Security Architect – Consultant
Indexed description
Job Title: Security Architect – Consultant (13810)
Location: Columbia, SC 29201 Fully Remote
Work Hours: Eastern Time, core hours approximately 8:30 AM–5:00 PM ET
Duration: 12 Months
Extension: Possible
Interview: 1 Round – Virtual; onsite option for local candidates
Position Summary: The Client is seeking a highly hands-on Security Architect / Security Engineer to support the Division of Information Security. This is primarily an engineering, automation, scripting, custom-tool development, systems-integration and operational-support role, not a governance-only architecture position.
The consultant will work with security automation architects, security architects, engineers, SOC analysts and incident responders to design, develop, integrate, deploy and continuously improve security tools and services supporting multiple State agencies.
The strongest candidate will have deep hands-on experience with Python development, security automation, APIs/SDKs, Linux engineering, IAM, security-platform integrations and troubleshooting.
Primary Responsibilities
- Design, develop, deploy, administer and support enterprise security automations and custom security tools.
- Develop Python-based automations, internal web applications, APIs, SDK integrations, scripts, dashboards and command-line utilities.
- Build automated workflows for alert enrichment, triage, incident response, case management, notification, containment, escalation and reporting.
- Develop tools supporting CVE vetting, vulnerability enrichment, prioritization, tracking and security decision support.
- Develop and maintain automations using Python, PowerShell, Bash, REST APIs, JSON, YAML and vendor SDKs.
- Integrate security technologies with ticketing, case-management, identity, notification and enterprise data systems.
- Support IAM functions including provisioning/deprovisioning, access reviews, RBAC, service accounts, API credentials, authentication and authorization.
- Deploy, configure, patch, monitor, optimize and troubleshoot Linux systems, security sensors, collectors, connectors, applications and Docker-based environments.
- Support DSPM, ASM, vulnerability management, email security, endpoint security, SIEM, XDR, SOAR, logging, monitoring, network security, cloud security and threat intelligence.
- Troubleshoot automation failures, API errors, system-performance problems, sensor issues, data-ingestion failures and platform integrations.
- Support high availability, backup/recovery, patching, lifecycle management, secure configuration and controlled change.
- Participate in technical escalations, knowledge transfer and operational handoffs with SOC and security-engineering teams.
Required Skills
- Bachelor’s degree in Information Technology, Computer Science, Software Engineering, Information Security or related field; 8+ years of relevant experience may substitute for education.
- 5+ years supporting large IT environments, security systems, software development and/or system deployments.
- Broad hands-on security engineering experience supporting multiple cybersecurity technologies, integrations and operational functions.
- Strong experience integrating enterprise technologies using APIs, SDKs, web services, structured data formats, authentication methods and vendor-supported interfaces.
- Strong troubleshooting experience across applications, security platforms, operating systems, networks, identity services and integrations.
- Hands-on Linux deployment, configuration, patching, scripting, service management, monitoring, troubleshooting and lifecycle management.
- Experience developing automation and response workflows using Python, PowerShell, Bash, REST APIs, JSON, YAML and vendor SDKs.
- Experience supporting IAM, DSPM, ASM, vulnerability management, email security, endpoint security, SIEM, SOAR, logging, monitoring and cloud security.
- Strong understanding of enterprise security architecture, incident response, networking, access control, secure software development, systems administration and cybersecurity frameworks.
Preferred Skills
- CISSP, Security+, GIAC or another relevant cybersecurity certification.
- Linux, Python, Cloud, IAM or other relevant security-engineering/platform certification.
- Hands-on security-engineering generalist experience in a large, multi-tenant, shared-services or managed-services environment.
- Hands-on Linux, Docker, security sensor, monitoring, scripting and platform administration experience.
- Experience supporting SOC analysts, security engineers, incident responders and agency customers.
- Familiarity with Palo Alto Networks, Proofpoint, Tenable, Cribl, WhatsUp Gold (WUG) or similar enterprise security technologies.
- Experience developing playbooks, runbooks, procedures and technical documentation.
- Experience developing/supporting internal web applications, APIs, dashboards, databases and command-line tools.
- Advanced Python development experience, including familiarity with full-stack development, APIs, databases, source control, testing and software deployment.
- DNS security knowledge.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search