Job Requirements
Washington, DC
Top Secret Polygraph not specified
Senior Level Career (10+ yrs experience)
Salary not specified
Join Premium to unlock estimated salaries
Job Description
We are seeking an Automation and Integration Engineer for an opportunity in Washington, DC.
Clearance: Active Top Secret (TS) Required
Level: Senior
Experience: 8+ years relevant experience, including 3+ years of hands-on automation, software development, systems integration, or DevSecOps experience
Position Summary
The Senior Cybersecurity Automation & Integration Engineer serves as a senior hands-on technical engineer responsible for designing, developing, integrating, deploying, and sustaining automation capabilities supporting cybersecurity and IT operations within a Federal Government environment.
The position combines cybersecurity engineering, software development, systems integration, workflow automation, and Artificial Intelligence (AI) to reduce manual effort, improve operational efficiency, accelerate response, and increase the reliability and consistency of cybersecurity processes.
This position is broader than traditional Security Orchestration, Automation, and Response (SOAR). The engineer is expected to evaluate operational requirements and determine the appropriate combination of custom development, APIs, workflow technologies, security platforms, cloud services, SOAR, and AI-enabled capabilities required to solve the problem.
The successful candidate must possess sufficient hands-on technical experience to independently deliver meaningful automation and integration capabilities within approximately 90–120 days of entering the environment.
Key Responsibilities
Identify manual, repetitive, error-prone, and inefficient cybersecurity and IT processes suitable for automation.
Analyze existing workflows and translate operational requirements into secure technical automation solutions.
Design and develop production-quality automation using Python, PowerShell, REST APIs, SDKs, webhooks, databases, and event-driven technologies.
Integrate cybersecurity and enterprise platforms including SIEM, EDR/XDR, vulnerability management, IAM, ITSM, asset management, cloud, threat intelligence, and compliance systems.
Automate processes supporting SOC operations, incident response, vulnerability management, identity management, continuous monitoring, compliance, reporting, and security engineering.
Develop automated collection, normalization, enrichment, correlation, analysis, and distribution of cybersecurity data.
Develop reusable automation frameworks, modules, libraries, services, APIs, and integration patterns rather than relying exclusively on standalone scripts.
Implement production engineering practices including logging, monitoring, exception handling, retries, timeouts, testing, auditability, configuration management, and failure recovery.
Apply secure engineering principles including least privilege, RBAC, service accounts, API security, credential/secrets management, authentication, authorization, and Zero Trust principles.
Maintain automation using Git-based source control, code review, testing, CI/CD, configuration management, and approved change-management processes.
Troubleshoot and sustain production automation and integrations.
Develop technical documentation, architecture diagrams, interface documentation, SOPs, and support procedures.
Provide technical leadership, architecture guidance, code reviews, and mentorship to other automation engineers.
AI & Intelligent Automation
The engineer will evaluate and leverage Government-approved AI/LLM technologies where they provide measurable operational value.
The engineer should understand and apply concepts including:
Generative AI and Large Language Models (LLMs)
AI/LLM APIs
Retrieval-Augmented Generation (RAG)
Structured model outputs
Prompt and context engineering
Embeddings and vector search
Tool/function calling
AI agents and agentic workflows
AI output validation
Human-in-the-loop controls
Potential applications include alert and incident summarization, vulnerability analysis, threat-intelligence analysis, knowledge retrieval, reporting, investigation assistance, security-data analysis, and analyst decision support.
The engineer must be able to determine when deterministic automation is preferable to AI, where AI provides meaningful value, and where human decision-making or approval must remain.
AI-enabled solutions must include appropriate security controls, validation, logging, auditing, and protection of classified, CUI, credentials, and other sensitive Government information.
Required Technical Qualifications
Active U.S. Government Top Secret (TS) security clearance.
8+ years of relevant cybersecurity, systems engineering, software development, automation, DevSecOps, or IT engineering experience.
3+ years of demonstrated hands-on automation, integration, or software development experience.
Strong Python proficiency developing maintainable automation, API integrations, and data-processing solutions.
Working proficiency with PowerShell, particularly within Windows/Microsoft enterprise environments.
Strong hands-on experience with REST APIs, JSON, SDKs, webhooks, authentication, OAuth/tokens, pagination, rate limits, retries, and error handling.
Experience integrating multiple cybersecurity and enterprise systems.
Hands-on proficiency with Git/source control, including branching, versioning, pull/merge requests, and code-review practices.
