Apply Edge Start your job search

Security Automation Lead

Shain Associates · New York City Metropolitan Area

Apply & track with Apply Edge

Lead the design and operation of a single, auditable security automation pipeline where security controls are authored, reviewed, validated, and deployedBuild drift reconciliation and validation engines that detect and remediate divergence across endpoint, identity, cloud, and vulnerability management domainsReplace manual console operations with version-controlled, auditable automation built on infrastructure-as-code and configuration management platformsImplement and scale infrastructure-as-code deployment patterns and reusable automation components that accelerate delivery of security controls across teamsBuild and maintain continuous integration and continuous deployment pipelines with automated linting, policy-as-code checks, pre-deployment validation gates, and promotion workflowsDesign observability and monitoring pipelines that surface drift, control failures, and deployment health across environments and enable rapid incident detection and responseInstrument container and Kubernetes security workflows, including image scanning, admission control, runtime policy enforcement, and namespace isolation, to harden cloud-native workloadsRun the team's sprint cycle with a single backlog, two-week cadence, clear Definition of Done, controlled intake of unplanned work, and disciplined capacity planningIntegrate automation with existing security and infrastructure tooling while driving the transition from contractor-delivered manual work to engineering-owned automationDefine, track, and report operational metrics such as toil reduction, bypass rate, change failure rate, drift detection and remediation time, and sprint predictability, using those metrics to drive continuous improvement and postmortemsWhat’s requiredDemonstrated experience building and operating security automation pipelines in production environments, including continuous integration and continuous deployment systems, infrastructure-as-code, configuration management, and scripting in PowerShell, Python, or BashHands-on experience using Terraform, CloudFormation, or Pulumi for infrastructure provisioning and policy enforcement at scaleProven experience building and operating CI/CD pipelines in GitHub Actions, GitLab CI, Jenkins, or equivalent, including branching strategies, automated testing, and promotion workflowsWorking knowledge of container orchestration platforms, including Kubernetes cluster operations, Helm chart management, image lifecycle, and admission controller integrationExperience designing and operating observability stacks using tools such as Prometheus, Grafana, Datadog, or Splunk for infrastructure and security telemetry, alerting, and dashboardingFamiliarity with policy-as-code frameworks such as Open Policy Agent—including Rego—Sentinel, or Cedar for automated compliance and guardrail enforcementDirect people management experience with responsibility for hiring, coaching, development, and accountability to delivery commitmentsDemonstrated experience operating in sprint discipline with ownership of backlog prioritization, capacity planning, and Definition of Done enforcementWorking knowledge of enterprise security tooling across endpoint detection and response, mobile device management, identity providers, security information and event management, and vulnerability management platforms.Commitment to the highest ethical standards