
Enterprise Cybersecurity AI Security Orchestration and Automation Engineer
- McLean, VA
- $69,400-158,000 per year
- Permanent
- Full-time
- Develop and maintain automation and orchestration pipelines in our security orchestration, automation, and response (SOAR) software.
- Analyze automation workflows and provide recommendations to improve the efficiency of the workflows using AI.
- Design and implement automation or AI-based solutions for manual processes.
- Apply consulting skills and AI expertise by simplifying technical requirements and trends.
- Grow your communication and technical skills by merging consulting and technology to create automated and efficient solutions.
- 4+ years of experience with cybersecurity engineering in network security, infrastructure security, applications or systems security, security operations, Security Information and Event Management (SIEM), incident response, or threat intelligence
- 4+ years of experience working with Python
- 3+ years of experience with major automation applications, including integrating tools, designing, writing playbooks, troubleshooting, training, or supporting technical requirements
- 3+ years of experience with SOAR tools such as Splunk SOAR, Swimlane, XSOAR, or Tines
- 3+ years of experience with data analysis
- 3+ years of experience working with Application Programming Interfaces (APIs) such as Palo, Versa, Splunk, and Elastic, and writing API integrations in Python
- Ability to produce new playbooks and automate manual security operation procedures per the backlog and requirements from security operations teams as new security tools and controls emerge in the marketplace
- Ability to help manage an inventory of integrations that enable broader playbook creation and develop connectors with tools to effectively enable end-to-end automation of security operations procedures
- Ability to be a self-starter and work independently and collaboratively in a team environment
- Bachelor’s degree in a Cybersecurity, Data Science, IT, or Mathematics field and 3+ years of experience in cybersecurity, IT, or data science in a professional environment, or 5+ years of experience in cybersecurity, IT, or data science in a professional environment in lieu of a degree
- Experience with threat intelligence tools such as ThreatQ, Analyst1, or ThreatConnect
- Experience with log management platforms, including Splunk or Elastic
- Experience with cybersecurity tools, including Splunk, Cisco ISE, Zscaler, Palo Alto, McAfee, Carbon Black, CrowdStrike, FireEye, vulnerability scanning tools, cloud security platforms, or ServiceNow
- Experience with ML frameworks such as TensorFlow, PyTorch, or scikit-learn
- Possession of strong analytical, problem-solving, and critical thinking skills
- Possession of strong written and verbal communication skills, including presenting complex information in a clear and concise manner
- Possession of strong detail-oriented skills
- Master’s degree in Cybersecurity, IT, Data Science, or a related field
Our people-first culture prioritizes the benefits of flexibility and collaboration, whether that happens in person or remotely.
- If this position is listed as remote or hybrid, you’ll periodically work from a Booz Allen or client site facility.
- If this position is listed as onsite, you’ll work with colleagues and clients in person, as needed for the specific role.