Title: Senior Security Architect
Job Location: Columbia,
Position Type: W2 Contract
Work Mode: 100% Remote (however should travel on need basis)
Core Hours: 8:30 AM 5:00 PM ET
On-Call: Monthly rotation supporting a 24x7 SOC Position Overview
We are seeking an experienced Security Architect Consultant to support cybersecurity automation, security tool development, identity and access management, Linux systems, enterprise security platforms, and security operations. This is a highly hands-on security engineering role focused on the design, development, deployment, integration, troubleshooting, and continuous improvement of security tools, automations, systems, and services. The successful candidate will collaborate with security architects, engineers, SOC analysts, incident responders, and other stakeholders.
Primary Skills
- Broad hands-on security engineering experience across multiple cybersecurity technologies and operational functions
- Strong experience developing security automations, scripts, integrations, utilities, and custom tools using Python
- Strong troubleshooting experience across:
- Applications
- Security platforms
- Operating systems
- Networks
- Identity services
- Enterprise integrations
- Hands-on Linux system administration, including:
- Deployment
- Configuration
- Patching
- Scripting
- Service management
- Monitoring
- Troubleshooting
- Lifecycle management
- Experience developing automation and security response workflows using:
- Python
- PowerShell
- Bash
- REST APIs
- JSON
- YAML
- Vendor SDKs
Key Responsibilities
- Plan, design, develop, deploy, administer, and support enterprise security automations and custom security tools.
- Develop Python-based automations, internal web applications, APIs, SDKs, scripts, dashboards, command-line utilities, and system integrations.
- Build automated workflows for alert enrichment, triage, incident response, case management, notifications, containment, escalation, and reporting.
- Develop tools supporting CVE analysis, vulnerability enrichment, prioritization, tracking, and security decision support.
- Support security platforms including IAM, DSPM, ASM, vulnerability management, email security, endpoint security, SIEM, XDR, SOAR, logging, monitoring, network security, cloud security, and threat intelligence.
- Integrate security technologies with ticketing, case management, notification, identity, data sources, APIs, SDKs, and other enterprise systems.
- Support IAM functions including provisioning, deprovisioning, access reviews, RBAC, service accounts, API credentials, authentication, and authorization.
- Deploy, configure, patch, monitor, optimize, and troubleshoot Linux systems supporting security sensors, collectors, applications, containers, and data-processing services.
- Support Docker-based environments.
- Provide technical troubleshooting, automation development, system integration, escalation support, knowledge transfer, and operational handoffs.
- Monitor automation health, application availability, system performance, sensor status, integration failures, API errors, and security operational metrics.
- Ensure high availability, resilience, backup, recovery, patching, lifecycle management, secure configuration, and controlled change processes.
- Collaborate with security and business stakeholders to align solutions with organizational goals, regulatory requirements, security frameworks, and risk tolerance.
Preferred Skills
Additional Technical Skills Education
Preferred Certifications Work Arrangement
- Experience serving as a Security Engineering Generalist in a large, multi-tenant, shared-services, or managed-services environment
- Hands-on experience with Linux, Docker, security sensors, monitoring, scripting, and security platform administration
- Experience supporting SOC analysts, security engineers, incident responders, and enterprise customers
- Experience developing:
- Playbooks
- Runbooks
- Procedures
- Technical documentation
- Familiarity with enterprise security technologies such as:
- Palo Alto Networks
- Proofpoint
- Tenable
- Cribl
- WhatsUp Gold
- Experience supporting IAM, DSPM, ASM, vulnerability management, email security, endpoint security, SIEM, SOAR, logging, monitoring, cloud security, and related technologies
- Strong understanding of:
- Enterprise security architecture
- Incident response
- Networking
- Access control
- Secure software development
- Systems administration
- Cybersecurity frameworks
- Experience integrating enterprise technologies using APIs, SDKs, web services, structured data formats, authentication methods, and vendor-supported interfaces
- Experience developing or supporting internal web applications, APIs, dashboards, databases, command-line tools, and related software components
- Advanced Python development experience
- Familiarity with full-stack development, source control, testing, and software deployment practices
- Bachelor's degree in Information Technology, Computer Science, Software Engineering, Information Security, or a related field
- 8 years of relevant work experience may be substituted for education
- Minimum 5 years of experience supporting large IT environments, security systems, software development, and/or system deployments
- CISSP
- Security+
- GIAC
- Other relevant cybersecurity certifications
- Linux certifications
- Python certifications
- Cloud certifications
- IAM certifications
- Other relevant security engineering or platform certifications
100% Remote
- Work must be performed within the contiguous United States
- Core working hours are 8:30 AM 5:00 PM ET
- Monthly on-call rotation supporting a 24x7 SOC
- After-hours maintenance, incident escalation support, and operational handoffs may be required
- South Carolina-based candidates are preferred when they can provide in-state field support when needed
- VPN access is required/provided for the role
Security & Screening Requirements
Candidates must successfully complete the required pre-employment screening process, including applicable background, credit, driving-record, employment-verification, and security checks.
Annual CJIS certification is required for this position.
Ideal Candidate Profile
The ideal candidate is a hands-on security engineering professional with strong Python automation, Linux, enterprise security, IAM, API integration, and security operations experience.
The candidate should be comfortable working independently in a rapidly changing environment while collaborating with security architects, engineers, SOC analysts, incident responders, and other stakeholders to build secure, scalable, and operationally reliable solutions.