Experience processing and transforming structured data using JSON, CSV, regular expressions, SQL, and related technologies.
Working knowledge of Linux and Windows sufficient to deploy, schedule, troubleshoot, and support automated processes.
Understanding of API keys, OAuth 2.0, tokens, certificates, service accounts, RBAC, least privilege, and enterprise secrets management.
Demonstrated experience implementing production automation with logging, testing, monitoring, error handling, configuration management, auditability, and recovery mechanisms.
Hands-on experience automating or integrating multiple cybersecurity technologies such as Splunk/Sentinel, Tenable/ACAS, EDR/XDR, ServiceNow, Active Directory/Entra ID, IAM, cloud, or comparable platforms.
Working knowledge of secure software-development and DevSecOps practices.
Ability to independently take an automation requirement from analysis and architecture through development, testing, security review, deployment, documentation, monitoring, and sustainment.
Federal Cybersecurity Knowledge
Working knowledge of NIST RMF, NIST SP 800-53, continuous monitoring, vulnerability management, incident response, POA&M management, Zero Trust principles, and Federal security authorization processes is required.
Desired Qualifications
Experience with Splunk, Microsoft Sentinel, Microsoft Defender, CrowdStrike, Tenable/ACAS, ServiceNow, Active Directory, Entra ID, AWS/Azure, SOAR platforms, CI/CD, SQL/databases, containers, serverless computing, Infrastructure-as-Code, enterprise secrets management, AI/LLM APIs, RAG, vector databases, and agentic automation frameworks.
Relevant certifications may include CISSP, SecurityX, Security+, GIAC, Microsoft, AWS, Splunk, or comparable cybersecurity, cloud, development, automation, or AI certifications.
Core Performance Expectation
The Senior Cybersecurity Automation & Integration Engineer must be capable of independently:
Analyze Process → Identify Automation Opportunity → Design Solution → Integrate Systems/APIs → Develop → Test → Secure → Deploy → Monitor → Document → Sustain
The engineer is expected to proactively identify opportunities to automate and integrate cybersecurity operations rather than being limited to administration of a specific SOAR or security platform.
The objective is to have the engineer producing operationally useful automation and integrations within the first 90–120 days, with increasing responsibility for enterprise-level automation architecture, reusable capabilities, and technical leadership thereafter.
Clearance: Active Top Secret (TS) Required
Level: Senior
Experience: 8+ years relevant experience, including 3+ years of hands-on automation, software development, systems integration, or DevSecOps experience
Position Summary
The Senior Cybersecurity Automation & Integration Engineer serves as a senior hands-on technical engineer responsible for designing, developing, integrating, deploying, and sustaining automation capabilities supporting cybersecurity and IT operations within a Federal Government environment.
The position combines cybersecurity engineering, software development, systems integration, workflow automation, and Artificial Intelligence (AI) to reduce manual effort, improve operational efficiency, accelerate response, and increase the reliability and consistency of cybersecurity processes.
This position is broader than traditional Security Orchestration, Automation, and Response (SOAR). The engineer is expected to evaluate operational requirements and determine the appropriate combination of custom development, APIs, workflow technologies, security platforms, cloud services, SOAR, and AI-enabled capabilities required to solve the problem.
The successful candidate must possess sufficient hands-on technical experience to independently deliver meaningful automation and integration capabilities within approximately 90–120 days of entering the environment.
Key Responsibilities
Identify manual, repetitive, error-prone, and inefficient cybersecurity and IT processes suitable for automation.
Analyze existing workflows and translate operational requirements into secure technical automation solutions.
Design and develop production-quality automation using Python, PowerShell, REST APIs, SDKs, webhooks, databases, and event-driven technologies.
Integrate cybersecurity and enterprise platforms including SIEM, EDR/XDR, vulnerability management, IAM, ITSM, asset management, cloud, threat intelligence, and compliance systems.
Automate processes supporting SOC operations, incident response, vulnerability management, identity management, continuous monitoring, compliance, reporting, and security engineering.
Develop automated collection, normalization, enrichment, correlation, analysis, and distribution of cybersecurity data.
Develop reusable automation frameworks, modules, libraries, services, APIs, and integration patterns rather than relying exclusively on standalone scripts.
Implement production engineering practices including logging, monitoring, exception handling, retries, timeouts, testing, auditability, configuration management, and failure recovery.
