State of South Carolina-posted 24 days ago
Full-time • Mid Level
Onsite • Columbia, SC
Executive, Legislative, and Other General Government Support

The Department of Administration's (Admin) Division of Information Security (DIS) is seeking a Security Automation Architect to join the team. DIS is responsible for a variety of statewide policies, standards, programs and services related to cybersecurity and information systems, including the statewide coordination of critical infrastructure information. The Security Automation Architect works with other team members and agency contacts to design, develop, and maintain automated security workflows across the enterprise. This position blends development, scripting, and security engineering to streamline data collection, analysis, detection, and reporting functions within DIS. The role focuses on automating repetitive cybersecurity tasks and integrating an ever-expanding range of tools and data sources to improve visibility and response capabilities. Through scripting, APIs, and SIEM, SOAR and other platforms, this position will orchestrate the use of all available resources focusing efforts for the automation of multiple cybersecurity initiatives throughout the State of South Carolina. If you are a forward-thinking security leader with an actionable mind set and want to make a difference, join us in our effort to protect SC. This position is onsite in beautiful Columbia, South Carolina.

  • Design, develop, and maintain automated workflows within a broad list of security tools such as SIEM, SOAR, vulnerability management, identity and access management, XDR, etc. to streamline the State of South Carolina's awareness, detection, alerting and reporting capabilities.
  • Automate data ingestion, parsing and normalization from multiple sources including firewalls, endpoint systems, vulnerability scanners and identity providers.
  • Develop (Python, Bash scripts, etc.) to support data enrichment, report generation, log validation and automate recurring operational tasks.
  • Build and maintain API integrations between key cybersecurity platforms across a variety of cybersecurity technologies.
  • Create automations for vulnerability and patch management tasks, including ticket creation and replication across multiple ticketing systems and tracking for follow-up workflows.
  • Collaborate with security architects, security engineers, SOC, MSSP, customer agencies and external agency partners to identify manual tasks suitable for automation.
  • Document architecture, code, workflows, tools and dependencies for repeatable use across the organization and integrations into customer agencies.
  • Continuously evaluate tools, tasks, APIs, services, systems and processes to identify efficiency gains and reduce human error.
  • A bachelor's degree in computer science or a related field and five (5) years of experience in IT security, software development, or automation. Relevant experience may be substituted for the bachelor's degree on a year-for-year basis.
  • Candidate must successfully pass all initial and recurring security background checks as a condition of hire and continued employment.
  • Strong customer service and communication skills are a must.
  • Advanced proficiency with Python and Bash scripting for automation, data parsing, and API integrations.
  • Strong understanding of SIEM/SOAR platforms and automating use cases for them as well as manual use case development.
  • Understanding of the implementation of Identity and Access Management.
  • Experience with RESTful APIs, JSON, and data transformation pipelines.
  • Familiarity with database systems (MS-SQL, MYSQL or equivalent) and basic query design.
  • Experience with log collection, normalization, and enrichment workflows.
  • Knowledge of vulnerability management tools and automation of scan imports and reports.
  • Ability to automate report generation, compliance tracking and dashboard updates.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service