Unknown Company

AI Automation & Security Engineer

new york, ny • Posted 4 days ago
Onsite Full Time IT & Technology

Builds and operates a system that scans GitHub/Artifactory repos for vulnerabilities and EOL libraries, then uses AI-driven automation to remediate findings — cutting manual triage and patch time firm-wide.

Core Technical Skills

  • Programming: Strong Python (scanners, orchestration, API integration); basic Bash for CI/CD glue
  • Source & Artifact Systems: GitHub (Actions, Advanced Security, PR workflows) and JFrog Artifactory/Xray; ability to scale across multi-repo, multi-language codebases
  • Scanning Tools: Hands-on with Snyk, Xray, CodeQL / Dependabot, Trivy, or Semgrep; understanding of CVE/CVSS scoring and EOL-detection sources (e.g., endoflife.date)
  • AI-Driven Remediation: Building agentic workflows (LLM-based) that interpret findings, generate patch PRs, run tests, and summarize fixes; prompt engineering for code-editing agents
  • CI/CD & Orchestration: Integrating scan-and-fix pipelines into GitHub Actions/Jenkins; Docker for isolated fix-testing; scheduling via Airflow/cron
  • Reporting: Structuring findings (JSON/SQL) into dashboards for tracking coverage and trends

Supporting Skills

  • Security fundamentals (injection, auth flaws, supply-chain/SBOM risk)
  • Risk-based prioritization beyond raw CVSS scores
  • Semantic versioning awareness for safe auto-upgrades

Communication Skills

  • Translating vulnerability data into concise, risk-framed leadership updates (exposure counts, MTTR, fix-rate trends)
  • Writing clear status emails on scan coverage and outstanding critical items
  • Building the business case (time saved, risk reduced) for non-technical stakeholders
  • Tracking emerging agentic/AI remediation tools and evaluating fit before firm-wide adoption

#J-18808-Ljbffr
Back to Job Search