Senior Automation Engineer

Imr Soft — United States · Posted ~2 hours ago

Senior Contract Hybrid

Skills

Python Bash GitHub Actions CI/CD security scanning vulnerability remediation AI automation LLM workflows GitHub JFrog Artifactory Snyk CodeQL LLMs

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A senior engineering role focused on building AI-driven automation systems for software security and delivery workflows. The position requires programming expertise, security tooling knowledge, and experience creating intelligent remediation pipelines.

Highlights

Work on AI-powered automation solutions that reduce security remediation effort and improve engineering efficiency.

Description

Position: Senior Automation Engineer Location: NYC, NY (3 days onsite is must) Duration: 12 Months Role Summary Builds and operates a system that scans GitHub/Artifactory repos for vulnerabilities and EOL libraries, then uses AI-driven automation to remediate findings — cutting manual triage and patch time firm-wide. Core Technical Skills Programming: Strong Python (scanners, orchestration, API integration); basic Bash for CI/CD glueSource & Artifact Systems: GitHub (Actions, Advanced Security, PR workflows) and JFrog Artifactory/Xray; ability to scale across multi-repo, multi-language codebasesScanning Tools: Hands-on with Snyk, Xray, CodeQL / Dependabot, Trivy, or Semgrep; understanding of CVE/CVSS scoring and EOL-detection sources (e.g., endoflife.date)AI-Driven Remediation: Building agentic workflows (LLM-based) that interpret findings, generate patch PRs, run tests, and summarize fixes; prompt engineering for code-editing agentsCI/CD & Orchestration: Integrating scan-and-fix pipelines into GitHub Actions/Jenkins; Docker for isolated fix-testing; scheduling via Airflow/cronReporting: Structuring findings (JSON/SQL) into dashboards for tracking coverage and trendsSupporting Skills Security fundamentals (injection, auth flaws, supply-chain/SBOM risk)Risk-based prioritization beyond raw CVSS scoresSemantic versioning awareness for safe auto-upgradesTesting discipline — regression validation before auto-mergeCommunication Skills Translating vulnerability data into concise, risk-framed leadership updates (exposure counts, MTTR, fix-rate trends)Writing clear status emails on scan coverage and outstanding critical itemsBuilding the business case (time saved, risk reduced) for non-technical stakeholdersContinuous Learning Tracking emerging agentic/AI remediation tools and evaluating fit before firm-wide adoption