Our team members are the key to our company's success, and their health and well-being, as well as that of their families, is very important to us. We offer a comprehensive benefits package that allows our team members stay healthy, plan for their future and maintain a healthy work-life balance. Benefits may vary with employment status. To see our fill list of Team Member Benefits please visit our career site: www.gotoworkhappy.com/benefits
Job Description:
At Seminole Hard Rock Support Services, we're on a mission to protect our guests, team members, and enterprise assets through world-class cybersecurity practices. As the Cybersecurity Automation Engineer, you will design, build, and continuously evolve the security automation and orchestration capabilities that underpin our enterprise cyber defense strategy, enabling faster threat response, streamlined identity operations, and intelligent, repeatable security workflows at scale.
Reporting to the Manager of IAM & Automation, this role requires a highly technical, full-stack engineer and forward-thinking architect who can translate cybersecurity strategy into production-grade automation solutions. You will personally design and develop applications, integrations, and AI-driven tooling across the full technology stack, from front-end interfaces and APIs to back-end services, infrastructure, and cloud platforms, integrating capabilities across IAM, security operations, and compliance to reduce manual effort, accelerate incident response, and strengthen the overall security posture across all Seminole Hard Rock business units.
This is a hands-on engineering role. The ideal candidate writes and ships production code, architects scalable systems, owns their solutions end-to-end, and brings the discipline of a software engineer to the problems of enterprise cybersecurity.
Responsibilities
Architecture & Design
- Design and maintain the enterprise security automation architecture, ensuring alignment with the broader cybersecurity strategy, zero-trust principles, and business objectives
- Evaluate, select, and integrate security automation platforms and tooling into a cohesive, scalable ecosystem, spanning hyperautomation/SOAR, SIEM and security analytics, telemetry pipelines, and cross-platform integrations with the broader security tool portfolio
- Define automation design patterns, standards, and reusable frameworks that accelerate development and ensure consistency across security domains
- Design infrastructure architectures across Linux and Windows environments, leveraging IaaS and PaaS services to deliver resilient, scalable, and cost-effective automation platforms
- Maintain architecture documentation, integration maps, and decision records so the automation ecosystem is fully understood and transferable
Full-Stack Development & Engineering
- Develop production-quality security automation applications, tools, and integrations across the full stack, including front-end dashboards and portals, RESTful/GraphQL APIs, back-end services, and database layers
- Build and deploy AI and machine learning‑powered solutions using Python (or similar) to automate threat detection, anomaly identification, intelligent access decisions, and predictive security analytics
- Develop and optimize integrations between security tools, cloud platforms (Azure, AWS), ITSM systems, and IAM platforms using Python, PowerShell, REST APIs, and modern integration frameworks
- Design and manage infrastructure-as-code (Terraform, Ansible, Salt/SaltStack, ARM/Bicep) for automated deployment and configuration of security platforms across IaaS and PaaS environments
- Implement CI/CD pipelines for security automation codebases, ensuring rigorous testing, version control, and reliable deployments across development, staging, and production environments
- Apply software engineering best practices to all automation work: peer code review, unit and integration testing, branching strategies, release tagging, and inline documentation
Security Orchestration & Workflow Automation
- Design, develop, and maintain automated security workflows and orchestration playbooks for incident response, alert triage, threat enrichment, and remediation, moving beyond off-the-shelf playbooks to custom-engineered solutions
- Build event‑driven automation that responds in real time to signals from SIEM, EDR, IAM, and cloud platforms, reducing mean time to detect and respond across the security operations function
- Automate identity lifecycle workflows (joiner/mover/leaver) in close collaboration with the IAM team, including provisioning, de‑provisioning, access reviews, and certification campaigns
- Develop self‑service automation portals and tooling that enable cybersecurity team members to trigger, monitor, and audit automated workflows without engineering intervention
Infrastructure & Platform Engineering
- Architect and manage automation platform infrastructure spanning Linux and Windows server environments, containerized workloads (Docke