ID.meposted 2 months ago
$203,183 - $255,000/Yr
Full-time • Senior
McLean, VA

About the position

ID.me is seeking a Principal Security Automation Engineer to lead the development, integration, and optimization of security automation across our cloud and DevSecOps environments. This mastery-level role requires deep expertise in security engineering, scripting, tool integration, and DevSecOps best practices, with a secondary focus on incident response for cloud and web application security. As the highest-level security automation expert, you will design, build, and optimize automated security workflows, custom tooling, and security orchestration solutions to enhance ID.me’s ability to detect, respond to, and mitigate security threats efficiently. Your expertise in coding (Python, Go, Bash), API integration, and security automation platforms (SOAR, XDR, SIEM, cloud-native tools) will drive security innovation and operational efficiency. Beyond automation engineering, you will collaborate with SOC, Threat Intelligence, and DevOps teams to ensure that incident response playbooks, security tooling, and cloud security controls are seamlessly integrated into CI/CD pipelines and DevSecOps workflows.

Responsibilities

  • Develop, integrate, and optimize security automation workflows to enhance detection, response, and remediation efficiency.
  • Build custom security tools and scripts using Python, Go, Bash, and APIs to improve security operations.
  • Automate repetitive security tasks, including threat intelligence ingestion, alert triage, IOC enrichment, vulnerability management, and remediation tracking.
  • Integrate security tools into CI/CD pipelines, ensuring SAST, DAST, SCA, SBOM scanning, and infrastructure-as-code security are fully automated.
  • Develop custom detection rules and response automations for SOAR, XDR, SIEM (Chronicle, Splunk), and cloud-native security platforms.
  • Work closely with DevOps and Engineering teams to embed secure-by-design automation into application and infrastructure deployments.
  • Optimize IAM, secrets management, and API security automation, ensuring strong access controls and cloud security posture management.
  • Continuously evaluate and implement new security automation technologies to enhance scalability, efficiency, and real-time security response.
  • Support incident response teams by automating investigation, containment, and remediation workflows, reducing response times for cloud and web security incidents.
  • Contribute to post-incident reviews and root cause analysis (RCA), driving security automation improvements to prevent repeat incidents.
  • Provide forensic and security automation expertise during major cloud and web application security incidents, assisting SOC and IR teams in rapid mitigation.
  • Help refine incident response playbooks and adversary emulation techniques, ensuring automation is at the core of response strategies.
  • Drive security automation adoption across DevSecOps teams, ensuring security best practices are seamlessly integrated into software development.
  • Automate compliance and security controls to align with FedRAMP, SOC 2, ISO 27001, and NIST 800-53 frameworks.
  • Collaborate with Threat Intelligence and Security Operations teams to improve real-time detection and automated response to evolving adversary tactics.
  • Mentor and guide security engineers, SOC analysts, and DevOps teams, fostering a culture of security automation and continuous learning.

Requirements

  • 12+ years of experience in cybersecurity, with 7+ years focused on security automation, scripting, and tool integration.
  • Advanced programming skills in Python, Go, or Bash for automating security operations.
  • Extensive experience integrating security tools via APIs, webhooks, and cloud-native security services.
  • Hands-on expertise with SOAR, SIEM, XDR, and security telemetry platforms (e.g., Chronicle, Splunk, AWS Security Hub, GCP Security Command Center).
  • Strong background in DevSecOps methodologies, embedding security automation into CI/CD pipelines and cloud-native environments.
  • Experience with Infrastructure as Code (Terraform, CloudFormation) to enforce security best practices in cloud deployments.
  • Deep understanding of threat intelligence automation, IOC enrichment, and detection engineering.
  • Strong knowledge of cloud security in AWS, GCP, Kubernetes, and containerized environments, with experience automating security controls in serverless architectures.
  • Working knowledge of incident response methodologies and security frameworks (MITRE ATT&CK, NIST CSF, Cyber Kill Chain, OWASP Top 10).
  • Strong leadership, cross-functional collaboration, and technical communication skills, with the ability to drive security automation strategies at an enterprise level.

