
Principal Security Automation Engineer
- California McLean, VA
- Permanent
- Full-time
- Develop, integrate, and optimize security automation workflows to enhance detection, response, and remediation efficiency.
- Build custom security tools and scripts using Python, Go, Bash, and APIs to improve security operations.
- Automate repetitive security tasks, including threat intelligence ingestion, alert triage, IOC enrichment, vulnerability management, and remediation tracking.
- Integrate security tools into CI/CD pipelines, ensuring SAST, DAST, SCA, SBOM scanning, and infrastructure-as-code security are fully automated.
- Develop custom detection rules and response automations for SOAR, XDR, SIEM (Chronicle, Splunk), and cloud-native security platforms.
- Work closely with DevOps and Engineering teams to embed secure-by-design automation into application and infrastructure deployments.
- Optimize IAM, secrets management, and API security automation, ensuring strong access controls and cloud security posture management.
- Continuously evaluate and implement new security automation technologies to enhance scalability, efficiency, and real-time security response.
- Support incident response teams by automating investigation, containment, and remediation workflows, reducing response times for cloud and web security incidents.
- Contribute to post-incident reviews and root cause analysis (RCA), driving security automation improvements to prevent repeat incidents.
- Provide forensic and security automation expertise during major cloud and web application security incidents, assisting SOC and IR teams in rapid mitigation.
- Help refine incident response playbooks and adversary emulation techniques, ensuring automation is at the core of response strategies.
- Drive security automation adoption across DevSecOps teams, ensuring security best practices are seamlessly integrated into software development.
- Automate compliance and security controls to align with FedRAMP, SOC 2, ISO 27001, and NIST 800-53 frameworks.
- Collaborate with Threat Intelligence and Security Operations teams to improve real-time detection and automated response to evolving adversary tactics.
- Mentor and guide security engineers, SOC analysts, and DevOps teams, fostering a culture of security automation and continuous learning.
- 12+ years of experience in cybersecurity, with 7+ years focused on security automation, scripting, and tool integration.
- Advanced programming skills in Python, Go, or Bash for automating security operations.
- Extensive experience integrating security tools via APIs, webhooks, and cloud-native security services.
- Hands-on expertise with SOAR, SIEM, XDR, and security telemetry platforms (e.g., Chronicle, Splunk, AWS Security Hub, GCP Security Command Center).
- Strong background in DevSecOps methodologies, embedding security automation into CI/CD pipelines and cloud-native environments.
- Experience with Infrastructure as Code (Terraform, CloudFormation) to enforce security best practices in cloud deployments.
- Deep understanding of threat intelligence automation, IOC enrichment, and detection engineering.
- Strong knowledge of cloud security in AWS, GCP, Kubernetes, and containerized environments, with experience automating security controls in serverless architectures.
- Working knowledge of incident response methodologies and security frameworks (MITRE ATT&CK, NIST CSF, Cyber Kill Chain, OWASP Top 10).
- Strong leadership, cross-functional collaboration, and technical communication skills, with the ability to drive security automation strategies at an enterprise level.
- Advanced certifications such as CISSP, GCP Professional Security Engineer, AWS Security Specialty, CKS (Certified Kubernetes Security Specialist), GCIH, GCFA, or OSCP.
- Experience with machine learning and AI-driven security automation.
- Familiarity with adversary emulation frameworks (Atomic Red Team, CALDERA, or MITRE ATT&CK Evaluations).
- Prior experience in cloud-native security engineering, API security, and zero-trust architecture.
- Is obsessed with security automation, continuously seeking new ways to eliminate manual processes and improve security efficiency.
- Can build and integrate custom security solutions, rather than just relying on vendor-provided tools.
- Enjoys working in fast-paced, high-impact security environments, where innovation is encouraged.
- Thinks strategically and operationally, balancing hands-on technical expertise with big-picture security leadership.
- Values mentorship and knowledge-sharing, helping upskill security teams and DevSecOps engineers.
- Stays ahead of emerging threats, technologies, and adversary tactics, constantly pushing security automation to the next level.