Infrastructure & Security Engineer

SOLUTIONS FOR INFORMATION DESIGN
  • Fairfax Station, VA
    Today

    Job Description

    Job Description

    Job Description
    Description:


    Summary: The Infrastructure & Security Engineer is a hands-on individual contributor with responsibilities split approximately evenly between infrastructure engineering and operations, and cybersecurity engineering and compliance. The role leads, owns, designs, administers, secures, and continuously improves SOLID's corporate and program-specific technology environments, including cloud services, servers, virtual machines, identity platforms, endpoints, networks, firewalls, backups, and monitoring tools. The position also supports Department of Defense Risk Management Framework and other federal cybersecurity requirements, including system hardening, vulnerability management, continuous monitoring, incident response, and Authority to Operate documentation. This role works with internal departments, customers, vendors, cybersecurity personnel, and software engineering teams to translate requirements into secure, practical, and sustainable solutions.



    Essential Job Functions / Responsibilities / Duties


    Infrastructure Engineering and Operations (40%)

    • Design, implement, administer, and improve secure, scalable, resilient, and supportable infrastructure across corporate and program environments.
    • Manage cloud services, servers, virtual machines, networks, firewalls, identity platforms, endpoints, VPN services, backups, collaboration platforms, and monitoring tools.
    • Perform provisioning, configuration, patching, upgrading, monitoring, troubleshooting, backup validation, capacity planning, and other systems administration activities.
    • Develop scripts, automation, and repeatable processes to improve deployment, configuration, monitoring, evidence collection, and administration.
    • Maintain system documentation, inventories, diagrams, configuration records, operating procedures, and core IT service management processes.
    • Support disaster recovery, business continuity, and Continuity of Operations planning, documentation, testing, and corrective actions.
    • Evaluate technologies and coordinate with vendors and service providers to improve performance, security, reliability, service quality, and cost effectiveness.


    Cybersecurity Engineering and Compliance (40%)

    • Implement, maintain, assess, and document cybersecurity controls applicable to SOLID's corporate and program environments.
    • Support RMF activities throughout the system lifecycle, including control implementation, assessment, authorization, and continuous monitoring.
    • Develop and maintain ATO packages, security plans, control implementation statements, network and data-flow diagrams, configuration evidence, POA&Ms, and related artifacts.
    • Perform system hardening, maintain secure configuration baselines, and manage vulnerability identification, prioritization, remediation, validation, and reporting.
    • Review security scans, alerts, logs, and configuration findings; coordinate corrective actions and support incident investigation, containment, remediation, and lessons learned.
    • Coordinate security assessments, penetration testing, tabletop exercises, internal audits, and customer or third-party reviews.
    • Support secure handling of CUI, PII, and other sensitive information, including Zero Trust, least privilege, MFA, identity and access management, endpoint security, and periodic permission reviews.
    • Evaluate proposed technologies, system changes, and integrations for security and compliance impacts and remain current on relevant threats and federal cybersecurity requirements.


    Engineering and Stakeholder Collaboration (20%)

    • Gather and analyze operational, business, cybersecurity, and technical requirements and translate them into practical infrastructure and security solutions.
    • Collaborate with software engineers and DevOps personnel to incorporate security into development, deployment, system integration, and CI/CD processes.
    • Communicate technical risks, constraints, recommendations, and alternatives clearly to technical and nontechnical stakeholders.
    • Perform other related duties as organizational and program needs require.
    Requirements:


    Required Qualifications

    • Bachelor's degree in computer science, information technology, cybersecurity, engineering, or related discipline. An equivalent combination of education, certifications, training, and experience may be considered.
    • Seven or more years of progressively responsible experience in IT infrastructure, systems engineering, cloud administration, cybersecurity, or a closely related field.
    • Demonstrated experience designing, implementing, administering, and securing enterprise infrastructure.
    • Hands-on experience with Microsoft Azure or Azure Government, Microsoft 365 and Entra ID, AWS or AWS GovCloud, virtualization, networking, endpoint management, backup, and monitoring technologies.
    • Experience implementing or assessing controls under NIST SP 800-53, NIST SP 800-171, RMF, CMMC, FedRAMP, FISMA, or comparable federal cybersecurity requirements.
    • Experience developing or maintaining ATO documentation, security control evidence, Plans of Action and Milestones, and audit-ready technical documentation.
    • Strong troubleshooting, scripting or automation, communication, and stakeholder engagement skills.


