Security Architect – Consultant
Location: South Carolina / Fully Remote
Employment Type: Contract
Position Overview
The Division of Information Security is seeking a Security Architect – Consultant to support cybersecurity automation, security engineering, IAM, enterprise security platforms, and security operations.
The ideal candidate will have strong hands-on experience with security engineering, Python automation, Linux, system integration, IAM, and enterprise cybersecurity technologies.
Key Responsibilities
Security Automation & Development
-
Develop Python-based security automations, scripts, APIs, SDK integrations, dashboards, and command-line tools.
-
Build automated workflows for alert enrichment, incident response, triage, notifications, escalation, and reporting.
-
Develop tools for CVE analysis, vulnerability enrichment, prioritization, and tracking.
-
Integrate security platforms with APIs, ticketing systems, case management, identity services, and enterprise data sources.
Security Platforms & Operations
-
Support IAM, DSPM, ASM, vulnerability management, SIEM, XDR, SOAR, endpoint, email, network, and cloud security technologies.
-
Deploy, configure, patch, monitor, and troubleshoot Linux systems supporting security services.
-
Support Docker-based environments, security sensors, collectors, and data-processing services.
-
Monitor automation health, system performance, API errors, integration failures, and security platform issues.
Identity & Access Management
-
Support user provisioning and deprovisioning.
-
Manage access reviews, RBAC, service accounts, API credentials, authentication, and authorization.
-
Support identity-based integrations across enterprise systems.
Security Engineering & Support
-
Troubleshoot complex issues across applications, security platforms, operating systems, networks, and identity services.
-
Support SOC analysts, security engineers, incident responders, and agency customers.
-
Develop technical documentation, runbooks, procedures, and knowledge-transfer materials.
-
Support high availability, backup, recovery, patching, lifecycle management, and secure configuration.
-
Participate in a 24x7 SOC on-call rotation.
Required Qualifications
-
Broad hands-on security engineering experience supporting multiple cybersecurity technologies and operational functions.
-
5+ years of experience supporting large IT environments, security systems, software development, and/or system deployments.
-
Strong Python development and security automation experience.
-
Strong Linux administration, scripting, troubleshooting, and lifecycle management experience.
-
Experience with Python, PowerShell, Bash, REST APIs, JSON, YAML, and vendor SDKs.
-
Experience with enterprise security integrations and APIs.
-
Strong understanding of security architecture, incident response, networking, access control, and secure software development.
-
Strong troubleshooting and problem-solving skills.
-
Bachelor’s degree in IT, Computer Science, Software Engineering, Information Security, or related field, or equivalent experience.
-
8 years of relevant work experience may substitute for education.
Preferred Qualifications
-
Experience with IAM, DSPM, ASM, vulnerability management, SIEM, SOAR, XDR, endpoint security, email security, and cloud security.
-
Experience with Docker and security sensor platforms.
-
Experience supporting SOC and incident response teams.
-
Experience with Palo Alto Networks, Proofpoint, Tenable, Cribl, or WhatsUp Gold.
-
Advanced Python and full-stack development experience.
-
Experience developing internal web applications, APIs, dashboards, databases, and command-line tools.
-
Experience creating security playbooks, runbooks, and technical documentation.
-
CISSP, Security+, GIAC, or other relevant cybersecurity certification.