Automate Workflows: Build and maintain automated workflows for blue-team operations, from data ingestion and normalization to correlation, alerting, and reporting, using scripts, services, and containerized pipelines.
System Hardening: Codify and automate hardening guidelines and best practices across operating systems, applications, and cloud platforms, ensuring repeatable, auditable baselines.
Collaborate Across Teams: Partner with security, engineering, and IT to integrate data sources and APIs, automate evidence collection for investigations and control verification, and ensure secure-by-default configurations aligned with internal security standards.
WAF Management: Define, automate, and monitor WAF rules as code to protect applications against web attacks, including safe rollout, testing, and telemetry for performance and compliance.
Requirements
Strong desire to learn and demonstrate skill in at least one scripting language (Python, TypeScript, or similar) to build production-ready automations and integrations.
Analytical problem-solving skills and attention to detail for debugging, tuning alerts, and measuring coverage.
Effective communication and ability to work as part of a collaborative team.
Familiarity with EDR platforms (e.g, CrowdStrike, Defender ATP)
Basic understanding of SIEM concepts (log ingestion, parsing, alerting, dashboards, correlation rules) with pipeline reliability.