"Kindly reply to this email pavankumar.s@vdartinc.com with matching resumes only. Please avoid sharing hotlists or non-relevant profiles that do not strictly fit the requirements."
No opt/cpt
Please submit only who can share stamped visa copy , i94 with travel history , local id proof , genuine documents.
plse dont share transfer cases or edited documents only genuine consultants plse.
Role Name: Automation Engineer with python (AI-Driven Code Security & Remediation Framework)
Location: NYC NY (Onsite/Hybrid – Face 2 Face Needed) – Local only.
Rate $55-60/hr on C2C (Couple of dollars flexible)
JOB DESCRIPTION:
Role Summary
Builds and operates a system that scans GitHub/Artifactory repos for vulnerabilities and EOL libraries, then uses AI-driven automation to remediate findings — cutting manual triage and patch time firm-wide.
Core Technical Skills
7+ years of experience
- Programming: Strong Python (scanners, orchestration, API integration); basic Bash for CI/CD glue
- Source & Artifact Systems: GitHub (Actions, Advanced Security, PR workflows) and JFrog Artifactory/Xray; ability to scale across multi-repo, multi-language codebases
- Scanning Tools: Hands-on with Snyk, Xray, CodeQL / Dependabot, Trivy, or Semgrep; understanding of CVE/CVSS scoring and EOL-detection sources (e.g., endoflife.date)
- AI-Driven Remediation: Building agentic workflows (LLM-based) that interpret findings, generate patch PRs, run tests, and summarize fixes; prompt engineering for code-editing agents
- CI/CD & Orchestration: Integrating scan-and-fix pipelines into GitHub Actions/Jenkins; Docker for isolated fix-testing; scheduling via Airflow/cron
- Reporting: Structuring findings (JSON/SQL) into dashboards for tracking coverage and trends
Supporting Skills
Security fundamentals (injection, auth flaws, supply-chain/SBOM risk)
Risk-based prioritization beyond raw CVSS scores
Semantic versioning awareness for safe auto-upgrades
Testing discipline — regression validation before auto-merge
Communication Skills
Translating vulnerability data into concise, risk-framed leadership updates (exposure counts, MTTR, fix-rate trends)
Writing clear status emails on scan coverage and outstanding critical items
Building the business case (time saved, risk reduced) for non-technical stakeholders
Continuous Learning
Tracking emerging agentic/AI remediation tools and evaluating fit before firm-wide adoption
|
||||||||||
|
--
Regards
Pavan
VDart Inc
Ph: (470) 251-2584 Ext:1866
Email: Pavankumar.s@vdartinc.com
Website: https://vdart.com
Confidentiality Notice
The information contained in this message may be privileged and confidential and protected from disclosure. If the reader of this message is not the intended recipient, or an employee or agent responsible for delivering this message to the intended recipient, you are hereby notified that any dissemination, distribution or copying of this communication is strictly prohibited. If you have received this communication in error, please notify us immediately by replying to the message and deleting it from your computer.
--
You received this message because you are subscribed to the Google Groups "Xrecnet IT Recruiters Network - Corp to Corp IT Jobs & Hotlists" group.
To unsubscribe from this group and stop receiving emails from it, send an email to xrecnet+unsubscribe@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/xrecnet/CAGf9M09UXLTHkwj74Uos4R_BNY7%2BHHx5n9e1XW3y3uEMjCf7AA%40mail.gmail.com.
No comments:
Post a Comment