> Markdown version of [/jobs/ext/169706-secure-infrastructure-engineer](https://www.wearedevelopers.com/jobs/ext/169706-secure-infrastructure-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Secure Infrastructure Engineer - **Company:** Dark Wolf Solutions - **Location:** Colorado Springs, CO, United States - **Experience:** Experienced - **Salary:** $150,000.0 - $180,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Microsoft Windows, Amazon Web Services, Systems Engineering, Microsoft Azure, Cyber Security, Information Systems, Databases, Relational Databases, Fuzz Testing, Python (Programming Language), PostgreSQL, Microsoft SQL Server, Windows Servers, Windows PowerShell, Ansible, Software Factory, Systems Integration, Scripting, Containerization, Kubernetes, Tenable Nessus, Nessus, CIS Benchmarks, Terraform, Docker, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** May 15, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=0a2d0dda336531b8 ## About the Role Do you have experience in Windows Server administration?, Do you have a Bachelor's degree?, * Bachelor's degree in IT Security, Information Systems, or equivalent * Minimum of 4+ years of experience in Systems Engineering, Infrastructure Operations, or working with commercial cloud providers (AWS, Azure, or GCP) * Deep expertise in Windows Server and Desktop administration and configuration * Proven experience applying and managing DoD DISA STIGs or CIS Benchmarks in an enterprise environment * Extensive experience with Containerization (Docker, Kubernetes) and Container Security * Strong proficiency in scripting and automation (PowerShell, Python, Ansible, or Terraform) to enforce security configurations * Solid problem-solving skills and the ability to troubleshoot complex application failures caused by security hardening * US Citizenship and ability to be clearable up to the Top Secret clearance with SCI eligibility, * Experience working in the healthcare industry or with medical device software * Experience with Platform One, Iron Bank, or similar DoD software factories * Understanding of the Risk Management Framework (RMF) and accreditation processes * Experience hardening PostgreSQL or other relational databases * Experience with automated compliance scanning tools and proprietary fuzzing or scanning pipelines * Industry certifications, such as AWS Certified Solutions Architect, Security+, or MCSE. ## Description Dark Wolf is seeking a Secure Infrastructure Engineer to join our team. This engineer will be responsible for designing, hardening, and automating the deployment of secure baseline images for a major medical technology client. The ideal candidate will have deep expertise in Windows operating systems and database hardening, specifically aligning with STIGs. You will work within a surgical engineering team to define and build "Gold Images" that balance strict federal compliance with operational functionality. This position will call for support at a main DW office location at a hybrid capacity. Tasks may include assisting with: * Designing and creating hardened "Gold Images" for core technologies including Windows Server 2025, Windows 11, and MS SQL. * Automating the application of DISA STIGs and CIS Benchmarks using PowerShell, Ansible, or similar scripting tools. * Integrating secure baselines into a centralized artifact repository for consumption by product teams. * Developing and maintaining documentation for security policies, configuration changes, and exception handling. * Collaborating with offensive security teams to validate image resilience against vulnerabilities. * Analyzing vulnerability scan results (from tools like Nessus or proprietary pipelines) and remediating configuration drift. * Deploying and maintaining a centralized artifact repository on cloud-native architecture (AWS/Azure). * Building and maintaining CI/CD pipelines to automate the ingestion, scanning, and publishing of secure container images. * Integrating low-CVE base images (e.g., via Chainguard) into the development supply chain. * Implementing and managing automated compliance scanning tools (SAST/DAST/Fuzzing) within the build pipeline. ## Related Videos - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Dev & Test in the Cloud? Deploy your cloud environments with Ansible & Terraform](https://www.wearedevelopers.com/videos/1607-dev-test-in-the-cloud-deploy-your-cloud-environments-with-ansible-terraform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Eclipse Che for Infrastructure Automation](https://www.wearedevelopers.com/videos/1611-eclipse-che-for-infrastructure-automation) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)