GitHub Platform & Security Automation Engineer
URSI Technologies Inc.
San Jose, CA, United States
about 2 months ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source
Tech stack
Application Programming Interfaces (APIs)
Audit Trail
Build Automation
Continuous Integration
Github
Identity and Access Management
Python (Programming Language)
Key Management
OAuth
Azure Active Directory
Security Information and Event Management
Policy as Code
+12 more
Scripting
Cloud Platform System
Okta
System Availability
Software Security
Git
Github Enterprise
Enterprise Integration
Graphql
Restful APIs
Devsecops
Security Orchestration, Automation & Response
Job description
We are seeking a hands-on engineer to drive GitHub Enterprise (GHE) platform security, automation, and operational excellence across large-scale environments. This role will focus on building enterprise-grade controls, improving developer experience, and ensuring compliance through automation and observability., · Design and implement secure GitHub authentication controls, including MFA enforcement for Git CLI/API usage and token governance (PATs, OAuth, GitHub Apps)
- Build automation to audit and enforce repository governance, including detection of public/internal repos, policy violations, and access misconfigurations
- Implement and operate end-to-end observability and monitoring for self-hosted GitHub Enterprise (GHE) - availability, performance, security events, and usage trends
- Develop User Behavior Analytics (UBA) leveraging GitHub audit logs, API telemetry, and integrations (SIEM/SOAR) to identify anomalies, insider risk, and misuse patterns
- Lead secure migration of repositories across GHE instances, maximizing retention of metadata (issues, PRs, comments, actions, permissions) using GitHub APIs and automation frameworks
- Define and enforce DevSecOps policies via GitHub Actions, branch protection rules, secret scanning, and code security integrations
- Work on patching, upgrades, and lifecycle operations for GHE, ensuring high availability and minimal disruption
- Automate compliance reporting and continuous audit readiness (access reviews, repo classification, artifact traceability), · Implement zero-trust access models for GitHub (device posture + identity-aware access)
- Integrate supply chain security controls (SBOM, provenance, dependency scanning, signed commits)
- Build developer productivity tooling (self-service onboarding, repo templates, policy-as-code)
- Enable GitHub Actions hardening (runner security, secrets management, ephemeral runners)
- Experience with cross-platform integrations (Okta, Azure AD, SIEM tools, vaults, CI/CD systems)
Requirements
· Strong experience with GitHub Enterprise Server and GitHub APIs/GraphQL
- Solid background in security automation, IAM, and DevSecOps
- Experience with Python/Go scripting, REST APIs, and automation frameworks
- Desirable - Familiarity with SIEM/observability platforms and audit log analytics
- Prior experience with large-scale repo migrations and platform operations
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on dice.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
EM
Eli McGarvie
almost 3 years ago
EM
Eli McGarvie
The Top 10 GitHub Alternatives (2025)
almost 3 years ago
BH
Bridgette Hernandez
4 reasons to start or update your GitHub profile
over 5 years ago
CH
Chris Heilmann
Dev Digest 120 - Apple and peers
about 2 years ago
CH
Chris Heilmann
Dev Digest 121 - AI goes offline
about 2 years ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
6 months ago