Sr. Cyber Security Engineer - Automation

Versant View all jobs
Englewood Cliffs, NJ, United States
1 day ago
Apply on www.careerjet.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
$130,000.0 - $160,000.0
Working hours
Regular working hours

Tech stack

Artificial Intelligence Amazon Web Services Amazon S3 Audit Trail Cloud Computing Security Cloud Engineering Code Review Cyber Security Continuous Integration Data Validation Github Identity and Access Management
+23 more
Intrusion Detection and Prevention Python (Programming Language) OpenID Role-Based Access Control Secure Coding Security Information and Event Management Tripwire Policy as Code Data Logging Large Language Models Multi-Agent Systems Software Security Amazon Virtual Private Cloud (VPC) AI Platforms Kubernetes Infrastructure Automation Frameworks Opsworks Cloudwatch Terraform Devsecops Serverless Computing Docker Security Orchestration, Automation & Response

Job description

The Senior Automation Security Engineer designs and delivers scalable automation that strengthens the organization’s security posture and engineering velocity. This role combines strong Python engineering with deep working knowledge of GitHub/GitHub Actions, Terraform, and AWS. The engineer leads secure automation patterns, enables disciplined internal use of AI tools, and builds production-quality agentic workflows with appropriate governance, observability, and human control. What You Will Do Automation Platform Engineering

  • Design, build, and operate reusable Python services, libraries, CLIs, and integrations that automate security controls and operational workflows.
  • Establish engineering standards for reliability, testing, observability, secrets handling, access control, and lifecycle ownership of automations.
  • Automate high-value workflows such as identity and access reviews, cloud configuration remediation, evidence collection, security findings enrichment, exception management, and incident response orchestration.

GitHub, GitHub Actions & DevSecOps

  • Own and improve GitHub Actions patterns for secure CI/CD, including reusable workflows, OIDC-based cloud access, artifact controls, approvals, and policy checks.
  • Integrate code scanning, dependency controls, secrets detection, IaC scanning, tests, and release gates into engineering workflows without unnecessary delivery friction.
  • Review workflow and repository permissions, third-party actions, supply-chain risks, and runner security; drive pragmatic remediation.

Terraform & AWS Security Automation

  • Design and maintain Terraform modules, guardrails, and policy-as-code controls for AWS environments.
  • Automate secure AWS configuration across IAM, Organizations, VPC, CloudTrail, CloudWatch, S3, KMS, Lambda, ECS/EKS, Secrets Manager, and related services.
  • Build safe detection and remediation flows using least privilege, change controls, dry runs, rollback approaches, and audit-ready logging.

Internal AI Enablement & Agent Development

  • Develop governed internal AI automations and agents that use approved models, tools, knowledge sources, and identity boundaries.
  • Design agent workflows with explicit tool scopes, input validation, prompt-injection defenses, audit logs, evaluation cases, and human-in-the-loop approvals for material actions.
  • Create reusable patterns for tool calling, retrieval/RAG, workflow orchestration, context handling, and secure deployment; mentor teams on their use.
  • Champion responsible AI-assisted or “vibe coding” practices: clear review accountability, source validation, secure code patterns, and protection of internal data.

Technical Leadership

  • Translate security and operational needs into an automation roadmap, architecture, and measurable outcomes.
  • Lead technical design reviews, mentor junior engineers, and partner with platform, cloud, SOC, and application teams.
  • Communicate tradeoffs and risk clearly to technical and non-technical stakeholders., * Automation products materially reduce manual work, improve control coverage, and have clear owners, runbooks, telemetry, and SLAs.
  • GitHub Actions and Terraform controls improve delivery security while remaining usable for engineering teams.
  • AWS risks are prevented, detected, or remediated through durable automation and measurable reduction in recurrence.
  • Internal AI agents deliver bounded business value while passing security review, evaluation, and operational-readiness criteria.
  • Teams adopt consistent, safe AI-assisted development practices and can reuse documented automation patterns.

Level Expectations

  • Independently owns ambiguous, cross-team automation problems from design through production operation.
  • Sets technical direction and guardrails; does not merely implement tickets.
  • Mentors others and raises the engineering quality, security posture, and AI readiness of the broader organization.

Requirements

  • Strong Python software engineering skills, including API integration, testing, packaging, error handling, and production troubleshooting.
  • Hands-on expertise with GitHub and GitHub Actions, including reusable workflows, OIDC, permissions, secure secrets use, and CI/CD controls.
  • Strong Terraform experience: modules, state, plans, code review, testing, and policy or guardrail implementation.
  • Deep practical understanding of AWS security and cloud architecture, especially IAM, network boundaries, logging, encryption, and serverless/container services.
  • Experience designing automation that is reliable, observable, least-privileged, and safe to roll out.
  • Demonstrated ability to lead design discussions, review code, and guide work across teams.
  • Working knowledge of AI/LLM application risks and the engineering controls needed for safe agentic automation., * Experience with security orchestration, SIEM/SOAR, detection engineering, incident response, or vulnerability-management automation.
  • Experience with policy-as-code and cloud security tools such as OPA, Checkov, tfsec, Trivy, AWS Config, Security Hub, or GuardDuty.
  • Hands-on delivery with LLM APIs, agent frameworks, MCP, RAG, evaluation frameworks, or enterprise AI platforms.
  • AWS Security Specialty, AWS DevOps Engineer, CISSP, Security+, or comparable certification.
  • Experience operating workloads with Docker, Kubernetes, ECS, or EKS.

Benefits & conditions

For LA County and City Residents Only: VERSANT Media will consider for employment qualified applicants with criminal histories, or arrest or conviction records, in a manner consistent with relevant legal requirements, including the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, where applicable. If you are a qualified individual with a disability or a disabled veteran and require support throughout the application and/or recruitment process as a result of your disability, you have the right to request a reasonable accommodation. You can submit your request to . VERSANT Media is committed to fair and equitable compensation practices. We include a good faith pay range for each position to comply with applicable state and local pay transparency laws and to promote equity across our organization. Actual compensation will be based on factors such as the candidate’s skills, qualifications, experience, and location and may include additional forms of compensation and benefits such as health insurance, retirement plans, paid time off, etc. VERSANT Media is not accepting unsolicited assistance from search firms for this employment opportunity. All resumes submitted by search firms to any employee at VERSANT via-email, the Internet, or in any form and/or method without a valid written Statement of Work in place for this position from VERSANT’s Talent Acquisition team will be deemed the sole property of VERSANT. No fee will be paid in the event the candidate is hired by VERSANT as a result of the referral or through other means. By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website’s terms and privacy policy apply, + $110,000-120,000 per year Software Guidance & Assistance, Inc., (SGA), is searching for a Cyber Security Engineer / Analyst for a full-time position with one of our premier financial services clients in New…

  • 8 days ago +

About the company

VERSANT (Nasdaq: VSNT) is an industry-changing media and entertainment business and home to trusted brands that shape culture, inform audiences, and build lasting connections. It operates across four core markets: political news and opinion, business news and personal finance, golf, and sports and genre entertainment. These markets are served through a powerful portfolio of iconic and innovative brands, including CNBC, MS NOW, USA Network, Golf Channel, Oxygen, E!, SYFY, and Versant’s sports division USA Sports, along with complementary digital assets including Fandango, Rotten Tomatoes, GolfNow and GolfPass.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

5:01 min

Bridging the gap between software development and security

Vandana Verma · LIVE

2:34 min

Docker sandbox architecture and microVM environment integration

Manuel de la Peña Manuel de la Peña · World Congress 2026 Europe

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

Videos

See all

Related articles

See all