Nice-to-haves

  • Advanced certifications such as CISSP, GCP Professional Security Engineer, AWS Security Specialty, CKS (Certified Kubernetes Security Specialist), GCIH, GCFA, or OSCP.
  • Experience with machine learning and AI-driven security automation.
  • Familiarity with adversary emulation frameworks (Atomic Red Team, CALDERA, or MITRE ATT&CK Evaluations).
  • Prior experience in cloud-native security engineering, API security, and zero-trust architecture.

Benefits

  • Comprehensive medical, dental, vision, health savings account, flexible spending accounts (medical, limited purpose, dependent care, commuter benefit accounts).
  • Basic and voluntary life and AD&D insurance.
  • 401(k) with company match.
  • Parental leave.
  • Unlimited paid time off subject to the terms and conditions of the PTO policy, including 8 company wide holidays.
  • Short and long-term disability insurance.
  • Accident and critical illness insurance.
  • Referral bonus policy.
  • Employee assistance program.
  • Pet insurance.
  • Travel assistant program.
  • Wellbeing and childcare discounts.
  • Benefit advocates.
  • Learning and development benefit.

Job Keywords

Hard Skills
  • Bash
  • Go
  • Kubernetes
  • Python
  • Terraform
  • 34T7E oaY3
  • 4UY1tAkeQacy buCofjJxrY9
  • 58QehDIMw lAhZL5kemEq
  • 5RQ9cj1SvAnC 0oMve7i4ZV5
  • 6jhuJP3 nR2kXVobi
  • 8IXzlZewur7RFnJ3C ewFP2yCgD1Ivfb
  • 8r3YMZRG42 X7L8EglmSA6cBK
  • 9IWdl
  • b3F4TM Yphj97gaN
  • bEkHADzoi IqUYO8R03bk
  • BTorE60D1 JdGnS6t3e
  • cFZaGXtvs bnXxiQca7jR3
  • exAdluptK rU2B84w1WSvP
  • eyIF tF1MWeybXqu2 xt6IJ7p1g
  • FHyOdLTZGCwUIr e2MNo8RwU60
  • firKvGs xfA0OvRd7J9g
  • hGxn9EjmA Of2nVtRk h2vEt7JqZI
  • iBwLKcfS pR3EjfWHT0vg
  • ixSJ0gtkE sk98gyFH4
  • jhvpys0UH UgPXJWi86
  • jv3mkYB
  • KF83MGnDZ hML9OEa
  • MGpOYEe5v 4jtKfQO1Wxgn5
  • mLkRO VoAg
  • MYnQH8FND Pa9qeJW6pNA
  • NBeScgFP 2mwCWvN9D
  • nrbLfJyEC UXv8SCNzEPp V3RdcbieA
  • NxUrKQ
  • ohqRZK2Xs JbwHOKk9g
  • oqEyMRgX6 PxwK6aTCcHOm
  • OVxWq0leR TfqhAzgBrnt
  • pOThlLoG4 3YQzqOLRkS61
  • PQ9S5w R81Diem uF6HPZvpt0
  • pUA1y7 kYsxHo1rM
  • pyFDfIPhRuV5UcG DJR 2PRMr
  • qWKVG NOgSsciFBebIX
  • qXTaFP1t nxZqHCQuM
  • StcV2 NM4xRe wTmxqKrnz
  • ufnD14y9TwV EynZHYgxoRzdf IyHZtonlQTdK
  • UvemZ TXmC0EpBGIH
  • V26P vEkBi9OYc8o
  • V6Yynq TshHtUAQR
  • vNGP8n6ht K23url1pJFxU
  • VULfmcx U16vKyMhnO
  • Wkjn1pb bpQE5Wk
  • wzdi 1lPk0ybm
  • z0DxvLa5Z LtZfQG3sUVcD
  • z3xdJfQPs U2aCOYs53o0T
  • ZJlpt0cNKGW9 9dCWunPKk
Soft Skills
  • Rzh7bnZ3tD soxCJNkzQ
Build your resume with AI

A Smarter and Faster Way to Build Your Resume

Go to AI Resume Builder
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service