Role: Security Architect-Consultant
Location: 100% Remote
Job Overview
We are seeking an experienced Security Architect-Consultant / Security Engineer to support the Division of Information Security. This role will focus on cybersecurity automation, security tool development, Identity and Access Management (IAM), Linux systems, enterprise security platforms, system integration, and security operations.
The successful candidate will work with security architects, engineers, SOC analysts, incident responders, and agency stakeholders to design, develop, deploy, integrate, troubleshoot, and continuously improve security tools and services supporting multiple state agencies.
Key Responsibilities
- Design, develop, deploy, administer, and support enterprise security automation and custom security tools.
- Develop Python-based automations, scripts, internal web applications, APIs, SDKs, dashboards, and command-line utilities.
- Build automated workflows for alert enrichment, incident triage, response, case management, notifications, escalation, containment, and reporting.
- Develop tools for CVE analysis, vulnerability enrichment, prioritization, tracking, and security decision support.
- Support enterprise security platforms including DSPM, ASM, IAM, Vulnerability Management, SIEM, XDR, SOAR, endpoint security, email security, logging, monitoring, cloud security, and threat intelligence.
- Integrate security technologies with ticketing, case management, notification, identity, data sources, APIs, and other enterprise systems.
- Develop and maintain automation using Python, PowerShell, Bash, REST APIs, JSON, YAML, and vendor SDKs.
- Support IAM activities including provisioning, deprovisioning, access reviews, RBAC, service accounts, API credentials, authentication, and authorization.
- Deploy, configure, patch, monitor, optimize, and troubleshoot Linux systems supporting security sensors, collectors, connectors, applications, containers, and data-processing services.
- Support Docker-based environments and security platform integrations.
- Troubleshoot complex application, platform, operating-system, network, identity, and integration issues.
- Monitor automation health, application availability, system performance, sensor status, API errors, integration failures, and vulnerability status.
- Maintain high availability, resilience, backup/recovery, secure configurations, patching, and controlled change processes.
- Provide technical escalation, knowledge transfer, documentation, runbooks, and operational handoffs to security teams.
Required Skills
- Strong hands-on Security Engineering experience across multiple cybersecurity technologies and enterprise environments.
- Strong Python development and security automation experience.
- Experience developing security scripts, integrations, utilities, workflows, and custom security tools.
- Strong troubleshooting experience across applications, security platforms, operating systems, networks, identity services, and integrations.
- Strong Linux administration experience, including deployment, configuration, patching, scripting, service management, monitoring, troubleshooting, and lifecycle management.
- Experience with Python, PowerShell, Bash, REST APIs, JSON, YAML, and vendor SDKs.
- Experience integrating enterprise technologies through APIs, SDKs, web services, authentication mechanisms, and structured data formats.
Preferred Skills
- Experience working as a Security Engineering Generalist in a large enterprise, multi-tenant, shared-services, or managed-services environment.
- Hands-on experience with Linux, Docker, security sensors, monitoring, scripting, and platform administration.
- Experience supporting SOC analysts, security engineers, incident responders, and enterprise customers.
- Experience with security technologies such as Palo Alto Networks, Proofpoint, Tenable, Cribl, and WhatsUp Gold.
- Experience creating security playbooks, runbooks, procedures, and technical documentation.
- Experience with IAM, DSPM, ASM, vulnerability management, email security, endpoint security, SIEM, SOAR, logging, monitoring, and cloud security.
- Strong understanding of enterprise security architecture, incident response, networking, access control, secure software development, systems administration, and cybersecurity frameworks.
- Experience with internal web applications, APIs, dashboards, databases, command-line tools, source control, testing, and software deployment.
Education & Experience
- Bachelor''s degree in Information Technology, Computer Science, Software Engineering, Information Security, or a related field.
- 8+ years of relevant professional experience; equivalent experience may substitute for education.
- At least 5 years of experience supporting large IT environments, security systems, software development, and/or system deployments.
Preferred Certifications
- CISSP
- CompTIA Security+
- GIAC
- Relevant cybersecurity certifications
- Linux, Python, Cloud, IAM, or other relevant security engineering/platform certifications.