Systems Engineer- Security

Expert Technology Services

  • Malvern, PA
  • 6 days ago

    Highlights

    Develop pipelines to collect, normalize, enrich, and correlate vulnerability intelligence from multiple sources (e.g., NVD, CISA, vendor advisories). - Build integrations between Threat Intelligence Platforms (TIP), SOAR, SIEM, cloud environments, and security tools.

    Numbers & Facts

    LocationMalvern, PA

    Description

    Job Summary (List Format):

    - Develop and Maintain Threat Intelligence Automation:
    - Design and implement automation workflows for intelligence collection, enrichment, analysis, dissemination, and reporting.
    - Build integrations between Threat Intelligence Platforms (TIP), SOAR, SIEM, cloud environments, and security tools.

    - Threat Intelligence Platform Engineering:
    - Serve as a primary technical owner for TIP, ensuring performance, integration, automation, and data quality.
    - Identify and implement improvements for platform scalability and user experience.

    - Vulnerability Intelligence Automation:
    - Develop pipelines to collect, normalize, enrich, and correlate vulnerability intelligence from multiple sources (e.g., NVD, CISA, vendor advisories).
    - Build workflows that link vulnerabilities to threat actor activity and technology exposure.

    - Security Operations Integration:
    - Collaborate with Incident Response, Detection Engineering, Threat Hunting, and Vulnerability Management teams.
    - Automate intelligence-driven workflows and improve operational collaboration and information sharing.

    - Collections and Data Engineering:
    - Develop and maintain data ingestion, normalization, transformation, and enrichment processes.
    - Lead intelligence collections engineering and data integration initiatives.

    - Innovation and Continuous Improvement:
    - Identify and implement opportunities to automate manual processes and enhance efficiency.
    - Evaluate and adopt emerging technologies, including AI-enabled solutions.
    - Establish metrics to measure automation effectiveness and operational outcomes.

    - Technical Requirements:
    - Minimum 3 years of cybersecurity experience, with at least 1 year in security engineering, automation, DevSecOps, or software development.
    - Strong proficiency in Python and developing automation workflows/APIs.
    - Experience integrating systems via REST APIs, webhooks, and handling structured/unstructured data (JSON, XML, CSV).
    - Familiarity with threat intelligence concepts, methodologies, and platforms (TIPs), and standards such as STIX and TAXII.

    ---

    Let me know if you want a more concise or tailored summary!

    Similar Jobs

    See more jobs