The client is seeking a Senior Security Automation Engineer to help design, build, and scale an enterprise security automation platform that improves security control validation, evidence collection, compliance reporting, and integration with secure software development workflows. This role is intended for a hands-on engineer who can build production-quality automation using Python and TypeScript, work effectively with AWS-based infrastructure, understand application security requirements and controls, and use AI technologies daily to improve engineering speed, analysis quality, and automation maturity. The position will support Client Application Security organization by advancing automated, evidence-based security validation across enterprise applications and development pipelines, including AI components that support AI-enabled secure SDLC (AIDLC) capabilities.
Key Responsibilities
Design, develop, enhance, and maintain enterprise security automation capabilities that support security control validation, evidence collection, compliance decisions, and reporting across enterprise applications.
Build scalable automation services, validators, APIs, data processing logic, and integration components using Python and TypeScript.
Work with AWS services and cloud-native architecture patterns to support secure, resilient, and scalable automation workflows, including data ingestion, processing, storage, and integration with enterprise security data sources.
Analyze security requirements, OWASP ASVS controls, secure software development expectations, control objectives, and tool outputs to define practical automation criteria and validation logic.
Develop automation that helps identify missing security evidence, validate secure implementation patterns, support auditability, and improve confidence in application compliance posture.
Integrate security automation capabilities into secure software development workflows, including CI/CD pipelines, developer feedback loops, source code repositories, and enterprise engineering platforms such as Harness or similar tools.
Use AI tools and agentic technologies as part of daily engineering work to accelerate design, coding, analysis, testing, documentation, troubleshooting, and security validation research.
Design and build AI-enabled components, services, and workflow integrations that support AI-enabled secure SDLC (AIDLC) capabilities, including intelligent validation assistance, control mapping support, evidence analysis, and developer security feedback.
Collaborate with Application Security architects, control owners, DevSecOps engineers, cloud teams, platform teams, compliance stakeholders, and application teams to translate security intent into scalable automation.
Produce clear technical documentation, implementation guidance, test evidence, and operational runbooks that allow automation logic to be reviewed, maintained, and scaled across the enterprise.
Required Qualifications
7+ years of experience in software engineering, security engineering, DevSecOps, application security automation, or enterprise platform engineering.
7+ years of advanced Python development experience, including architecting and delivering enterprise-grade automation, backend services, API integrations, security tooling workflows, and scalable data processing solutions in complex production environments.
Hands-on TypeScript or JavaScript experience, especially for automation services, platform tooling, developer experience workflows, or frontend/backend integration work.
Working knowledge of AWS infrastructure and cloud-native services, with the ability to understand and support secure automation architectures deployed in AWS.
Strong understanding of application security concepts, including SAST, DAST, SCA, secrets scanning, secure coding, API security, vulnerability management, and secure SDLC practices.
Ability to understand security controls and translate high-level requirements into scalable automation solutions, measurable validation logic, auditable evidence collection, and repeatable control-testing
Experience integrating with enterprise systems, APIs, data sources, CI/CD platforms, source code repositories, dashboards, or security tools.
Familiarity with GitHub, GitHub Advanced Security, CodeQL, pull request workflows, and code scanning concepts.
Ability to use AI technologies fluently and responsibly in daily engineering work to improve productivity, quality, analysis, testing, and documentation.
Familiarity with modern AI technologies and practical experience using or building AI-assisted components, workflow automations, or engineering productivity capabilities that can support AI-enabled secure SDLC (AIDLC) use cases.
Strong communication skills with the ability to explain automation design, security logic, implementation assumptions, and limitations to technical and non-technical stakeholders.
Preferred Qualifications
Experience building or supporting compliance automation, control validation, evidence collection, policy-as-code, or audit-readiness platforms.
Experience with OWASP ASVS, NIST 800-53, OWASP Top 10, CWE, secure coding standards, or enterprise security control frameworks.
Experience with Harness, GitHub Actions, Jenkins, or similar CI/CD platforms, including security gate integration, pipeline validation, or developer workflow automation.
Experience developing custom CodeQL queries, security validators, or rule-based detection logic to identify secure or insecure code patterns.
Experience with AI-assisted software development, AI-enabled secure SDLC (AIDLC), AI component development, security agents, prompt engineering, semantic code analysis, or AI-supported compliance validation.
Experience integrating with security tools such as SAST, DAST, SCA, secret scanning, vulnerability management, cloud security, asset discovery, ITSM, SIEM, or enterprise data lake platforms.
Experience with AWS services commonly used for automation and data processing, such as Lambda, S3, IAM, Glue, DynamoDB, API Gateway, CloudWatch, Step Functions, or related services.
Experience designing resilient microservices, event-driven workflows, ETL-style pipelines, or modular automation frameworks.
Background in application security architecture, DevSecOps enablement, cloud security, secure software patterns, or developer platform engineering.
Experience working in aviation, transportation, financial services, healthcare, or another highly regulated enterprise environment.
Ideal Candidate Profile for Sourcing Suppliers
The strongest candidate is a software engineer or platform engineer with security experience, not a traditional security analyst. They should be capable of designing, building, and maintaining enterprise-scale automation systems using Python and modern cloud technologies.
Prioritize candidates who have built internal platforms, automation services, developer tooling, workflow orchestration systems, APIs, or cloud-native applications.
Look for demonstrated proficiency with Python, TypeScript/JavaScript, AWS, APIs, data pipelines, and distributed system integration.
Candidates should understand secure software development practices and be able to translate security requirements and controls into automated validation and enforcement capabilities.
Candidates must be comfortable leveraging AI technologies daily and should ideally have experience building AI-enabled components, agents, workflow automations, or developer productivity solutions.
Strong candidates will have experience integrating capabilities into GitHub, CI/CD pipelines, developer workflows, and engineering platforms such as Harness.
Experience with AI-enabled SDLC (AIDLC), GitHub Advanced Security, CodeQL, security automation, developer platforms, or large-scale enterprise engineering initiatives is high
EEO:
“Mindlance is an Equal Opportunity Employer and does not discriminate in employment on the basis of – Minority/Gender/Disability/Religion/LGBTQI/Age/Veterans.”