Python Developer/Automation Engineer
The U.S. Department of Homeland Security (DHS), Customs and Border Protection (CBP) Security Operations Center (SOC) is a U.S. Government program responsible for preventing, identifying, containing, and eradicating cyber threats to CBP networks through monitoring, intrusion detection, and protective security services to CBP information systems including local area networks/wide area networks (LAN/WAN), commercial Internet connection, public facing websites, wireless, mobile/cellular, cloud, security devices, servers, and workstations. The CBP SOC is responsible for the overall security of CBP Enterprise-wide information systems, and collects, investigates, and reports any suspected and confirmed security violations.
Leidos is seeking a Python Developer/Automation Engineer to join our team. As a member of this highly technical Operations Enhancement team supporting U.S. Customs and Border Protection (CBP), you will be responsible for developing, testing, and maintaining scripts/code used for automating workflows, processes, and tasks within the Security Orchestration, Automation, and Response (SOAR) platform in support of the CBP SOC.
Primary Responsibilities:
- Author, test, and maintain automation scripts/workflows within SOAR platform.
- Design, implement, and maintain efficient and reusable Python code.
- Review, debug, and resolve technical issues throughout all stages of SDLC.
- Integrate SOAR platform with other security tools and APIs to execute automated workflows.
- Coordinate with System Administrators, Engineers, and ISSOs to provision service accounts and/or grant required permissions.
- Assist with process development and process improvement for Security Operations to include creation/modification of SOPs, Playbooks, and Work instructions.
- Measure effectiveness of process improvement and automation efforts via metrics and KPIs.
- Must be a US Citizen.
Basic Qualifications:
- Bachelors' degree from an accredited college in a related discipline, or equivalent experience/combined education, with 8 to 12 years of professional experience; or 6 to 10 years of professional experience with a Masters' degree.
- Additional years of experience and certifications may be considered in lieu of a degree.
- Have expert proficiency with Python.
- Working knowledge of SOAP/REST APIs, JSON, HTML/CSS, Javascript, XML.
- Experience with SOAR platforms such as Swimlane, Phantom, Demisto, etc.
- Experience as a SOC Analyst and/or Incident Responder.
- Authored SOC SOPs, playbooks, work instructions, and/or other process documents.
- Familiarity with Splunk Search Processing Language (SPL) and/or Elastic Domain Specific Language (DSL).
- General networking knowledge to include operation of routers, firewalls, DNS, DHCP, subnetting, VPN, and Web Proxies.
Preferred Qualifications:
- Should have 2 years of experience serving as a SOC Analyst or Incident Responder.
Clearance:
- All Department of Homeland Security CBP SOC employees are required to favorably pass a 5-year (BI) Background Investigation.
Come break things (in a good way). Then build them smarter.
We're the tech company everyone calls when things get weird. We don't wear capes (they're a safety hazard), but we do solve high-stakes problems with code, caffeine, and a healthy disregard for "how it's always been done."