We are looking for a DevOps Engineer with a strong focus on infrastructure and operating system security to harden, monitor, and protect our on-premises environment. You will own the security posture of our servers, virtualization layer, and internal networks — building automated, repeatable hardening and compliance processes rather than one-off fixes. This role sits at the intersection of DevOps automation and security engineering.
Key Responsibilities
Harden Linux (and Windows, where applicable) servers in line with CIS Benchmarks; automate hardening and compliance checks using Ansible, OpenSCAP, and Lynis.
Design, implement, and maintain host-level security controls: SSH hardening, sudo/least-privilege policies, SELinux/AppArmor, auditd, host firewalls (nftables/firewalld), and kernel hardening.
Build and operate a vulnerability management program: scheduled scanning (OpenVAS/Nessus), CVE triage, and an automated patching cadence across the fleet.
Manage configuration as code — ensure all server configurations are version-controlled, repeatable, and drift-detected using Ansible (or Puppet/Salt).
Deploy and operate centralized logging, monitoring, and detection (Wazuh/ELK/Graylog), including file integrity monitoring, alerting on privileged activity, and log retention.
Strengthen network security: VLAN segmentation, firewall rule management
Implement and administer secrets management (HashiCorp Vault or equivalent); eliminate hardcoded credentials and enforce rotation.
Harden identity infrastructure (Active Directory / FreeIPA / LDAP): tiered admin model, service account hygiene, MFA for administrative access
Secure out-of-band management interfaces (iDRAC/iLO/IPMI) and enforce firmware/BIOS security controls.
Support compliance and audit activities by mapping technical controls to frameworks such as CIS, NIST, or ISO 27001.
Participate in incident response: investigation, containment, and post-incident hardening.
Required Skills & Qualifications
5+ years in DevOps, systems engineering, or infrastructure roles with hands-on security responsibility.
Strong Linux administration skills (RHEL/Ubuntu) with deep knowledge of OS hardening, permissions, PAM, and kernel security parameters.
Practical experience applying and auditing CIS Benchmarks (OpenSCAP, Lynis, or similar).
Proficiency with Ansible (or Puppet/Salt) for automated configuration and hardening at scale.
Solid networking fundamentals: TCP/IP, VLANs, firewalls, TLS/PKI, VPNs, and network segmentation.
Experience with vulnerability scanning and patch management in on-prem environments.
Experience with centralized logging/SIEM and host-based intrusion detection (Wazuh, ELK, Graylog, or similar).
Scripting ability in Bash and Python.
Familiarity with virtualization platforms (VMware vSphere, Proxmox, or Hyper-V) and their security models.
Version control (Git) and infrastructure-as-code practices.