- Home
- Jobs
- Software Delivery & Cloud
- Secure Infrastructure Engineer

Secure Infrastructure Engineer at Dark Wolf Solutions
Dark Wolf Hubs/Herndon, VAFull-timeSoftware Delivery & CloudPosted 27 days ago
Apply with PipelineAbout the Role
<div>
<p data-path-to-node="0"><span style="font-size: 10pt;"><strong>Dark Wolf </strong>is seeking a <strong data-path-to-node="0" data-index-in-node="23">Secure Infrastructure Engineer</strong> to join our team. This engineer will be responsible for designing, hardening, and automating the deployment of secure baseline images for a major medical technology client. The ideal candidate will have deep expertise in Windows operating systems and database hardening, specifically aligning with STIGs. You will work within a surgical engineering team to define and build "Gold Images" that balance strict federal compliance with operational functionality. This position will call for support at a main DW office location at a hybrid capacity. Tasks may include assisting with:</span></p>
<ul>
<li style="font-size: 10pt;" data-path-to-node="1,0,0"><span style="font-size: 10pt;">Designing and creating hardened "Gold Images" for core technologies including Windows Server 2025, Windows 11, and MS SQL.</span></li>
<li style="font-size: 10pt;" data-path-to-node="1,0,0"><span style="font-size: 10pt;">Automating the application of DISA STIGs and CIS Benchmarks using PowerShell, Ansible, or similar scripting tools.</span></li>
<li style="font-size: 10pt;" data-path-to-node="1,0,0"><span style="font-size: 10pt;">Integrating secure baselines into a centralized artifact repository for consumption by product teams.</span></li>
<li style="font-size: 10pt;" data-path-to-node="1,0,0"><span style="font-size: 10pt;">Developing and maintaining documentation for security policies, configuration changes, and exception handling.</span></li>
<li style="font-size: 10pt;" data-path-to-node="1,0,0"><span style="font-size: 10pt;">Collaborating with offensive security teams to validate image resilience against vulnerabilities.</span></li>
<li style="font-size: 10pt;" data-path-to-node="1,0,0"><span style="font-size: 10pt;">Analyzing vulnerability scan results (from tools like Nessus or proprietary pipelines) and remediating configuration drift.</span></li>
<li style="font-size: 10pt;" data-path-to-node="1,0,0"><span style="font-size: 10pt;">Deploying and maintaining a centralized artifact repository on cloud-native architecture (AWS/Azure).</span></li>
<li style="font-size: 10pt;" data-path-to-node="1,0,0"><span style="font-size: 10pt;">Building and maintaining CI/CD pipelines to automate the ingestion, scanning, and publishing of secure container images.</span></li>
<li style="font-size: 10pt;" data-path-to-node="1,0,0"><span style="font-size: 10pt;">Integrating low-CVE base images (e.g., via Chainguard) into the development supply chain.</span></li>
<li style="font-size: 10pt;" data-path-to-node="1,0,0"><span style="font-size: 10pt;">Implementing and managing automated compliance scanning tools (SAST/DAST/Fuzzing) within the build pipeline.</span></li>
</ul>
<span style="font-size: 10pt;"><strong>Required Qualifications:</strong></span></div>
<div>
<ul>
<li style="font-size: 10pt;"><span style="font-size: 10pt;">Bachelor’s degree in IT Security, Information Systems, or equivalent</span></li>
<li style="font-size: 10pt;"><span style="font-size: 10pt;">Minimum of 4+ years of experience in Systems Engineering, Infrastructure Operations, or working with commercial cloud providers (AWS, Azure, or GCP)</span></li>
<li style="font-size: 10pt;"><span style="font-size: 10pt;">Deep expertise in Windows Server and Desktop administration and configuration</span></li>
<li style="font-size: 10pt;"><span style="font-size: 10pt;">Proven experience applying and managing DoD DISA STIGs or CIS Benchmarks in an enterprise environment</span></li>
<li style="font-size: 10pt;"><span style="font-size: 10pt;">Extensive experience with Containerization (Docker, Kubernetes) and Container Security</span></li>
<li style="font-size: 10pt;"><span style="font-size: 10pt;">Strong proficiency in scripting and automation (PowerShell, Python, Ansible, or Terraform) to enforce security configurations</span></li>
<li style="font-size: 10pt;"><span style="font-size: 10pt;">Solid problem-solving skills and the ability to troubleshoot complex application failures caused by security hardening</span></li>
<li style="font-size: 10pt;"><span style="font-size: 10pt;">US Citizenship and ability to be clearable up to the Top Secret clearance with SCI eligibility</span></li>
</ul>
<h3 data-path-to-node="5"><span style="font-size: 10pt;">Desired Qualifications:</span></h3>
<ul>
<li style="font-size: 10pt;" data-path-to-node="5"><span style="font-size: 10pt;">Experience working in the healthcare industry or with medical device software</span></li>
<li style="font-size: 10pt;" data-path-to-node="5"><span style="font-size: 10pt;">Experience with Platform One, Iron Bank, or similar DoD software factories</span></li>
<li style="font-size: 10pt;" data-path-to-node="5"><span style="font-size: 10pt;">Understanding of the Risk Management Framework (RMF) and accreditation processes</span></li>
<li style="font-size: 10pt;" data-path-to-node="5"><span style="font-size: 10pt;">Experience hardening PostgreSQL or other relational databases</span></li>
<li style="font-size: 10pt;" data-path-to-node="5"><span style="font-size: 10pt;">Experience with automated compliance scanning tools and proprietary fuzzing or scanning pipelines</span></li>
<li style="font-size: 10pt;" data-path-to-node="5"><span style="font-size: 10pt;">Industry certifications, such as AWS Certified Solutions Architect, Security+, or MCSE.</span></li>
</ul>
<p>This position will be supported at a hybrid capacity at any of the following DW Office locations: Herndon, VA, Omaha, NE, Colorado Springs, CO, Tampa, FL. </p>
</div>
<div>
<div>
<p>The estimated salary range for this position is $150,000.00 - $180,000.00, commensurate on experience and technical skillset. </p>
<p>We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories.</p>
<p>We are strictly looking for direct, full-time W2 employees. We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this role.<br> <br>In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.</p>
</div>
</div>
Related Roles
DevSecOps Engineer
Dark Wolf Solutions
Arlington, VADevSecOps Engineer
Dark Wolf Solutions
Dark Wolf Hubs/Herndon, VAField Service Representative
Dark Wolf Solutions
North Bay, OntarioSoftware Engineer
Dark Wolf Solutions
Tampa, FLLinux System Administrator / Network Engineer
Dark Wolf Solutions
College Park, MDPlatform Engineer
Dark Wolf Solutions
Herndon, VA/Hybrid