Automation Engineer in McLean, Virginia at Merlin International Inc
Explore Related Opportunities
Job Description
About Merlin Group
Merlin Group operates at the intersection of cyber innovation, national security, and technology-driven transformation. With a mission to accelerate the adoption of high-impact technologies across the U.S. public sector and regulated commercial markets, Merlin is uniquely structured around three core tenets – Invest, Enable, and Scale – each designed to address a specific stage of the technology lifecycle. Together, our affiliates – Merlin Ventures, CGC, and Merlin Cyber – form a flywheel that builds enduring capability for customers, partners, and the broader cyber ecosystem, operationalizing technological advancement into mission-ready, enterprise-grade solutions.
At Merlin, we believe our strength lies in our people. Team members are encouraged to be creative, collaborative, and nimble, pursuing paths to deliver the cutting-edge cybersecurity solutions that our customers rely on. From next-generation cyber defense to secure cloud and AI, we are united by one purpose – transforming innovation into mission impact.
The Opportunity
The Engineering team partners closely with the Security Operations Center to build and maintain the automation infrastructure that supports continuous compliance and security operations. This role sits within Engineering and focuses on building sustainable, repeatable pipelines for evidence collection, detection deployment, and incident response orchestration across a FedRAMP-authorized environment.
We are looking for an Automation Engineer to design and implement the CI/CD and evidence automation infrastructure that underpins our security operations. You will build the pipelines that transform manual compliance processes into automated, repeatable workflows — ensuring continuous audit readiness rather than point-in-time compliance. This role is ideal for an engineer who wants to apply software engineering practices to security operations at scale.
Primary Duties & Responsibilities
- Design and implement automated evidence collection pipelines across compliance control families
- Build CI/CD infrastructure for detection rule deployment, testing, and validation
- Develop SOAR playbooks and workflow automation for incident response processes
- Automate vulnerability disclosure, file integrity monitoring, and notification workflows
- Create evidence validation tooling to support continuous audit readiness
- Identify and implement opportunities for AI-assisted automation within security operations
Qualifications
Required- 3+ years building CI/CD pipelines and infrastructure automation
- Experience with SOAR platforms (Cortex XSOAR, Singularity Hyper automation, Phantom, or similar)
- Proficiency in Python for security automation scripting
- Familiarity with evidence collection requirements for compliance frameworks such as FedRAMP or SOC 2
- Experience with infrastructure-as-code tools (Terraform, CloudFormation, or similar)
Preferred
- Experience automating compliance evidence workflows in a FedRAMP-authorized environment
- Familiarity with SIEM platforms (Splunk, Sentinel One) and detection rule lifecycle management
- Background in DevSecOps practices and security pipeline integration
- Experience with multi-cloud architectures (AWS, Azure, GCP)
- Familiarity with AI/ML tooling applied to security automation use cases
Success Attributes
- Ability to operate in a fast-paced, growth-oriented environment
- Strong collaboration across distributed teams
Benefits & Perks
We want to empower and inspire employees to be and do their best. Our workdays are dynamic, collegial, and fun. Our office features multiple places to work unconstrained by typical office barriers. Our wellness package provides access to an on-site gym and includes medical, dental, and vision insurance along with options for FSA and EAP. We offer 401(k) with employer match, unlimited PTO, and a culture respectful of the reality that not everything in one’s personal life is guaranteed to happen only after hours.
All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran, or any other status protected by applicable federal, state, local, or international law.