Corporate Security Automation Engineer
Job description
About the role
This position is centered around designing, implementing, and optimizing the company's corporate security infrastructure. You will be responsible for enhancing security controls, ensuring they align with business objectives, and driving automation initiatives to maintain a security posture. The role emphasizes improving security through automated solutions and self-service capabilities, supporting the company's growth and compliance needs. You will collaborate closely with various teams to develop scalable, secure, and efficient security processes that protect critical corporate data and systems. The ideal candidate will have a strong background in enterprise security, cloud environments, and automation tools, contributing to a secure, compliant, and resilient infrastructure.
Key facts
What you'll do
- Use Infrastructure as Code (IaC) tools such as Terraform to develop, maintain, and manage consistent, automated enterprise configurations, ensuring proper change management procedures are followed. You will automate the provisioning and configuration of security infrastructure, reducing manual effort and minimizing errors.
- Design and implement endpoint security measures, including vulnerability management, malware protection, and device compliance, aligned with industry standards and best practices. This includes automating security updates and patch management processes across endpoints.
- Secure corporate SaaS applications by configuring vendor security features or building custom automations to meet internal security standards and compliance requirements. You will work on integrating SaaS security controls into the broader security ecosystem.
- Develop and manage data protection controls, including Data Loss Prevention (DLP) tools, encryption strategies, and secure data handling procedures. You will automate data classification and monitoring processes to prevent data leaks and ensure sensitive information remains protected.
- Create secure methods for sharing data internally and externally, including automating secure file transfer processes, managing access controls, and ensuring compliance with data privacy policies.
- Collaborate with IT, Infrastructure, and Security teams to deploy security measures, maintain critical corporate systems for high availability, and ensure compliance with relevant standards. You will automation to streamline security operations, incident response, and system maintenance.
- Develop, test, and execute incident response plans and disaster recovery procedures, including conducting tabletop exercises to prepare for potential security incidents. You will automate aspects of incident detection and response to improve reaction times and accuracy.
- Monitor security infrastructure and automate alerts and reporting to facilitate proactive security management. You will analyze security logs and metrics to identify potential vulnerabilities or threats.
- Stay current with evolving security threats, industry standards, and automation technologies, recommending improvements and new tools to enhance the security posture.
- Document security processes, automation workflows, and configurations clearly for team knowledge sharing and compliance audits.
Requirements
- A minimum of 5 years of IT experience, with at least 3 years specifically in enterprise security within cloud environments. Experience should include managing security in scalable, cloud-based infrastructures.
- Proficiency with Infrastructure as Code (IaC) tools such as Terraform (preferred), Puppet, Chef, or Ansible. Hands-on experience in automating infrastructure deployment and configuration management is essential.
- Demonstrated ability to lead security projects and achieve measurable improvements through automation, utilizing scripting languages like Python, Go, or TypeScript. You should have a track record of developing automation scripts and tools to enhance security operations.
- Strong understanding of networking concepts, authentication standards, and security frameworks such as MITRE ATT&CK, NIST CSF, and CIS benchmarks. You will apply this knowledge to design secure architectures and controls.
- Hands-on experience with Zero Trust Network Access (ZTNA) solutions and Data Loss Prevention (DLP) tools, such as Netskope and Zscaler. Familiarity with configuring and managing these solutions is required.
- Ability to communicate complex technical concepts clearly and effectively to non-technical stakeholders, influencing decision-making and security policies.
- Experience working in a fast-paced environment, managing multiple projects simultaneously, and adapting to evolving security threats and technologies.
- Knowledge of cloud platforms, particularly AWS, and familiarity with container orchestration tools like Kubernetes, is highly beneficial.
- Familiarity with security compliance standards and the ability to implement controls that meet regulatory requirements.
Nice to have
- Experience with workflow automation tools such as n8n, which can be used to streamline security workflows and incident response processes.
- Knowledge of React Native and React, which can be advantageous for integrating security controls into mobile and web applications.
- Additional experience with scripting, automation, or security tools not listed but relevant to enterprise security automation efforts.
Skills & tools
- Terraform
- Puppet
- Chef
- Ansible
- Python
- Go
- TypeScript
- Netskope
- Zscaler
- n8n
- Node.js
- NestJS
- Kubernetes
- AWS
- React Native
Practical notes
This role offers a competitive base salary within the specified range, along with stock options and comprehensive health benefits starting from day one. The company provides a 401(k) plan with matching contributions to support long-term financial planning. The position is based in the United States and is fully remote, allowing flexibility in work hours and location. The company fosters a high-growth, inclusive, and mission-driven culture, emphasizing innovation and continuous improvement. The interview process typically includes an initial conversation with a Talent Partner, followed by technical assessments, team interviews, and discussions with senior leadership. The company encourages candidates to demonstrate their automation expertise, security knowledge, and ability to collaborate across teams to enhance security posture.