Automation Engineer — AI-Driven Code Security & Remediation Framework

New York, NY, US • Posted 1 day ago • Updated 1 day ago
Contract Corp To Corp
Contract Independent
Contract W2
12 Months
No Travel Required
On-site
Depends on Experience
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Python
  • AI-Driven Automation
  • Vulnerability Scanning
  • GitHub
  • GitHub Actions
  • GitHub Advanced Security
  • JFrog Artifactory
  • JFrog Xray
  • Snyk
  • CodeQL
  • Dependabot
  • Trivy
  • Semgrep
  • CVE/CVSS
  • EOL Detection
  • LLM/Agentic AI
  • AI-Driven Code Remediation
  • Prompt Engineering
  • CI/CD
  • Jenkins
  • Docker
  • Airflow
  • Bash
  • API Integration
  • JSON/SQL
  • SBOM
  • Software Supply Chain Security
  • Semantic Versioning
  • Automated Testing
  • Regression Testing
  • Security Automation
  • Risk-Based Vulnerability Prioritization

Summary

Hi All,
 
 
Position: Automation Engineer — AI-Driven Code Security & Remediation Framework
Location: NYC, NY (3 days onsite is must )
Duration: 12 Months

Role Summary
Builds and operates a system that scans GitHub/Artifactory repos for vulnerabilities and EOL libraries, then uses AI-driven automation to remediate findings — cutting manual triage and patch time firm-wide.
 
Core Technical Skills
  • Programming: Strong Python (scanners, orchestration, API integration); basic Bash for CI/CD glue
  • Source & Artifact Systems: GitHub (Actions, Advanced Security, PR workflows) and JFrog Artifactory/Xray; ability to scale across multi-repo, multi-language codebases
  • Scanning Tools: Hands-on with Snyk, Xray, CodeQL / Dependabot, Trivy, or Semgrep; understanding of CVE/CVSS scoring and EOL-detection sources (e.g., endoflife.date)
  • AI-Driven Remediation: Building agentic workflows (LLM-based) that interpret findings, generate patch PRs, run tests, and summarize fixes; prompt engineering for code-editing agents
  • CI/CD & Orchestration: Integrating scan-and-fix pipelines into GitHub Actions/Jenkins; Docker for isolated fix-testing; scheduling via Airflow/cron
  • Reporting: Structuring findings (JSON/SQL) into dashboards for tracking coverage and trends
 
Supporting Skills
  • Security fundamentals (injection, auth flaws, supply-chain/SBOM risk)
  • Risk-based prioritization beyond raw CVSS scores
  • Semantic versioning awareness for safe auto-upgrades
  • Testing discipline — regression validation before auto-merge
 
Communication Skills
  • Translating vulnerability data into concise, risk-framed leadership updates (exposure counts, MTTR, fix-rate trends)
  • Writing clear status emails on scan coverage and outstanding critical items
  • Building the business case (time saved, risk reduced) for non-technical stakeholders
 
Continuous Learning
  • Tracking emerging agentic/AI remediation tools and evaluating fit before firm-wide adoption
 
Skill Levels
  • Expert Level resource: 8 to 10 or more total experience out of which at least three years of experience in the relevant AI driven automation for code scanning and remediation matching the above skills
  • Advanced level: Total 6 – 8 years of total experience out of which at least three years of experience in the relevant AI driven automation for code scanning and remediation matching the above skills
 
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10439682
  • Position Id: 31445-8947-1790108119
  • Posted 1 day ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Hybrid in New York, New York

Yesterday

Easy Apply

Contract

50 - 55

New York, New York

Today

Contract

Jersey City, New Jersey

Yesterday

Easy Apply

Contract

80

Jersey City, New Jersey

Today

Full-time

USD 175,750.00 - 260,000.00 per year

Search all similar jobs