| Location | Pittsburgh, PA |
| Industry | Computer/IT Services |
| Salary | $100,000–$125,000 Per Year |
| Company Size | 100 to 499 employees |
Started in 2006 and headquartered in Connecticut, VLink is one of the fastest growing digital technology services and consulting companies. Since its inception, our innovative team members have been solving the most complex business, and IT challenges of our global clients.
Automation Pipeline Development & Maintenance:
Build, maintain, and enhance the runbook library for L1 and L2 vulnerability remediation - covering OS patching, base image updates, SSL/TLS configuration, infrastructure config changes, and middleware updates
Develop and maintain automation scripts for vulnerability intake, deduplication, and routing across scan sources including Archer, Tanium, Sysdig, SecurityCenter, and Imperva
Implement and maintain CI/CD pipeline integrations per architecture specifications - Jenkins and GitHub Actions specifically
Build and maintain automated PR generation pipelines for container base image updates and library version bumps across application mnemonics
Develop and maintain the automated RITM generation integration with ServiceNow - triggering, routing, and status tracking without manual intervention
Ensure automation pipeline health through proactive monitoring, alerting, and self-healing mechanisms
Implement policy-as-code rules using OPA/Conftest per framework specifications defined by the Solution Architect
Build automated policy enforcement and risk-based gating mechanisms within CI/CD pipelines
Develop and maintain automated vulnerability scanning integrations - SAST, DAST, SCA, container scanning, IaC scanning, and secrets detection
Build feedback loop mechanisms to flag and retest vulnerabilities prior to production deployment
Implement and maintain compliance automation rules and audit-ready evidence generation
Collaborate with AI/ML Engineers to build and maintain the AI triage engine integration - connecting vulnerability feeds to the LangChain-based routing and scoring layer
Build the deduplication layer that normalizes and cross-references vulnerability data across multiple scan sources
Implement automated vulnerability routing logic based on risk scores, asset criticality, and remediation pathway classification
Build and maintain AI co-pilot integrations for L3 simple fix PR generation - Python-based agent pipeline using LangChain and Azure OpenAI
Develop feedback loop mechanisms that feed closure data back into the triage model for continuous accuracy improvement
Build and maintain the unified SLA compliance dashboard in Archer - real-time vulnerability status, MTTR tracking, backlog burn-down by severity and mnemonic
Develop weekly automated SLA burn-down reports and monthly executive summaries per specifications defined by the Solution Architect
Build Jira-based tracking integrations unifying WS1 and WS2 reporting into a single view
Implement automated data pipelines that aggregate vulnerability status across Archer, ServiceNow, Jira, and scan sources into the reporting layer
Develop and maintain operational metrics dashboards - automation efficiency, runbook execution rates, PR generation throughput, AI triage accuracy
Identify opportunities to automate recurring manual tasks across all three execution crews and implement solutions
Monitor runbook execution performance and tune scripts to improve throughput and reduce failure rates
Contribute execution-level insights to the Solution Architect for continuous improvement of the automation framework
Document all automation scripts, runbooks, and integration patterns in Confluence - maintaining up-to-date operational guides for the GCC execution teams
Support knowledge transfer of automation frameworks to execution crew members as new capabilities are deployed
8+ years of hands-on experience in DevSecOps, automation engineering, or infrastructure automation
Strong Python scripting, Ansible and Terraform experience - daily operational use for automation scripts, API integrations, and data pipeline development
Hands-on Jenkins and GitHub Actions experience - pipeline build, maintenance, and troubleshooting, not just design-level familiarity
Experience building and maintaining CI/CD security integrations - at least two of SAST, DAST, SCA, container scanning, or IaC scanning tools in production environments
ServiceNow API integration experience - ITSM workflow automation, RITM creation, and status tracking via REST API
Docker and container operations experience - base image management, Dockerfile optimization, container security scanning
OPA/Conftest or equivalent policy-as-code implementation experience
Experience with GRC or vulnerability management platforms - Archer, Qualys, Tenable, or equivalent
Strong REST API development and integration experience - building automation pipelines that connect multiple enterprise systems
Jira administration and workflow automation experience
Strong communications (verbal and written) skills and solid technical writing experience
Strong attention to detail to spot discrepancies in transactions or customer information
Ansible
GitHub
Jenkins
Python
Benefits are offered to eligible professionals on their first day of employment to include:
Competitive compensation
Comprehensive insurance options
Matching contributions through the 401(k) plan and the share purchase plan
Paid time off for vacation, holidays, and sick time
Paid parental leave
Learning opportunities and tuition assistance
VLink is an equal opportunity employer committed to fostering an inclusive environment where diversity is celebrated. All qualified applicants will be considered for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status. Employment is contingent upon successful completion of a background check.
This job application process may use AI-powered tools to assist in screening and evaluating applications based on objective, job-related qualifications. AI is used solely to support the recruitment process and all final hiring decisions are made exclusively by our human recruitment team.
Applicant information will be handled in accordance with VLink's privacy policy.
Started in 2006, VLink has built a solid foundation of providing end-to-end project delivery services, IT services, and talent acquisition solutions to various clients of all sizes -from small, medium to large Fortune 500 companies. We have a stellar history of providing continuous and superior quality services to our customers. This is a testament to the quality of our employees, who are our greatest asset. We believe providing our employees with the tools, training, and processes will not only improve their skills but provide a high caliber of service to our clients. This employee-centric approach, coupled with our financial stability and retention policies and procedures, has resulted in an employee turnover rate well below industry averages. In addition, over the past twelve years, VLink has created a robust database of thousands of pre-screened candidates who may be actively seeking new opportunities. Presently, VLink has over 400+ employees working on-site at client sites in the United States, and in our offshore delivery centers in India and Indonesia.