Primary Responsibilities
· Author, test, and maintain automation scripts/workflows within SOAR platform
· Design, implement, and maintain efficient and reusable Python code
· Review, debug, and resolve technical issues throughout all stages of SDLC
· Integrate SOAR platform with other security tools and APIs to execute automated workflows
· Coordinate with System Administrators, Engineers, and ISSOs to provision service accounts and/or grant required permissions
· Assist with process development and process improvement for Security Operations to include creation/modification of SOPs, Playbooks, and Work instructions
· Measure effectiveness of process improvement and automation efforts via metrics and KPIs
· Have expert proficiency with Python
· Working knowledge of SOAP/REST APIs, JSON, HTML/CSS, Javascript, XML
· Experience with SOAR platforms such as Swimlane, Phantom, Demisto, etc
· Experience as a SOC Analyst and/or Incident Responder
· Authored SOC SOPs, playbooks, work instructions and/or other process documents
· Familiarity with Splunk Search Processing Language (SPL) and/or Elastic Domain Specific Language (DSL)
· General networking knowledge to include operation of routers, firewalls, DNS, DHCP, subnetting, VPN and Web Proxies
Required Education/Experience
BS degree in Science, Technology, Engineering, Math or related field and 3 years of prior relevant experience
Preferred Qualifications
Should have 2 years of experience serving as a SOC Analyst or Incident Responder
Freqently Asked Questions
Expertise in Python frameworks like Flask or Django can boost automation capabilities, but familiarity with SOAR platforms such as Swimlane, Phantom, or Demisto is crucial. These tools streamline security operations, enabling efficient integration and workflow automation tailored for security environments common in Leesburg, VA.
This role uniquely blends Python programming with security automation, meaning your day often shifts between writing reusable automation scripts and collaborating on incident response processes. Expect to debug technical issues while enhancing security operations, making it a dynamic position requiring both coding and analytical skills.
Professionals can progress into senior automation engineer roles, security architect positions, or management of SOC teams. Deepening expertise in Python alongside SOAR tools and incident response strategies opens doors to leadership in cybersecurity automation within Leesburg’s growing tech sector.
While a BS degree is required, certifications like Certified SOC Analyst (CSA), GIAC Python Coder (GPYC), or certifications in SOAR platforms can greatly enhance candidacy. Local employers like Base-One Inc value these credentials to ensure proficiency in both Python automation and cybersecurity operations.
Leesburg’s proximity to Washington D.C. fuels demand for security-focused Python developers, especially those skilled in automation for SOC environments. Candidates often face moderate competition but benefit from numerous government and private sector contracts emphasizing cybersecurity innovations.
Base-One Inc emphasizes integrating SOAR platforms with other security tools, requiring Python Developers/Automation Engineers to customize solutions that enhance incident response workflows. Their approach values collaboration with system administrators and security teams to align automation with stringent security protocols.
Base-One Inc offers exposure to cutting-edge security automation projects and encourages skill development in Python scripting and SOAR platform mastery. This environment fosters professional growth by blending practical incident response knowledge with advanced automation techniques.
In Leesburg, VA, Python Developers with automation and security experience typically earn between $95,000 and $120,000 annually. Factors like SOAR platform expertise and incident response background can push compensation towards the higher end, reflecting the specialized skills demanded locally.
Networking fundamentals are vital since automation engineers often interact with firewalls, VPNs, and proxies. Understanding routing, subnetting, and DNS enhances the ability to design workflows that accurately reflect real-world network security conditions prevalent in Leesburg’s cybersecurity roles.
Challenges include ensuring seamless integration of SOAR platforms with diverse security tools and navigating complex permissions with ISSOs and system admins. Additionally, adapting automation scripts to evolving cyber threats requires constant process refinement to maintain operational effectiveness.
Find The Related Jobs
Capitol Communicator
Full Stack Developer
Herndon, VA
Capitol Communicator
Full Stack Developer
Oakton, VA
Capitol Communicator
Full Stack Developer
Great Falls, VA
Capitol Communicator
Full Stack Developer
Dunn Loring, VA
Capitol Communicator
Full Stack Developer
Arlington, VA
Capitol Communicator
Full Stack Developer
Chantilly, VA