Primary Responsibilities
· Author, test, and maintain automation scripts/workflows within SOAR platform
· Design, implement, and maintain efficient and reusable Python code
· Review, debug, and resolve technical issues throughout all stages of SDLC
· Integrate SOAR platform with other security tools and APIs to execute automated workflows
· Coordinate with System Administrators, Engineers, and ISSOs to provision service accounts and/or grant required permissions
· Assist with process development and process improvement for Security Operations to include creation/modification of SOPs, Playbooks, and Work instructions
· Measure effectiveness of process improvement and automation efforts via metrics and KPIs
· Have expert proficiency with Python
· Working knowledge of SOAP/REST APIs, JSON, HTML/CSS, Javascript, XML
· Experience with SOAR platforms such as Swimlane, Phantom, Demisto, etc
· Experience as a SOC Analyst and/or Incident Responder
· Authored SOC SOPs, playbooks, work instructions and/or other process documents
· Familiarity with Splunk Search Processing Language (SPL) and/or Elastic Domain Specific Language (DSL)
· General networking knowledge to include operation of routers, firewalls, DNS, DHCP, subnetting, VPN and Web Proxies
Required Education/Experience
BS degree in Science, Technology, Engineering, Math or related field and 3 years of prior relevant experience
Preferred Qualifications
Should have 2 years of experience serving as a SOC Analyst or Incident Responder
Freqently Asked Questions
Proficiency in Python is essential, complemented by familiarity with REST and SOAP APIs, JSON, and SOAR platforms like Swimlane or Phantom. Knowledge of networking basics and incident response protocols also enhances your capability in automation and security orchestration roles.
Starting with core scripting and automation tasks, professionals often advance toward senior engineering roles focusing on complex workflow integrations and security operations. Gaining expertise in SOAR platforms and incident response can open leadership opportunities in cybersecurity automation.
Daily tasks include designing reusable Python scripts, debugging automation workflows, collaborating with security teams to integrate SOAR tools, and developing process improvements to boost operational efficiency within security environments.
Certifications like CompTIA Security+, Certified SOC Analyst (CSA), or Python programming credentials are valued locally. Given the cybersecurity focus, certifications in incident response or SOAR platform expertise enhance job prospects in Fairfax's competitive tech market.
Fairfax hosts a growing number of cybersecurity firms and government contractors, increasing demand for Python automation experts. The blend of Python skills and SOC experience makes candidates highly sought after due to regional emphasis on security operations.
At Base-One Inc, these engineers collaborate closely with SOC analysts and system admins, crafting automation workflows on SOAR platforms to streamline incident response. This synergy enhances threat detection and operational efficiency across their cybersecurity initiatives.
Base-One Inc emphasizes hands-on development within SOAR environments and encourages cross-functional teamwork with security operations teams. Their focus on process improvement and automation metrics provides engineers a dynamic platform for technical growth and impact.
Salaries in Fairfax typically range from $90,000 to $120,000 annually, reflecting the area's high cost of living and tech demand. This range aligns closely with national averages for similar roles, with bonuses often tied to cybersecurity project performance.
Absolutely. Entry-level Python developers with foundational scripting knowledge can expand into automation by learning SOAR platforms and security workflows. Gaining experience in incident response and API integrations accelerates this career progression effectively.
Complex integrations with various security tools and APIs can cause intermittent failures. Troubleshooting requires understanding of both scripting logic and security operations context, as well as coordinating with multiple teams to resolve permission or data flow issues.
Find The Related Jobs
Capitol Communicator
Full Stack Developer
Herndon, VA
Capitol Communicator
Full Stack Developer
Oakton, VA
Capitol Communicator
Full Stack Developer
Great Falls, VA
Capitol Communicator
Full Stack Developer
Dunn Loring, VA
Capitol Communicator
Full Stack Developer
Arlington, VA
Capitol Communicator
Full Stack Developer
Chantilly, VA