Lorven Technologies Inc. logo

Automation Engineer (AI-Driven Code Security)

Lorven Technologies Inc.

On-siteNew York City, NYseniorPosted 4h ago

Job description

Hi,

Our client is looking for

Automation Engineer (AI-Driven Code Security & Remediation Framework) in New York

below is the detailed requirements.

Job Title: Automation Engineer (AI-Driven Code Security & Remediation Framework)

Location: New York

Job Description:

  • Bachelor's degree or Maters Degree in Computer science, or a related field, with 12+ Years of relevant experience.

  • Programming: Strong Python (scanners, orchestration, API integration); basic Bash for CI/CD glue

  • Source & Artifact Systems: GitHub (Actions, Advanced Security, PR workflows) and JFrog Artifactory/Xray; ability to scale across multi-repo, multi-language codebases

  • Scanning Tools: Hands-on with Snyk, Xray, CodeQL / Dependabot, Trivy, or Semgrep; understanding of CVE/CVSS scoring and EOL-detection sources (e.g., endoflife.date)

  • AI-Driven Remediation: Building agentic workflows (LLM-based) that interpret findings, generate patch PRs, run tests, and summarize fixes; prompt engineering for code-editing agents

  • CI/CD & Orchestration: Integrating scan-and-fix pipelines into GitHub Actions/Jenkins; Docker for isolated fix-testing; scheduling via Airflow/cron

  • Reporting: Structuring findings (JSON/SQL) into dashboards for tracking coverage and trends

Supporting Skills

  • Security fundamentals (injection, auth flaws, supply-chain/SBOM risk)

  • Risk-based prioritization beyond raw CVSS scores

  • Semantic versioning awareness for safe auto-upgrades

  • Testing discipline โ€” regression validation before auto-merge

Communication Skills

  • Translating vulnerability data into concise, risk-framed leadership updates (exposure counts, MTTR, fix-rate trends)

  • Writing clear status emails on scan coverage and outstanding critical items

  • Building the business case (time saved, risk reduced) for non-technical stakeholders

Continuous Learning

  • Tracking emerging agentic/AI remediation tools and evaluating fit before firm-wide adoption