> Markdown version of [/jobs/ext/190292-jcip-senior-infrastructure-virtualization-storage-technical-reviewer](https://www.wearedevelopers.com/jobs/ext/190292-jcip-senior-infrastructure-virtualization-storage-technical-reviewer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # JCIP Senior Infrastructure Virtualization & Storage Technical Reviewer - **Company:** Pueo Business Solutions - **Location:** Reston, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** User Authentication, Cyber Security, Data Security, VMware ESX Servers, Federal Information Processing Standards (FIPS), Hyper-V, Identity and Access Management, Kernel-Based Virtual Machine, NetApp Applications, Network Attached Storage (Server Appliance), VMware Infrastructure, Virtualization Technology, Storage Technologies, Vulnerability Analysis - **Published:** May 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=0f0164d9c7b5d66c ## About the Role * Knowledge: + Strong understanding of virtualization platforms: VMware ESXi, Microsoft Hyper-V, and KVM architectures and security features. + Familiarity with common NAS/SAN systems (NetApp, Dell EMC) and their security considerations. + Ability to interpret and apply STIGs, SRGs, and NIST 800-53/800-171 controls related to virtualized infrastructure and storage. + Knowledge of encryption standards, including FIPS, and their application in storage security. + Awareness of virtualization and storage-related attack vectors and mitigation strategies. * Skills: + Proficient in performing manual checklist audits and functional risk assessments for virtualized and storage environments. + Strong analytical skills to evaluate complex system configurations and security controls. + Effective communication skills to present findings and recommendations to technical teams and leadership. + Ability to mentor junior inspectors and lead technical discussions. * Abilities: + Lead IV&S inspection efforts independently with minimal oversight. + Provide actionable security architecture recommendations to enhance virtual and storage infrastructure defenses. + Manage inspection activities and deliverables efficiently within tight schedules. + Adapt quickly to vendor-specific nuances while maintaining a vendor-agnostic security focus. * Certifications: + Obtain an IAT-III or Maintain IAT Level III Certification in compliance with DoD 8570.01-M and DoD Directive 8140 Cyberspace Workforce Management. + CASP+ CE + CCNP Security + CISA + CISSP (or Associate) ## Description * Conduct comprehensive technical assessments and manual audits of virtualized infrastructure platforms and network-attached storage (NAS) environments in Intelligence Community (IC) settings. * Evaluate compliance with IC Directives, Security Technical Implementation Guides (STIGs), Security Requirement Guides (SRGs), and NIST 800-53 Rev 5 and 800-171 security controls relevant to virtualization and storage systems. * Perform independent manual STIG checklist reviews for leading virtualization platforms including VMware ESXi, Microsoft Hyper-V, and KVM, as well as NAS/SAN devices such as NetApp and Dell EMC systems. * Analyze risks and attack vectors associated with virtualized environments and storage architectures; assess controls including encryption, authentication, access management, and FIPS compliance. * Provide technical recommendations and architectural guidance to improve virtual infrastructure security posture. * Liaise with virtualization system administrators, storage teams, and leadership to communicate findings, risk assessments, and remediation strategies. * Lead and mentor Level 1 IDRs in conducting IV&S inspections and risk analysis. * Stay current with emerging virtualization and storage security threats, industry trends, and vendor hardening best practices. * Participate in inspection planning, execution, reporting, and deliver clear, concise written and oral assessments. * Travel as necessary to support onsite inspections. (8-12 weeks of travel avg, some international and passport required). ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Web-based Information Visualization](https://www.wearedevelopers.com/videos/84-web-based-information-visualization) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)