Primary Responsibilities
· Author, test, and maintain automation scripts/workflows within SOAR platform
· Design, implement, and maintain efficient and reusable Python code
· Review, debug, and resolve technical issues throughout all stages of SDLC
· Integrate SOAR platform with other security tools and APIs to execute automated workflows
· Coordinate with System Administrators, Engineers, and ISSOs to provision service accounts and/or grant required permissions
· Assist with process development and process improvement for Security Operations to include creation/modification of SOPs, Playbooks, and Work instructions
· Measure effectiveness of process improvement and automation efforts via metrics and KPIs
· Have expert proficiency with Python
· Working knowledge of SOAP/REST APIs, JSON, HTML/CSS, Javascript, XML
· Experience with SOAR platforms such as Swimlane, Phantom, Demisto, etc
· Experience as a SOC Analyst and/or Incident Responder
· Authored SOC SOPs, playbooks, work instructions and/or other process documents
· Familiarity with Splunk Search Processing Language (SPL) and/or Elastic Domain Specific Language (DSL)
· General networking knowledge to include operation of routers, firewalls, DNS, DHCP, subnetting, VPN and Web Proxies
Required Education/Experience
BS degree in Science, Technology, Engineering, Math or related field and 3 years of prior relevant experience
Preferred Qualifications
Should have 2 years of experience serving as a SOC Analyst or Incident Responder
Freqently Asked Questions
A Python Developer/Automation Engineer enhances security operations by scripting automation workflows within SOAR platforms like Swimlane or Phantom. They integrate APIs and automate incident response, significantly speeding up detection and remediation processes while reducing manual intervention.
Beyond core Python expertise, this role demands familiarity with SOAR tools, REST/SOAP APIs, security operations concepts, and networking fundamentals such as VPNs and firewalls, setting it apart from standard Python programming jobs focused solely on software development.
Working in Reston's cybersecurity hub offers exposure to evolving SOAR technologies and collaboration with security teams, which can open doors to advanced roles like SOC architect or cybersecurity automation lead, leveraging both Python skills and security operations knowledge.
Base-One Inc typically encourages continuous learning, offering access to cybersecurity certifications and hands-on experience with cutting-edge SOAR platforms. Their collaborative environment nurtures expertise in automation scripts, enhancing both technical and operational capabilities.
At Base-One Inc, there's a strong focus on integrating automation within security operations, requiring candidates to combine Python development with SOC analyst experience — a specialized blend not commonly emphasized in standard software engineering roles.
Reston’s thriving tech sector means Python automation positions are in high demand but competitive. Candidates with hands-on SOAR platform experience and security operations knowledge tend to have an advantage in securing roles at companies like Base-One Inc.
Reston’s traffic can be congested during peak hours, so it's advisable to consider flexible scheduling or remote work options when possible. Proximity to Metro stations also influences commute ease, which can impact daily work-life balance.
The average compensation for this hybrid role in Reston typically falls between $95,000 and $125,000 annually, depending on experience, SOAR expertise, and security background, aligning with regional standards for software engineers specializing in automation.
Integrating SOAR tools transforms daily work by shifting focus towards automating incident response workflows and collaborating closely with security teams, requiring strong scripting skills and a strategic mindset to enhance operational efficiency.
Candidates should have a STEM degree coupled with at least three years of relevant experience, preferably including two years as a SOC analyst or incident responder, along with proficiency in Python, API integration, and knowledge of security operations frameworks.
Find The Related Jobs
Capitol Communicator
Full Stack Developer
Herndon, VA
Capitol Communicator
Full Stack Developer
Oakton, VA
Capitol Communicator
Full Stack Developer
Great Falls, VA
Capitol Communicator
Full Stack Developer
Dunn Loring, VA
Capitol Communicator
Full Stack Developer
Arlington, VA
Capitol Communicator
Full Stack Developer
Chantilly, VA