Summary: The Infrastructure & Security Engineer is a hands-on individual contributor with responsibilities split approximately evenly between infrastructure engineering and operations, and cybersecurity engineering and compliance. The role leads, owns, designs, administers, secures, and continuously improves SOLID's corporate and program-specific technology environments, including cloud services, servers, virtual machines, identity platforms, endpoints, networks, firewalls, backups, and monitoring tools. The position also supports Department of Defense Risk Management Framework and other federal cybersecurity requirements, including system hardening, vulnerability management, continuous monitoring, incident response, and Authority to Operate documentation. This role works with internal departments, customers, vendors, cybersecurity personnel, and software engineering teams to translate requirements into secure, practical, and sustainable solutions.
Essential Job Functions / Responsibilities / Duties
Infrastructure Engineering and Operations (40%)
- Design, implement, administer, and improve secure, scalable, resilient, and supportable infrastructure across corporate and program environments.
- Manage cloud services, servers, virtual machines, networks, firewalls, identity platforms, endpoints, VPN services, backups, collaboration platforms, and monitoring tools.
- Perform provisioning, configuration, patching, upgrading, monitoring, troubleshooting, backup validation, capacity planning, and other systems administration activities.
- Develop scripts, automation, and repeatable processes to improve deployment, configuration, monitoring, evidence collection, and administration.
- Maintain system documentation, inventories, diagrams, configuration records, operating procedures, and core IT service management processes.
- Support disaster recovery, business continuity, and Continuity of Operations planning, documentation, testing, and corrective actions.
- Evaluate technologies and coordinate with vendors and service providers to improve performance, security, reliability, service quality, and cost effectiveness.
Cybersecurity Engineering and Compliance (40%)
- Implement, maintain, assess, and document cybersecurity controls applicable to SOLID's corporate and program environments.
- Support RMF activities throughout the system lifecycle, including control implementation, assessment, authorization, and continuous monitoring.
- Develop and maintain ATO packages, security plans, control implementation statements, network and data-flow diagrams, configuration evidence, POA&Ms, and related artifacts.
- Perform system hardening, maintain secure configuration baselines, and manage vulnerability identification, prioritization, remediation, validation, and reporting.
- Review security scans, alerts, logs, and configuration findings; coordinate corrective actions and support incident investigation, containment, remediation, and lessons learned.
- Coordinate security assessments, penetration testing, tabletop exercises, internal audits, and customer or third-party reviews.
- Support secure handling of CUI, PII, and other sensitive information, including Zero Trust, least privilege, MFA, identity and access management, endpoint security, and periodic permission reviews.
- Evaluate proposed technologies, system changes, and integrations for security and compliance impacts and remain current on relevant threats and federal cybersecurity requirements.
Engineering and Stakeholder Collaboration (20%)
- Gather and analyze operational, business, cybersecurity, and technical requirements and translate them into practical infrastructure and security solutions.
- Collaborate with software engineers and DevOps personnel to incorporate security into development, deployment, system integration, and CI/CD processes.
- Communicate technical risks, constraints, recommendations, and alternatives clearly to technical and nontechnical stakeholders.
- Perform other related duties as organizational and program needs require.
Required Qualifications
- Bachelor's degree in computer science, information technology, cybersecurity, engineering, or related discipline. An equivalent combination of education, certifications, training, and experience may be considered.
- Seven or more years of progressively responsible experience in IT infrastructure, systems engineering, cloud administration, cybersecurity, or a closely related field.
- Demonstrated experience designing, implementing, administering, and securing enterprise infrastructure.
- Hands-on experience with Microsoft Azure or Azure Government, Microsoft 365 and Entra ID, AWS or AWS GovCloud, virtualization, networking, endpoint management, backup, and monitoring technologies.
- Experience implementing or assessing controls under NIST SP 800-53, NIST SP 800-171, RMF, CMMC, FedRAMP, FISMA, or comparable federal cybersecurity requirements.
- Experience developing or maintaining ATO documentation, security control evidence, Plans of Action and Milestones, and audit-ready technical documentation.
- Strong troubleshooting, scripting or automation, communication, and stakeholder engagement skills.
Required Knowledge, Skills, & Abilities
- Strong knowledge of enterprise infrastructure, cloud computing, systems administration, networking, identity and access management, endpoint management, vulnerability management, and cybersecurity fundamentals.
- Working knowledge of IaaS and PaaS services, logging and monitoring, storage, backup, virtualization, firewalls, switching, routing, VPN technologies, and endpoint security.
- Ability to develop clear, accurate, and audit-ready technical and cybersecurity documentation.
- Experience with PowerShell, Python, or comparable scripting and automation technologies; familiarity with infrastructure as code, configuration management, and DevSecOps practices.
- Demonstrated ability to diagnose complex technical problems, identify root causes, implement sustainable solutions, and manage competing priorities independently.
- Excellent organizational, analytical, communication, technical writing, and documentation skills.
Additional Requirements
- United States citizenship and current CompTIA Security+ (or higher) certification at the time of hire.
- Ability to obtain and maintain a government security clearance and satisfy applicable DoD 8140 qualification requirements.
- Ability to support occasional maintenance, incident response, or system restoration activities outside normal business hours.
Preferred Qualifications
- Experience supporting systems operating under a DoD ATO or in Azure Government, AWS GovCloud, NIPRNet, or other federal environments.
- Experience with Terraform, Bicep, CloudFormation, Ansible, security scanning, EDR, SIEM, cloud security posture management, or automated compliance tools.
- Experience supporting CMMC assessments or implementing NIST SP 800-171 requirements.
- Relevant certifications such as CISSP or Microsoft Certified Azure (e.g. Administrator Associate, Security Engineer Associate, Solutions Architect, Identity and Access).