CIS Baseline & Server Image Security Engineer

TechAffinity Inc
Austin, TX, United States
3 months ago
Apply on dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Encodings Cyber Security Internet Security Linux Security Modules Windows Servers Red Hat Enterprise Linux Software Vulnerability Management Build Process CIS Benchmarks Server Operating Systems & Platforms

Job description

The CIS Baseline & Server Image Security Engineer is responsible for designing, maintaining, and implementing Center for Internet Security (CIS)-aligned security baselines and hardened server images for enterprise server operating systems. This role focuses on modern server platforms including Windows Server 2025 and Red Hat Enterprise Linux (RHEL).

The position works closely with Cyber Security Operations Center (CSOC) and multiple ITD infrastructure and engineering teams to ensure CIS benchmarks, security baselines, and gold images remain current, approved, and aligned with client required security posture. The role ensures that server operating system images reflect approved security controls while remaining operationally supportable., Develop, maintain, and deploy CIS security baselines for Windows Server 2025 and RHEL, ensuring they’‘re built into standardized server images and aligned with Client/DIR security governance., · Build and maintain CIS-based security baselines for Windows Server and RHEL, translating benchmarks into GPOs, local policies, and configuration standards; keep versioned documentation and approval records.

· Integrate approved baselines into gold server images and post-build processes; validate consistent application across new deployments and update images as OS releases or CIS versions change.

· Partner with CSOC and SRM to review baseline changes, validate security posture, and resolve configuration findings.

· Coordinate with Server Operations, Platform Engineering, Change Management, and Vulnerability Management on baseline impacts, remediation, and platform alignment.

· Identify and document baseline exceptions, risk decisions, and compensating controls in line with governance processes.

Requirements

· Hands-on experience building/maintaining CIS baselines for server OSes, with strong skills in Windows Server (GPO enforcement) and RHEL hardening.

· Experience embedding security baselines into server images or standardized builds.

· Strong cross-functional collaboration, documentation, and communication skills.

Preferred Qualifications

· Experience in a government, regulated, or large enterprise environment.

· Direct collaboration with a CSOC.

· Familiarity with vulnerability management, compliance, or audit work.

· Experience managing multiple OS versions/lifecycle transitions.

Success Measures

· Approved, versioned baselines kept current with CIS releases.

· Standardized images consistently reflecting current benchmarks.

· Clear documentation of updates and exceptions.

· Measurable improvement in server security posture/consistency.

Minimum Yrs of Experience, Skills, and Qualifications

· Hands-on experience developing and maintaining CIS security baselines for server operating systems.

· Strong knowledge of:

· Windows Server security configuration (including GPO-based enforcement)

· Linux security hardening, particularly RHEL

· Experience integrating security baselines into server images or standardized builds.

· Ability to work cross-functionally with security and infrastructure teams.

· Strong documentation, communication, and organizational skills

Preferred Skills and Qualifications

· Experience supporting CIS baselines in a government, regulated, or large enterprise environment.

· Prior experience collaborating directly with a Cyber Security Operations Center (CSOC).

· Familiarity with vulnerability management, configuration compliance, or audit activities.

· Experience supporting multiple server OS versions and lifecycle transitions.

Deliverables & Success Measures

· Approved, versioned CIS baselines for supported server operating systems.

· Secure, standardized server OS images reflecting current CIS benchmarks.

· Documented baseline updates and exception decisions aligned with CSOC and ITD standards.

· Improved consistency and security posture across enterprise server platforms.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

3:17 min

Optimizing character encoding with Kim variable byte encoding

Douglas Crockford Douglas Crockford · World Congress 2024

2:59 min

Generating a Swagger JSON file during the build process

Roman Alexis Anastasini · World Congress 2021

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

4:12 min

Distilling cross-encoder models into smaller efficient sentence embedding models

Marek Suppa · LIVE

Videos

See all

Related articles

See all