4 days ago
Remote, United StatesSenior
Responsibilities
- Design, build, and operate reusable Python services, libraries, CLIs, and integrations for security and operational automation.
- Establish reliability, testing, observability, secrets-handling, access-control, and lifecycle standards for automation products.
- Automate identity and access reviews, cloud remediation, evidence collection, findings enrichment, exception management, and incident response orchestration.
- Own secure GitHub Actions patterns, including reusable workflows, OIDC-based cloud access, artifact controls, approvals, policy checks, scanning, and release gates.
- Design and maintain Terraform modules, guardrails, and policy-as-code controls for AWS environments.
- Automate secure AWS configuration and detection/remediation workflows using least privilege, change controls, dry runs, rollback approaches, and audit-ready logging.
- Develop governed internal AI automations and agent workflows with scoped tools, retrieval, validation, prompt-injection defenses, audit logs, evaluations, and human approvals.
- Translate security and operational needs into an automation roadmap, lead technical design reviews, mentor junior engineers, and guide cross-team technical direction.
Requirements
- Strong Python software engineering skills, including API integration, testing, packaging, error handling, and production troubleshooting.
- Hands-on expertise with GitHub and GitHub Actions, including reusable workflows, OIDC, permissions, secure secrets use, and CI/CD controls.
- Strong Terraform experience covering modules, state, plans, code review, testing, and policy or guardrail implementation.
- Deep practical understanding of AWS security and cloud architecture, including IAM, network boundaries, logging, encryption, and serverless or container services.
- Experience designing reliable, observable, least-privileged automation that is safe to roll out.
- Ability to lead design discussions, review code, and guide work across teams.
- Working knowledge of AI/LLM application risks and controls for safe agentic automation.
- Preferred experience with security orchestration, SIEM/SOAR, detection engineering, incident response, vulnerability-management automation, policy-as-code, cloud security tools, LLM APIs, agent frameworks, MCP, RAG, evaluation frameworks, enterprise AI platforms, Docker, Kubernetes, ECS, or EKS.
- Preferred certifications include AWS Security Specialty, AWS DevOps Engineer, CISSP, Security+, or a comparable certification.
Benefits
- Health insurance, retirement plans, and paid time off may be included as part of the compensation and benefits package.
- External candidates may be required to attend an in-person interview at a VERSANT Media location before a hiring decision.
