Location: Malvern, PA
Description: Our client is currently seeking a Cyber Security Automation Engineer: Long term contract - HYBRID REMOTE - Mondays and Fridays Remote
Responsibilities
This role sits at the intersection of threat intelligence, security engineering, automation, and software development. You will work closely with Threat Intelligence, Incident Response, Detection Engineering, Threat Hunting, Vulnerability Management, and Security Operations teams to develop scalable solutions that transform intelligence into action while enhancing Vanguard's ability to anticipate, detect, and respond to cyber threats.
Threat Intelligence Automation
- Design, develop, and maintain automation workflows that support intelligence collection, enrichment, analysis, dissemination, and reporting.
- Build integrations between the Threat Intelligence Platform (TIP), SOAR platforms, SIEMs, cloud environments, and security tooling.
- Design and maintain automated workflows for ingestion, enrichment, deduplication, scoring, validation, and dissemination of indicators of compromise (IOCs).
- Integrate commercial, open-source, industry, internal, and government intelligence sources into the TIP and related security platforms.
- Automate delivery of intelligence to security controls, including SIEM, EDR, email security, network security, and detection engineering platforms.
Threat Intelligence Platform Engineering
- Serve as a primary technical owner of the Threat Intelligence Platform, responsible for automation development, data quality, platform integrations, workflow design, and capability maturation.
- Identify opportunities to improve platform performance, scalability, and user experience.
Vulnerability Intelligence Automation
- Develop automation pipelines that collect, normalize, enrich, and correlate vulnerability intelligence from sources including NVD, CISA KEV, vendor advisories, ISACs, security research, and internal telemetry.
- Build workflows that correlate vulnerabilities with threat actor activity, exploit availability, malware campaigns, and enterprise technology exposure.
Security Operations Integration
- Partner with Incident Response, Detection Engineering, Threat Hunting, Vulnerability Management, and Security Operations teams to automate intelligence-driven workflows.
- Develop integrations that improve information sharing, operational collaboration, and workflow efficiency across security teams.
- Translate intelligence requirements and analyst use cases into scalable automation and engineering solutions.
Collections and Data Engineering
- Develop and maintain data ingestion, normalization, transformation, and enrichment processes that support intelligence operations.
- Serve as a technical leader for intelligence collections engineering and data integration initiatives.
Innovation and Continuous Improvement
- Identify opportunities to eliminate manual processes and improve efficiency through automation and orchestration.
- Evaluate and implement emerging technologies, including AI-enabled capabilities, that enhance intelligence collection, enrichment, analysis, and operational effectiveness.
- Establish metrics and reporting to measure automation effectiveness, analyst efficiency gains, intelligence delivery speed, and operational outcomes.
Qualifications
- Minimum of three years of cybersecurity experience with at least one year focused on security engineering, automation, DevSecOps, software development, or related technical disciplines.
- Strong proficiency in Python and experience developing and maintaining automation workflows and APIs.
- Experience integrating systems using REST APIs, webhooks, and modern data exchange methodologies.
- Experience working with structured and unstructured security data, including JSON, XML, CSV, and related formats.
- Experience with threat intelligence concepts, methodologies, and operational workflows
- Experience implementing or supporting Threat Intelligence Platforms (TIPs) and intelligence standards such as STIX, TA
By providing your phone number, you consent to: (1) receive automated text messages and calls from the Judge Group, Inc. and its affiliates (collectively "Judge") to such phone number regarding job opportunities, your job application, and for other related purposes. Message & data rates apply and message frequency may vary. Consistent with Judge's Privacy Policy, information obtained from your consent will not be shared with third parties for marketing/promotional purposes. Reply STOP to opt out of receiving telephone calls and text messages from Judge and HELP for help.
Contact: This job and many more are available through The Judge Group. Please apply with us today!