Cyber Security Engineer - Automation
The Junior Automation Security Engineer builds and supports practical automations that make security controls easier to operate, validate, and scale. This is a hands-on engineering role for a curious builder who can write clean Python, work confidently in GitHub and GitHub Actions, and learn how Terraform and AWS services fit together. The engineer will use approved internal AI tools to accelerate research, prototyping, and documentation, while developing simple, secure agents and workflow automations under senior guidance.
What You Will Do
Security Automation & Python
- Build and maintain Python scripts, CLIs, API integrations, and scheduled jobs that reduce repetitive security and operational work.
- Automate evidence collection, configuration checks, alert enrichment, ticket creation, reporting, and basic remediation workflows.
- Write unit tests, logging, error handling, and concise documentation so automations are safe to operate and easy to support.
GitHub, CI/CD & Infrastructure as Code
- Contribute to repositories using pull requests, code review, branching, issue tracking, and dependency hygiene.
- Create and maintain GitHub Actions workflows for linting, testing, scanning, packaging, and controlled deployment tasks.
- Read, update, and test Terraform modules and plans with guidance; help identify insecure cloud configuration patterns before release.
AWS & Cloud Security Foundations
- Work with core AWS concepts including IAM, VPC, CloudTrail, CloudWatch, S3, Lambda, EC2, Secrets Manager, and AWS Organizations.
- Help automate cloud inventory, access reviews, configuration validation, tagging checks, and security findings triage.
- Follow least-privilege, secrets-management, logging, and change-control practices in all automation work.
AI-Assisted Engineering & Agents
- Use approved internal AI coding and productivity tools responsibly for code exploration, test generation, documentation, and prototyping.
- Practice AI-assisted or “vibe coding” in a disciplined way: validate generated code, protect confidential data, and submit reviewed changes.
- Help develop narrowly scoped internal agents that call approved tools, retrieve permitted knowledge, and keep a human approval step for impactful actions.
- Learn core AI security risks, including prompt injection, over-permissioned tools, data leakage, and unsafe agent behavior.
Collaboration
- Partner with security, platform, cloud, SOC, and engineering teams to turn recurring problems into reliable automations.
- Participate in incident follow-up, backlog refinement, peer review, and knowledge sharing.
Required Qualifications
- Working proficiency in Python and REST APIs; able to read, debug, and improve scripts written by others.
- Hands-on experience with Git and GitHub; familiarity with CI/CD concepts and GitHub Actions.
- Fundamental understanding of AWS services, IAM, networking, logging, and infrastructure-as-code concepts.
- Basic experience with Terraform or a strong willingness to learn it through real repository work.
- Comfort learning unfamiliar tools, asking sound technical questions, and documenting work clearly.
- Security mindset: understands the importance of least privilege, secrets handling, code review, and change control.
Preferred Qualifications
- Security tooling, SIEM/SOAR, vulnerability management, ticketing, or cloud operations experience.
- Exposure to container technologies, Docker, Kubernetes, or policy-as-code.
- Experience using enterprise AI tools, LLM APIs, RAG, MCP, or agent frameworks in a controlled environment.
- AWS Cloud Practitioner, AWS Solutions Architect Associate, Security+, or comparable learning path.
How Success Is Measured
- Useful, tested automations reduce manual effort and are adopted by their intended teams.
- GitHub Actions and Terraform changes are reviewed, traceable, and meet agreed security checks.
- Cloud configuration findings are surfaced accurately and remediated efficiently.
- AI-enabled workflows stay within approved data, access, and human-approval boundaries.
Level Expectations
- Delivers scoped work with guidance and grows into independent ownership of well-defined automations.
- Escalates ambiguity or risk early and uses established patterns rather than inventing unreviewed controls.
- Builds breadth across Python, GitHub Actions, Terraform, AWS, and secure AI practices.
As part of our selection process, external candidates may be required to attend an in-person interview with a VERSANT Media employee at one of our locations prior to a hiring decision. VERSANT Media's policy is to provide equal employment opportunities to all applicants and employees without regard to race, color, religion, creed, gender, gender identity or expression, age, national origin or ancestry, citizenship, disability, sexual orientation, marital status, pregnancy, veteran status, membership in the uniformed services, genetic information, or any other basis protected by applicable law.
For LA County and City Residents Only: VERSANT Media will consider for employment qualified applicants with criminal histories, or arrest or conviction records, in a manner consistent with relevant legal requirements, including the City of Los Angeles' Fair Chance Initiative for Hiring Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, where applicable.
If you are a qualified individual with a disability or a disabled veteran and require support throughout the application and/or recruitment process as a result of your disability, you have the right to request a reasonable accommodation. You can submit your request to candidateaccessibility@versantmedia.com.
VERSANT Media is committed to fair and equitable compensation practices. We include a good faith pay range for each position to comply with applicable state and local pay transparency laws and to promote equity across our organization. Actual compensation will be based on factors such as the candidate's skills, qualifications, experience, and location and may include additional forms of compensation and benefits such as health insurance, retirement plans, paid time off, etc.
VERSANT Media is not accepting unsolicited assistance from search firms for this employment opportunity. All resumes submitted by search firms to any employee at VERSANT via-email, the Internet, or in any form and/or method without a valid written Statement of Work in place for this position from VERSANT's Talent Acquisition team will be deemed the sole property of VERSANT. No fee will be paid in the event the candidate is hired by VERSANT as a result of the referral or through other means.