Sr. Cyber Security Engineer - Automation

  • Full-time
  • Business Segment: Versant O&T
  • Compensation: USD 130000 - USD 160000 - yearly

Company Description

VERSANT (Nasdaq: VSNT) is an industry-changing media and entertainment business and home to trusted brands that shape culture, inform audiences, and build lasting connections. It operates across four core markets: political news and opinion, business news and personal finance, golf, and sports and genre entertainment. These markets are served through a powerful portfolio of iconic and innovative brands, including CNBC, MS NOW, USA Network, Golf Channel, Oxygen, E!, SYFY, and Versant's sports division USA Sports, along with complementary digital assets including Fandango, Rotten Tomatoes, GolfNow and GolfPass.

Job Description

The Senior Automation Security Engineer designs and delivers scalable automation that strengthens the organization’s security posture and engineering velocity. This role combines strong Python engineering with deep working knowledge of GitHub/GitHub Actions, Terraform, and AWS. The engineer leads secure automation patterns, enables disciplined internal use of AI tools, and builds production-quality agentic workflows with appropriate governance, observability, and human control.

What You Will Do

Automation Platform Engineering

  • Design, build, and operate reusable Python services, libraries, CLIs, and integrations that automate security controls and operational workflows.
  • Establish engineering standards for reliability, testing, observability, secrets handling, access control, and lifecycle ownership of automations.
  • Automate high-value workflows such as identity and access reviews, cloud configuration remediation, evidence collection, security findings enrichment, exception management, and incident response orchestration.

GitHub, GitHub Actions & DevSecOps

  • Own and improve GitHub Actions patterns for secure CI/CD, including reusable workflows, OIDC-based cloud access, artifact controls, approvals, and policy checks.
  • Integrate code scanning, dependency controls, secrets detection, IaC scanning, tests, and release gates into engineering workflows without unnecessary delivery friction.
  • Review workflow and repository permissions, third-party actions, supply-chain risks, and runner security; drive pragmatic remediation.

Terraform & AWS Security Automation

  • Design and maintain Terraform modules, guardrails, and policy-as-code controls for AWS environments.
  • Automate secure AWS configuration across IAM, Organizations, VPC, CloudTrail, CloudWatch, S3, KMS, Lambda, ECS/EKS, Secrets Manager, and related services.
  • Build safe detection and remediation flows using least privilege, change controls, dry runs, rollback approaches, and audit-ready logging.

Internal AI Enablement & Agent Development

  • Develop governed internal AI automations and agents that use approved models, tools, knowledge sources, and identity boundaries.
  • Design agent workflows with explicit tool scopes, input validation, prompt-injection defenses, audit logs, evaluation cases, and human-in-the-loop approvals for material actions.
  • Create reusable patterns for tool calling, retrieval/RAG, workflow orchestration, context handling, and secure deployment; mentor teams on their use.
  • Champion responsible AI-assisted or “vibe coding” practices: clear review accountability, source validation, secure code patterns, and protection of internal data.

Technical Leadership

  • Translate security and operational needs into an automation roadmap, architecture, and measurable outcomes.
  • Lead technical design reviews, mentor junior engineers, and partner with platform, cloud, SOC, and application teams.
  • Communicate tradeoffs and risk clearly to technical and non-technical stakeholders.

 

     

      Qualifications

      Required Qualifications

      • Strong Python software engineering skills, including API integration, testing, packaging, error handling, and production troubleshooting.
      • Hands-on expertise with GitHub and GitHub Actions, including reusable workflows, OIDC, permissions, secure secrets use, and CI/CD controls.
      • Strong Terraform experience: modules, state, plans, code review, testing, and policy or guardrail implementation.
      • Deep practical understanding of AWS security and cloud architecture, especially IAM, network boundaries, logging, encryption, and serverless/container services.
      • Experience designing automation that is reliable, observable, least-privileged, and safe to roll out.
      • Demonstrated ability to lead design discussions, review code, and guide work across teams.
      • Working knowledge of AI/LLM application risks and the engineering controls needed for safe agentic automation.

      Preferred Qualifications

      • Experience with security orchestration, SIEM/SOAR, detection engineering, incident response, or vulnerability-management automation.
      • Experience with policy-as-code and cloud security tools such as OPA, Checkov, tfsec, Trivy, AWS Config, Security Hub, or GuardDuty.
      • Hands-on delivery with LLM APIs, agent frameworks, MCP, RAG, evaluation frameworks, or enterprise AI platforms.
      • AWS Security Specialty, AWS DevOps Engineer, CISSP, Security+, or comparable certification.
      • Experience operating workloads with Docker, Kubernetes, ECS, or EKS.

      How Success Is Measured

      • Automation products materially reduce manual work, improve control coverage, and have clear owners, runbooks, telemetry, and SLAs.
      • GitHub Actions and Terraform controls improve delivery security while remaining usable for engineering teams.
      • AWS risks are prevented, detected, or remediated through durable automation and measurable reduction in recurrence.
      • Internal AI agents deliver bounded business value while passing security review, evaluation, and operational-readiness criteria.
      • Teams adopt consistent, safe AI-assisted development practices and can reuse documented automation patterns.

      Level Expectations

      • Independently owns ambiguous, cross-team automation problems from design through production operation.
      • Sets technical direction and guardrails; does not merely implement tickets.
      • Mentors others and raises the engineering quality, security posture, and AI readiness of the broader organization.

      Additional Information

      As part of our selection process, external candidates may be required to attend an in-person interview with a VERSANT Media employee at one of our locations prior to a hiring decision. VERSANT Media's policy is to provide equal employment opportunities to all applicants and employees without regard to race, color, religion, creed, gender, gender identity or expression, age, national origin or ancestry, citizenship, disability, sexual orientation, marital status, pregnancy, veteran status, membership in the uniformed services, genetic information, or any other basis protected by applicable law.

      For LA County and City Residents Only: VERSANT Media will consider for employment qualified applicants with criminal histories, or arrest or conviction records, in a manner consistent with relevant legal requirements, including the City of Los Angeles' Fair Chance Initiative for Hiring Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, where applicable.

      If you are a qualified individual with a disability or a disabled veteran and require support throughout the application and/or recruitment process as a result of your disability, you have the right to request a reasonable accommodation. You can submit your request to [email protected].

      VERSANT Media is committed to fair and equitable compensation practices. We include a good faith pay range for each position to comply with applicable state and local pay transparency laws and to promote equity across our organization. Actual compensation will be based on factors such as the candidate's skills, qualifications, experience, and location and may include additional forms of compensation and benefits such as health insurance, retirement plans, paid time off, etc.

      VERSANT Media is not accepting unsolicited assistance from search firms for this employment opportunity. All resumes submitted by search firms to any employee at VERSANT via-email, the Internet, or in any form and/or method without a valid written Statement of Work in place for this position from VERSANT's Talent Acquisition team will be deemed the sole property of VERSANT. No fee will be paid in the event the candidate is hired by VERSANT as a result of the referral or through other means.

      By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply

      Privacy Notice