Secure Infrastructure Engineer

Dark Wolf Solutions
Tampa, FL, United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Compensation
$150,000.0 - $180,000.0
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Microsoft Windows Amazon Web Services Systems Engineering Microsoft Azure Cyber Security Information Systems Databases Relational Databases Fuzz Testing Python (Programming Language) PostgreSQL
+17 more
Microsoft SQL Server Windows Servers Windows PowerShell Ansible Software Factory Systems Integration Scripting Containerization Kubernetes Tenable Nessus Nessus CIS Benchmarks Terraform Docker Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

Dark Wolf is seeking a Secure Infrastructure Engineer to join our team. This engineer will be responsible for designing, hardening, and automating the deployment of secure baseline images for a major medical technology client. The ideal candidate will have deep expertise in Windows operating systems and database hardening, specifically aligning with STIGs. You will work within a surgical engineering team to define and build ā€œGold Imagesā€ that balance strict federal compliance with operational functionality. This position will call for support at a main DW office location at a hybrid capacity. Tasks may include assisting with:

  • Designing and creating hardened ā€œGold Imagesā€ for core technologies including Windows Server 2025, Windows 11, and MS SQL.
  • Automating the application of DISA STIGs and CIS Benchmarks using PowerShell, Ansible, or similar scripting tools.
  • Integrating secure baselines into a centralized artifact repository for consumption by product teams.
  • Developing and maintaining documentation for security policies, configuration changes, and exception handling.
  • Collaborating with offensive security teams to validate image resilience against vulnerabilities.
  • Analyzing vulnerability scan results (from tools like Nessus or proprietary pipelines) and remediating configuration drift.
  • Deploying and maintaining a centralized artifact repository on cloud-native architecture (AWS/Azure).
  • Building and maintaining CI/CD pipelines to automate the ingestion, scanning, and publishing of secure container images.
  • Integrating low-CVE base images (e.g., via Chainguard) into the development supply chain.
  • Implementing and managing automated compliance scanning tools (SAST/DAST/Fuzzing) within the build pipeline.

Requirements

Do you have experience in Windows Server administration?, Do you have a Bachelor’s degree?, * Bachelor’s degree in IT Security, Information Systems, or equivalent

  • Minimum of 4+ years of experience in Systems Engineering, Infrastructure Operations, or working with commercial cloud providers (AWS, Azure, or GCP)
  • Deep expertise in Windows Server and Desktop administration and configuration
  • Proven experience applying and managing DoD DISA STIGs or CIS Benchmarks in an enterprise environment
  • Extensive experience with Containerization (Docker, Kubernetes) and Container Security
  • Strong proficiency in scripting and automation (PowerShell, Python, Ansible, or Terraform) to enforce security configurations
  • Solid problem-solving skills and the ability to troubleshoot complex application failures caused by security hardening
  • US Citizenship and ability to be clearable up to the Top Secret clearance with SCI eligibility, * Experience working in the healthcare industry or with medical device software
  • Experience with Platform One, Iron Bank, or similar DoD software factories
  • Understanding of the Risk Management Framework (RMF) and accreditation processes
  • Experience hardening PostgreSQL or other relational databases
  • Experience with automated compliance scanning tools and proprietary fuzzing or scanning pipelines
  • Industry certifications, such as AWS Certified Solutions Architect, Security+, or MCSE.

Benefits & conditions

4.54.5 out of 5 stars Tampa, FL Hybrid work $150,000 - $180,000 a year - Full-time, The estimated salary range for this position is $150,000.00 - $180,000.00, commensurate on experience and technical skillset.

We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories.

We are strictly looking for direct, full-time W2 employees. We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this role.

In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler Ā· LIVE

1:42 min

Automating Skupper deployments using Ansible

Alex Soto Alex Soto Ā· WWC 2024

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz Ā· WWC 2025

1:45 min

Transitioning from software development to security roles

Stefania Chaplin Ā· WWC 2022

3:19 min

Executing complex workflows using Ansible Automation Platform

Goetz Rieger Goetz Rieger Ā· WWC 2025

2:34 min

Docker sandbox architecture and microVM environment integration

Manuel de la Peña Manuel de la Peña · WWC Europe 2026

Videos

See all

Related articles

See all