Security Automation Engineer / Vulnerability Management Engineer
Remote is allowed - prefer near Atlanta (EST timezone)
Job Summary
JIRA Proficiency, AWS Cloud Environment, AI-Driven Automation,
Data Sources (BigQuery & AWS Data Lake): Practical familiarity with pulling security data from Google BigQuery and Amazon Data Lakes for analytics.
NIST & MITRE ATT&CK Frameworks: Prior experience with NIST standards or the MITRE ATT&CK matrix is a valuable bonus for evaluating adversary threat intent and prioritizing vulnerabilities.
We are seeking a Security Automation Engineer with strong software engineering expertise to build and scale automated vulnerability management and security operations capabilities. This role combines security engineering, automation development, threat intelligence integration, and risk management to transform manual security workflows into intelligent, scalable solutions.
The ideal candidate will have experience building automation platforms, integrating security data sources, implementing risk-based prioritization, and developing remediation workflows that improve organizational security posture.
Key Responsibilities
Security Automation & Pipeline Engineering
- Design, develop, and maintain automated vulnerability ingestion and enrichment pipelines.
- Integrate data from multiple security platforms, asset inventories, endpoint security tools, attack surface management solutions, and threat intelligence sources.
- Build scalable data processing and normalization frameworks to support enterprise vulnerability management.
Risk-Based Prioritization
- Develop automated risk-scoring and defect prioritization mechanisms.
- Implement intelligent routing and workflow automation to reduce manual triage efforts.
- Apply exploitability and threat intelligence signals to improve remediation prioritization.
Threat Intelligence Integration
- Incorporate indicators such as EPSS, CVSS, and CISA KEV into risk assessment workflows.
- Collaborate with security teams to operationalize threat intelligence within remediation and ticketing systems.
- Maintain risk tracking and residual risk reporting processes.
Automated Remediation
- Develop automated remediation workflows and security orchestration capabilities.
- Support AI-assisted remediation initiatives, including automated code recommendations and pull request generation.
- Implement policy guardrails and governance controls to ensure secure deployment practices.
Security Defect Management
- Enforce security defect lifecycle standards through automation.
- Ensure automated tickets include accurate severity, prioritization, ownership attribution, and remediation requirements.
- Improve workflow efficiency by reducing manual review and operational overhead.
Analytics & Continuous Improvement
- Analyze vulnerability trends and security policy violations.
- Develop preventive controls and automation strategies to reduce recurring security defects.
- Create reporting and metrics that support risk reduction initiatives.
Required Qualifications
Software Engineering
- Strong proficiency in Python, Go, or comparable programming languages.
- Experience developing REST API integrations, automation services, and data processing solutions.
- Strong background in software development, scripting, and workflow automation.
Cybersecurity Expertise
- Experience with Vulnerability Management and Security Defect Management programs.
- Understanding of Attack Surface Management (ASM) and Cloud Security Posture Management (CSPM).
- Knowledge of enterprise security operations and security engineering practices.
Risk & Threat Intelligence
- Experience applying CVSS, EPSS, CISA KEV, and related exploitability frameworks.
- Ability to programmatically correlate threat intelligence with asset and vulnerability data.
- Understanding of risk-based remediation and prioritization methodologies.
Data Engineering & Automation
- Experience aggregating and normalizing data from multiple security platforms.
- Ability to build scalable risk models and data correlation frameworks.
- Strong analytical and problem-solving skills.
Preferred Attributes
- Builder mindset with a passion for automation and operational excellence.
- Experience modernizing manual workflows through engineering solutions.
- Strong collaboration and communication skills.
Education
- Bachelor's degree in Computer Science, Cybersecurity, Software Engineering, Information Systems, or related field.
- Equivalent practical experience in security automation, security engineering, or software development will also be considered.