> Markdown version of [/jobs/ext/2203151-security-automation-architect](https://www.wearedevelopers.com/jobs/ext/2203151-security-automation-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Automation Architect - **Company:** The Smart - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Backup Devices, Bash Shell, Command-Line Interface, Cloud Computing, Cloud Computing Security, Cyber Security, System Configuration, Decision Support Systems, Linux, Monitoring of Systems, Identity and Access Management, JSON, Python (Programming Language), Windows PowerShell, Role-Based Access Control, Security Information and Event Management, Software Engineering, Systems Integration, User Provisioning Software, Software Vulnerability Management, Web Applications, WhatsUp Gold (Software), YAML, Data Logging, Data Processing, Scripting, System Availability, Information Technology, Palo Alto Networks, 3-tier Architectures, Restful APIs, Docker, Security Orchestration, Automation & Response - **Published:** August 23, 2026 - **Apply:** https://www.wayup.com/i-j-Security-Automation-Architect-SMART-TECH-SKILLS-LLC-731593838331806/ ## About the Role Required Qualifications * Bachelor's degree in Information Technology, Computer Science, Software Engineering, Information Security, or a related field (or 8 or more years of relevant experience in lieu of degree). * 5 or more years of experience supporting large enterprise IT environments, security systems, software development, or system deployments. * Broad hands-on security engineering experience supporting multiple cybersecurity technologies, integrations, and operational functions. * Strong experience developing security automations, custom tools, and scripts using Python. * Demonstrated experience deploying, configuring, patching, scripting, and troubleshooting Linux operating systems. * Experience building automation and incident response workflows using Python, PowerShell, Bash, REST APIs, JSON, YAML, and vendor SDKs. * Experience supporting IAM, vulnerability management, SIEM, SOAR, endpoint security, and cloud security platforms. * Strong understanding of enterprise security architecture, incident response, networking, access controls, and cybersecurity frameworks. * Ability to successfully pass mandatory comprehensive background checks and obtain CJIS certification. Preferred Qualifications * Hands-on security engineering experience in a large multi-tenant, shared-services, or managed-service environment. * Experience with Docker containerization, security sensors, monitoring tools, and platform administration. * Familiarity with enterprise tools such as Palo Alto Networks, Proofpoint, Tenable, Cribl, and WhatsUp Gold. * Relevant professional certifications (e.g., CISSP, Security+, GIAC, Linux, Python, or Cloud certifications). * Local residency in South Carolina to assist with physical hardware/sensor maintenance if needed. Core Skills & Attributes * Advanced analytical and troubleshooting capabilities across complex distributed environments. * Strong collaborative mindset to support SOC analysts, incident responders, and multi-agency stakeholders. * Excellent technical documentation skills for creating playbooks, runbooks, and architectural diagrams. * Self-sufficient, adaptable approach to balancing development projects with operational on-call escalations. ## Description Role Overview The Security Architect / Security Automation Engineer serves within an enterprise cybersecurity division, directly supporting security automation, custom tool development, IAM, and enterprise security platforms. This role collaborates with architects, engineers, SOC analysts, and incident responders across multiple public sector agencies to design, develop, deploy, and maintain automated security workflows, Linux-based security sensors, and integrated security technologies., Security Automation & Tool Development * Design, develop, deploy, and maintain custom security tools, internal web applications, APIs, SDK integrations, dashboards, and command-line utilities using Python. * Build automated workflows for alert enrichment, triage, incident response, case management, notifications, containment, and reporting using Python, PowerShell, Bash, REST APIs, JSON, and YAML. * Develop custom tools to support CVE vetting, vulnerability enrichment, prioritization, tracking, and risk decision support. Linux Systems & Security Infrastructure * Deploy, configure, patch, optimize, and troubleshoot Linux systems and Docker-based environments supporting security sensors, collectors, connectors, and data-processing services. * Ensure high availability, resilience, backup, recovery, patching, and secure configuration lifecycle management across security infrastructure. * Support and maintain enterprise security platforms, including DSPM, ASM, vulnerability management, email security, endpoint security, SIEM, SOAR, logging, and monitoring tools (e.g., Palo Alto Networks, Proofpoint, Tenable, Cribl, WhatsUp Gold). Identity, Operations, & SOC Support * Support Identity and Access Management (IAM) functions, including user provisioning/deprovisioning, access reviews, RBAC, service accounts, and API authentication. * Provide Tier 3 escalation support, platform troubleshooting, system integration, and operational handoffs for SOC analysts and incident responders. * Monitor and report on automation health, application availability, system performance, sensor status, and API integration errors. * Participate in a monthly on-call rotation supporting 24x7 SOC operations across multiple participating agencies. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [CI/CD with Github Actions](https://www.wearedevelopers.com/videos/856-ci-cd-with-github-actions) - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)