Tech Stack
AnsibleAWSAzureChefCloudCyber SecurityDockerElasticSearchKafkaKubernetesLinuxLogstashMongoDBPuppetPythonSOAPSplunkTerraform
About the role
- Develop custom plugins and 3rd party integrations for a commercial-off-the-shelf cybersecurity software product
- Design, develop, and implement data models, index structures, and storage strategies
- Build ingesting/indexing processes and transform/normalize data to common standards using log aggregation tools (e.g., Elasticsearch and Splunk)
- Enrich data upon ingest and querying
- Create queries against big data
- Collaborate with security teams to integrate third-party applications and APIs
Requirements
- Minimum 5 years of strong Python programming experience
- Experience in authoring and developing Python libraries
- Experience using REST and SOAP APIs to query and update data across multiple third-party applications
- Experience with Git, CI/CD and other development tools
- Experience with cloud infrastructure and networking in AWS and/or Azure
- Degree in a STEM related discipline and/or a minimum 5 years of cybersecurity experience
- Must be able to work from anywhere in the continental United States
- Nice to have:
- Experience with SOAR tools, Swimlane, Cyber Triage, Phantom
- Experience with the ELK (Elasticsearch, Logstash, Kibana) stack, Elastic Cloud on Kubernetes (ECK), Kafka, Beats, and/or Splunk
- Experience modeling with databases (relational/non-relational), especially MongoDB
- Configuration management experience with Ansible/Terraform/Chef/Puppet
- Experience with container services (Docker, Kubernetes, etc.)
- Linux administration experience
- Active (ISC)2 CISSP certification