Security Architect
100% remote (EST Time zone)
12+ Months
Primary responsibilities:
Primarily assist in the planning, design, development, deployment, administration and operational support of enterprise security automations and custom security tools, including:
Python-based automations, internal web applications, APIs, SDKs, scripts, dashboards, command-line utilities and system integrations
Automated workflows for alert enrichment, triage, incident response, case management, notifications, containment, escalation and reporting
Custom tools to assist with CVE vetting, vulnerability enrichment, prioritization, tracking and security decision support
Required Skills
-- Broad hands-on security engineering experience supporting multiple cybersecurity technologies, systems, integrations and operational functions.
-- Experience developing security automations, scripts, integrations, utilities and custom tools using Python.
-- Strong experience troubleshooting complex technical issues across applications, security platforms, operating systems, networks, identity services and integrations.
-- Linux system deployment, configuration, patching, scripting, service management, monitoring, troubleshooting and lifecycle management
-- Experience developing automation and response workflows using Python, PowerShell, Bash, REST APIs, JSON, YAML and vendor SDKs.
-- Experience supporting IAM, DSPM, ASM, vulnerability management, email security, endpoint security, SIEM, SOAR, logging, monitoring, cloud security and other enterprise security technologies.
-- Strong understanding of enterprise security architecture, incident response, networking, access control, secure software development, systems administration and industry-standard cybersecurity frameworks.
Preferred Skills
-- Hands-on experience serving as a security engineering generalist in a large, multi-tenant, shared-services or managed-service environment.
-- Hands-on Linux, Docker, security sensor, monitoring, scripting and platform administration experience.
-- Experience supporting SOC analysts, security engineers, incident responders, agency customers and rapidly changing operational priorities.
-- Familiarity with Palo Alto Networks, Proofpoint, Tenable, Cribl, WUG or other enterprise security technologies and experience developing playbooks, runbooks, procedures and technical documentation