Senior Security Automation Engineer AI/DevSecOps | Contract | New York, NY (Hybrid)
Senior Security Automation Engineer AI/DevSecOps
Location: New York, NY Hybrid (3 days onsite per week) - Local Or Near by Area
Duration: 12 Months
Job Type: Contract
Job Overview
We are seeking a highly experienced Senior Security Automation Engineer to design, build, and operate an AI-driven security automation framework for large-scale software environments.
The engineer will develop automated workflows that scan source-code repositories and software artifacts for vulnerabilities, outdated/EOL dependencies, and software supply-chain risks, then leverage AI-driven automation to analyze findings and accelerate remediation through automated code changes and pull requests.
This is an ideal opportunity for a senior engineer with a strong combination of Python automation, Application Security/DevSecOps, GitHub, artifact security, CI/CD, and Generative AI/LLM experience.
Key Responsibilities
- Build and maintain Python-based automation for vulnerability scanning, analysis, remediation, and reporting.
- Integrate security scanning and remediation workflows across GitHub repositories and artifact-management platforms.
- Develop automated workflows to identify vulnerabilities, CVEs, outdated dependencies, and EOL libraries.
- Build AI/LLM-powered workflows that analyze security findings, recommend fixes, generate code changes, create pull requests, and validate remediation.
- Integrate security automation with GitHub Actions, Jenkins, and other CI/CD platforms.
- Develop scalable solutions capable of operating across large, multi-repository and multi-language environments.
- Containerize automated remediation and testing workflows using Docker.
- Automate scheduling and orchestration using tools such as Airflow or cron.
- Structure vulnerability and remediation data using JSON, SQL, or similar technologies for reporting and dashboards.
- Implement regression and validation checks before automated changes are approved or merged.
- Apply risk-based prioritization using CVE/CVSS, exploitability, business impact, dependency criticality, and EOL considerations.
- Collaborate with security, engineering, DevOps, and leadership teams to communicate vulnerability exposure, remediation progress, and MTTR.
- Evaluate emerging AI-driven security and code-remediation technologies and recommend appropriate solutions.
Required Technical Skills
- 8+ years of overall software, automation, security, or DevOps engineering experience.
- Strong hands-on Python development and automation experience.
- Strong experience with GitHub, GitHub Actions, and Git-based PR workflows.
- Experience with JFrog Artifactory/Xray or comparable artifact security platforms.
- Hands-on experience with one or more security scanning tools such as Snyk, CodeQL, Dependabot, Trivy, or Semgrep.
- Strong understanding of CVE, CVSS, vulnerability management, dependency security, SBOM, and software supply-chain risks.
- Experience developing AI/LLM, Generative AI, or agentic automation workflows for code analysis or remediation.
- Experience integrating automation with CI/CD pipelines, preferably GitHub Actions and/or Jenkins.
- Experience with Docker and automated testing environments.
- Strong understanding of software versioning and safe dependency upgrades.
- Strong API integration and workflow-orchestration experience.
Preferred Skills
- Bash scripting.
- Airflow or similar orchestration tools.
- SQL and JSON-based reporting.
- Experience with automated pull-request generation and code remediation.
- Experience with LLM-based code agents and prompt engineering.
- Application Security / Product Security experience.
- Experience operating security automation at enterprise scale.
Experience Levels
Expert: 8 10+ years overall experience, including 3+ years of relevant AI-driven automation, security scanning, and remediation experience.
Advanced: 6 8 years overall experience, including 3+ years of relevant AI-driven automation, security scanning, and remediation experience.
Soft Skills
- Strong analytical and problem-solving skills.
- Ability to translate technical security findings into concise business-oriented updates.
- Strong written and verbal communication.
- Ability to work with engineering, security, DevOps, and leadership stakeholders.
- Strong interest in emerging AI and security automation technologies.