Security Automation & Detection Engineer
Apex Systems · Plano, TX · 1 wk ago
Information TechnologyContract
About the Role
One of your financial clients is seeking a Security Automation & Detection Engineer to support and enhance their third-party continuous monitoring and cybersecurity operations programs. This role will focus on integrating threat intelligence sources, automating security processes, improving data quality, and developing detections that strengthen the organization's visibility into cyber risks. The position is hybrid, requiring 3 days a week onsite in either Plano, TX or Malvern, PA.
Responsibilities
- Integrate and operationalize multiple threat intelligence sources within the client's continuous monitoring environment.
- Develop and implement security detections using threat intelligence, vulnerability management, and third-party risk data.
- Analyze, normalize, and transform security data to support ingestion into SIEM and security monitoring platforms.
- Design and develop automation solutions, proof-of-concept integrations, and reusable scripts using Python and APIs.
- Create and maintain technical documentation and integration patterns to support production implementation efforts.
- Automate workflows related to third-party and supplier security data management.
- Support data quality initiatives, including identifying and resolving incomplete or missing supplier security information.
- Partner with cybersecurity, vendor management, and risk stakeholders to improve monitoring capabilities and operational processes.
- Contribute to detection engineering, security automation, and other cybersecurity initiatives as priorities evolve.
Requirements
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent professional experience.
- Experience in security engineering, detection engineering, security operations, cybersecurity automation, or a related discipline.
- Strong proficiency in Python scripting and REST API integrations.
- Experience building automation solutions and streamlining operational workflows.
- Understanding of SIEM platforms and security data ingestion concepts.
- Ability to translate security use cases into actionable detections and automated processes.
- Strong analytical, troubleshooting, and problem-solving skills.
Preferred Qualifications
- Experience with vulnerability management, risk assessment, and remediation processes.
- Familiarity with threat intelligence platforms, intelligence feeds, and threat-driven security operations.
- Experience working within a Security Operations Center (SOC) environment.
- Knowledge of detection engineering, security orchestration, and incident response practices.
- Hands-on experience with SIEM technologies such as Splunk or Elastic.
- Experience with SOAR (Security Orchestration, Automation, and Response) platforms.
- Relevant cybersecurity certifications (Security+, CySA+, GCIH, GCIA, CISSP, or similar) are a plus.
Benefits
- Medical, dental, vision, life, and disability insurance plans.
- Employee Stock Purchase Program (ESPP).
- 401K program with company match after 12 months of tenure.
- Health Savings Account (HSA) on the HDHP plan.
- SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions.
- Corporate discount savings program and other discounts.
- On-demand training program and access to certification prep, technical and leadership courses/books/seminars after 6+ months of tenure.
- Certification discounts and perks for associations including CompTIA and IIBA.
- Dedicated customer service team for consultants and a certified Career Coach.