Linux Security Engineer
Role details
Job location
Tech stack
Job description
As a Linux Security Engineer in Infrastructure Security, you play a crucial role in helping maintain security posture for supporting the mission of a progressive Federal agency.
Your primary responsibilities will include:
-
Perform security hardening and rule creation Linux environment. This includes reviewing new and re-evaluating existing configuration settings and rules to verify USCIS' security posture and eliminate unnecessary risk.
-
Review existing configuration settings to identify potential security vulnerabilities and propose settings or architectural changes to address these vulnerabilities.
-
Audit firmware versions and configuration settings for all Linux end points to eliminate vulnerabilities and ensure network devices are deployed in accordance with vendor recommendations, industry best-practices, DoD
-
Security Technical and Implementation Guides (STIG), and DHS configuration guidance.
-
Analyze Security Incidents and provide recommendations for improvement.
-
Deliver consulting services to help clients achieve a superior security posture and effectively manage security incidents.
-
Create remediation recommendations and roadmaps to address identified security vulnerabilities and incidents.
Requirements
-
Expertise in installing, configuring, operating, and patching Linux servers and managing Linux-based applications.
-
Advanced knowledge of configuration management tools (e.g., Ansible, Chef, Puppet, SaltStack) and Linux/Windows administration in medium-large enterprises.
-
Strong shell scripting experience (ssh, scp, rsync, sudo) with hands-on work in containerization and orchestration tools (Docker, Podman, Kubernetes, ECS/EKS, Fargate, Singularity).
-
Advanced understanding of clustering, load balancing, replication services, and automation using Python with frameworks such as Flask, Django, or FastAPI.
-
Familiarity with container security tools (Twistlock, Falco, Clair) and possession of an active RHCE or equivalent certification/experience.
Ability to obtain and maintain Public Trust clearance
Preferred technical and professional experience
-
Able to perform security hardening, reviewing new and re-evaluating existing configuration settings and rules to verify organizations security posture and eliminate unnecessary risk in all environments.
-
Experience supporting federal agencies.
-
Ability to demonstrate and explain technical concepts to both technical and non-technical audiences
-
Able to clearly communicate with both customers and teammates and provide recommendations for improvements to existing software applications
-
Understanding of New Relic, Nagios or similar monitoring.