Cloud Computing Cloud Computing Security Cyber Security System Configuration Decision Support Systems Linux Monitoring of Systems Identity and Access Management
+22 more
JSON Python (Programming Language) Windows PowerShell Role-Based Access Control Security Information and Event Management Software Engineering Systems Integration User Provisioning Software Software Vulnerability Management Web Applications WhatsUp Gold (Software) YAML Data Logging Data Processing Scripting System Availability Information Technology Palo Alto Networks 3-tier Architectures Restful APIs Docker Security Orchestration, Automation & Response

Job description

Role Overview The Security Architect / Security Automation Engineer serves within an enterprise cybersecurity division, directly supporting security automation, custom tool development, IAM, and enterprise security platforms. This role collaborates with architects, engineers, SOC analysts, and incident responders across multiple public sector agencies to design, develop, deploy, and maintain automated security workflows, Linux-based security sensors, and integrated security technologies., Security Automation & Tool Development * Design, develop, deploy, and maintain custom security tools, internal web applications, APIs, SDK integrations, dashboards, and command-line utilities using Python. * Build automated workflows for alert enrichment, triage, incident response, case management, notifications, containment, and reporting using Python, PowerShell, Bash, REST APIs, JSON, and YAML. * Develop custom tools to support CVE vetting, vulnerability enrichment, prioritization, tracking, and risk decision support. Linux Systems & Security Infrastructure * Deploy, configure, patch, optimize, and troubleshoot Linux systems and Docker-based environments supporting security sensors, collectors, connectors, and data-processing services. * Ensure high availability, resilience, backup, recovery, patching, and secure configuration lifecycle management across security infrastructure. * Support and maintain enterprise security platforms, including DSPM, ASM, vulnerability management, email security, endpoint security, SIEM, SOAR, logging, and monitoring tools (e.g., Palo Alto Networks, Proofpoint, Tenable, Cribl, WhatsUp Gold). Identity, Operations, & SOC Support * Support Identity and Access Management (IAM) functions, including user provisioning/deprovisioning, access reviews, RBAC, service accounts, and API authentication. * Provide Tier 3 escalation support, platform troubleshooting, system integration, and operational handoffs for SOC analysts and incident responders. * Monitor and report on automation health, application availability, system performance, sensor status, and API integration errors. * Participate in a monthly on-call rotation supporting 24x7 SOC operations across multiple participating agencies.

Requirements

Required Qualifications * Bachelor’s degree in Information Technology, Computer Science, Software Engineering, Information Security, or a related field (or 8 or more years of relevant experience in lieu of degree). * 5 or more years of experience supporting large enterprise IT environments, security systems, software development, or system deployments. * Broad hands-on security engineering experience supporting multiple cybersecurity technologies, integrations, and operational functions. * Strong experience developing security automations, custom tools, and scripts using Python. * Demonstrated experience deploying, configuring, patching, scripting, and troubleshooting Linux operating systems. * Experience building automation and incident response workflows using Python, PowerShell, Bash, REST APIs, JSON, YAML, and vendor SDKs. * Experience supporting IAM, vulnerability management, SIEM, SOAR, endpoint security, and cloud security platforms. * Strong understanding of enterprise security architecture, incident response, networking, access controls, and cybersecurity frameworks. * Ability to successfully pass mandatory comprehensive background checks and obtain CJIS certification. Preferred Qualifications * Hands-on security engineering experience in a large multi-tenant, shared-services, or managed-service environment. * Experience with Docker containerization, security sensors, monitoring tools, and platform administration. * Familiarity with enterprise tools such as Palo Alto Networks, Proofpoint, Tenable, Cribl, and WhatsUp Gold. * Relevant professional certifications (e.g., CISSP, Security+, GIAC, Linux, Python, or Cloud certifications). * Local residency in South Carolina to assist with physical hardware/sensor maintenance if needed. Core Skills & Attributes * Advanced analytical and troubleshooting capabilities across complex distributed environments. * Strong collaborative mindset to support SOC analysts, incident responders, and multi-agency stakeholders. * Excellent technical documentation skills for creating playbooks, runbooks, and architectural diagrams. * Self-sufficient, adaptable approach to balancing development projects with operational on-call escalations.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.wayup.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

1:35 min

Centralizing configuration logic with native YAML block references

Matthieu Vincent Matthieu Vincent · Europe 2026 Virtual

3:47 min

Exploring JSON, CBOR, and JOSE for data serialization

Aaron Russell · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

4:07 min

Preparing tools and authentication for automation

Johannes Ostner Johannes Ostner · Europe 2026 Virtual

2:00 min

Introduction to YAML syntax and basic formatting

Chris Ayers · LIVE

Videos

See all

Related articles

See all