Apply secure engineering principles including least privilege, RBAC, service accounts, API security, credential/secrets management, authentication, authorization, and Zero Trust principles.
Maintain automation using Git-based source control, code review, testing, CI/CD, configuration management, and approved change-management processes.
Troubleshoot and sustain production automation and integrations.
Develop technical documentation, architecture diagrams, interface documentation, SOPs, and support procedures.
Provide technical leadership, architecture guidance, code reviews, and mentorship to other automation engineers.
AI & Intelligent Automation
The engineer will evaluate and leverage Government-approved AI/LLM technologies where they provide measurable operational value.
The engineer should understand and apply concepts including:
Generative AI and Large Language Models (LLMs)
AI/LLM APIs
Retrieval-Augmented Generation (RAG)
Structured model outputs
Prompt and context engineering
Embeddings and vector search
Tool/function calling
AI agents and agentic workflows
AI output validation
Human-in-the-loop controls
Potential applications include alert and incident summarization, vulnerability analysis, threat-intelligence analysis, knowledge retrieval, reporting, investigation assistance, security-data analysis, and analyst decision support.
The engineer must be able to determine when deterministic automation is preferable to AI, where AI provides meaningful value, and where human decision-making or approval must remain.
AI-enabled solutions must include appropriate security controls, validation, logging, auditing, and protection of classified, CUI, credentials, and other sensitive Government information.
Required Technical Qualifications
Active U.S. Government Top Secret (TS) security clearance.
8+ years of relevant cybersecurity, systems engineering, software development, automation, DevSecOps, or IT engineering experience.
3+ years of demonstrated hands-on automation, integration, or software development experience.
Strong Python proficiency developing maintainable automation, API integrations, and data-processing solutions.
Working proficiency with PowerShell, particularly within Windows/Microsoft enterprise environments.
Strong hands-on experience with REST APIs, JSON, SDKs, webhooks, authentication, OAuth/tokens, pagination, rate limits, retries, and error handling.
Experience integrating multiple cybersecurity and enterprise systems.
Hands-on proficiency with Git/source control, including branching, versioning, pull/merge requests, and code-review practices.
Experience processing and transforming structured data using JSON, CSV, regular expressions, SQL, and related technologies.
Working knowledge of Linux and Windows sufficient to deploy, schedule, troubleshoot, and support automated processes.
Understanding of API keys, OAuth 2.0, tokens, certificates, service accounts, RBAC, least privilege, and enterprise secrets management.
Demonstrated experience implementing production automation with logging, testing, monitoring, error handling, configuration management, auditability, and recovery mechanisms.
Hands-on experience automating or integrating multiple cybersecurity technologies such as Splunk/Sentinel, Tenable/ACAS, EDR/XDR, ServiceNow, Active Directory/Entra ID, IAM, cloud, or comparable platforms.
Working knowledge of secure software-development and DevSecOps practices.
Ability to independently take an automation requirement from analysis and architecture through development, testing, security review, deployment, documentation, monitoring, and sustainment.
Federal Cybersecurity Knowledge
Working knowledge of NIST RMF, NIST SP 800-53, continuous monitoring, vulnerability management, incident response, POA&M management, Zero Trust principles, and Federal security authorization processes is required.
Desired Qualifications
Experience with Splunk, Microsoft Sentinel, Microsoft Defender, CrowdStrike, Tenable/ACAS, ServiceNow, Active Directory, Entra ID, AWS/Azure, SOAR platforms, CI/CD, SQL/databases, containers, serverless computing, Infrastructure-as-Code, enterprise secrets management, AI/LLM APIs, RAG, vector databases, and agentic automation frameworks.
Relevant certifications may include CISSP, SecurityX, Security+, GIAC, Microsoft, AWS, Splunk, or comparable cybersecurity, cloud, development, automation, or AI certifications.
Core Performance Expectation
The Senior Cybersecurity Automation & Integration Engineer must be capable of independently:
Analyze Process → Identify Automation Opportunity → Design Solution → Integrate Systems/APIs → Develop → Test → Secure → Deploy → Monitor → Document → Sustain
The engineer is expected to proactively identify opportunities to automate and integrate cybersecurity operations rather than being limited to administration of a specific SOAR or security platform.
The objective is to have the engineer producing operationally useful automation and integrations within the first 90–120 days, with increasing responsibility for enterprise-level automation architecture, reusable capabilities, and technical leadership thereafter.
group id: 10507395