Secondarily assist in the planning, design, deployment and operational support of a broad range of security platforms, including: DSPM, ASM, IAM, vulnerability management, email security, endpoint security, SIEM, XDR, soar, logging, monitoring, network security, cloud security and threat intelligence technologies integrations with ticketing, case management, notification, identity, data sources, Apis, SDKS and other enterprise systems as needed support for technologies such as palo alto networks, Proofpoint, tenable, CRIBL, WHATSUP gold and other current or future security products
Develop, test, deploy and maintain automated security workflows, applications and scripts using python, POWERSHELL, BASH, REST Apis, JSON, YAML, vendor SDKS and other appropriate technologies.
Assist with identity and access management functions, including user provisioning, deprovisioning, access reviews, role-based access control, service accounts, API credentials, authentication, authorization and identity-based system integrations.
Deploy, configure, patch, monitor, optimize and troubleshoot Linux systems supporting security sensors, collectors, connectors, applications, containers and data-processing services, including docker-based environments.
Support security architects, engineers, soc analysts, incident responders and agency customers through platform troubleshooting, automation development, system integration, technical escalation, knowledge transfer and operational handoffs.
Monitor and report on automation health, application availability, system performance, sensor status, integration failures, api errors, vulnerability status, platform issues and other security engineering and operational metrics.
Ensure high availability, resilience, backup, recovery, patching, lifecycle management, secure configuration and controlled change processes for security tools, linux systems, applications, automations and supporting services.
Collaborate with security architects, engineers, analysts, incident responders and agency stakeholders to align solutions with business goals, industry-standard frameworks, regulatory requirements and organizational risk tolerance.
Familiarity with palo alto networks, Proofpoint, tenable, Cribl, WUG or other enterprise security technologies and experience developing playbooks, runbooks, procedures and technical documentation
Preferred certifications:
CISSP, security+, GIAC or other relevant cybersecurity certification
Linux, python, cloud, IAM or other relevant security engineering or platform certification
Additional skills/duties:
Experience integrating enterprise technologies using Apis, SDKS, web services, structured data formats, authentication methods and vendor-supported interfaces.
experience developing or supporting internal web applications, APIS, dashboards, databases, command-line tools and related software components.
Advanced python development experience and familiarity with full-stack development, internal web applications, APIS, databases, source control, testing and software deployment practices