Infrastructure Security Engineer
The job description
Tech stack. CIS benchmarks and hardening guides, Ansible or Puppet, HashiCorp Vault, OS patch management, CrowdStrike or Wazuh, Terraform, Bash and Python, drift detection tooling
About the role
You will harden the servers, networks, and platforms that everything else at a technology company runs on, turning secure configuration from an aspirational checklist into automated, continuously enforced reality. The infrastructure security team works across Linux and Windows fleets, cloud accounts, and network devices, partnering with platform owners rather than policing them. You will build baselines, automate remediation, and eliminate entire classes of misconfiguration. This role matters because attackers live off misconfigured infrastructure, and every baseline you enforce removes whole categories of easy wins for them before they can ever be exploited. Automation is your primary tool, and you apply it relentlessly.
What you will achieve
- Bring 95 percent of production servers into CIS benchmark compliance through automated, continuously enforced remediation rather than periodic audit scrambles.
- Cut critical patch deployment time from weeks to days with a tested, staged rollout process that operations teams genuinely trust.
- Eliminate long-lived static secrets from code and configuration by migrating teams to centralized vaulting with dynamic, short-lived credentials.
- Build drift detection that flags and automatically remediates unauthorized configuration changes within one hour of occurrence.
- Deliver golden images and hardened baselines that all newly provisioned infrastructure inherits automatically, with exceptions tracked and expiring.
What you will bring
Must-haves
- 2 to 5 years in systems administration, infrastructure engineering, or security engineering roles with production ownership.
- Deep Linux or Windows hardening experience guided by CIS benchmarks or DISA STIGs.
- Configuration management skills with Ansible, Puppet, Chef, or an equivalent tool applied at fleet scale.
- Experience with secrets management platforms such as HashiCorp Vault or cloud-native KMS offerings.
- Understanding of patch management lifecycles, testing rings, and safe rollout practices that avoid outages.
- Scripting ability in Bash and Python for compliance auditing, evidence collection, and remediation automation.
- Collaboration skills to get platform teams adopting baselines willingly instead of resenting them.
Nice-to-haves
- Experience with immutable infrastructure patterns and image-based provisioning pipelines.
- Familiarity with EDR deployment, policy management, and detection tuning at fleet scale.
- Knowledge of network device hardening for switches, routers, and load balancers.
- Exposure to compliance automation frameworks such as OSCAL or InSpec.
Google
Microsoft
CrowdStrike
Palo Alto Networks
Cisco
Okta