    Required Knowledge, Skills, & Abilities

    • Strong knowledge of enterprise infrastructure, cloud computing, systems administration, networking, identity and access management, endpoint management, vulnerability management, and cybersecurity fundamentals.
    • Working knowledge of IaaS and PaaS services, logging and monitoring, storage, backup, virtualization, firewalls, switching, routing, VPN technologies, and endpoint security.
    • Ability to develop clear, accurate, and audit-ready technical and cybersecurity documentation.
    • Experience with PowerShell, Python, or comparable scripting and automation technologies; familiarity with infrastructure as code, configuration management, and DevSecOps practices.
    • Demonstrated ability to diagnose complex technical problems, identify root causes, implement sustainable solutions, and manage competing priorities independently.
    • Excellent organizational, analytical, communication, technical writing, and documentation skills.


    Additional Requirements

    • United States citizenship and current CompTIA Security+ (or higher) certification at the time of hire.
    • Ability to obtain and maintain a government security clearance and satisfy applicable DoD 8140 qualification requirements.
    • Ability to support occasional maintenance, incident response, or system restoration activities outside normal business hours.


    Preferred Qualifications

    • Experience supporting systems operating under a DoD ATO or in Azure Government, AWS GovCloud, NIPRNet, or other federal environments.
    • Experience with Terraform, Bicep, CloudFormation, Ansible, security scanning, EDR, SIEM, cloud security posture management, or automated compliance tools.
    • Experience supporting CMMC assessments or implementing NIST SP 800-171 requirements.
    • Relevant certifications such as CISSP or Microsoft Certified Azure (e.g. Administrator Associate, Security Engineer Associate, Solutions Architect, Identity and Access).

    Numbers & Facts

    LocationFairfax Station, VA

    Skills

    • Amazon Web Services (AWS)unmatched
    • Analysis Skillsunmatched
    • Ansibleunmatched
    • Automationunmatched
    • Business Analysisunmatched
    • Business Continuity Planning (BCP)unmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Capacity Managementunmatched
    • Cloud Computingunmatched
    • CompTIA Security+unmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Configuration Managementunmatched
    • Continuous Deployment/Deliveryunmatched
    • Continuous Improvementunmatched
    • Continuous Integrationunmatched
    • Corrective Actionunmatched
    • Cost Effectiveness Analysisunmatched
    • DevOpsunmatched
    • Disaster Recoveryunmatched
    • DoD Directive 8140unmatched
    • DoD Directive 8570unmatched
    • Documentationunmatched
    • Documentation Planunmatched
    • Endpoint Securityunmatched
    • Establish Prioritiesunmatched
    • FISMA - Federal Information Security Management Actunmatched
    • Firewallsunmatched
    • Governmentunmatched
    • IT Service Management (ITSM)unmatched
    • Identify Issuesunmatched
    • Identity Data Managementunmatched
    • Incident Responseunmatched
    • Information Technology & Information Systemsunmatched
    • Infrastructure as a Service (IaaS)unmatched
    • Internal Auditunmatched
    • Internet Securityunmatched
    • Microsoft Windows Azureunmatched
    • Network Administration/Managementunmatched
    • Network Switchingunmatched
    • Operational Auditunmatched
    • Operations Processesunmatched
    • Organizational Skillsunmatched
    • Penetration Testingunmatched
    • Performance Managementunmatched
    • Platform as a Service (PaaS)unmatched
    • Process Improvementunmatched
    • Python Programming/Scripting Languageunmatched
    • Requirements Managementunmatched
    • Risk Management Framework (RMF)unmatched
    • Root Cause Analysisunmatched
    • Scripting (Scripting Languages)unmatched
    • Security Analysisunmatched
    • Security Clearanceunmatched
    • Security Information and Event Management (SIEM)unmatched
    • Software Engineeringunmatched
    • Software Patchesunmatched
    • System Integration (SI)unmatched
    • System Lifecycleunmatched
    • System Operationsunmatched
    • Systems Administration/Managementunmatched
    • Systems Engineeringunmatched
    • Systems Maintenanceunmatched
    • Technical Writingunmatched
    • Testingunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • United States Citizenunmatched
    • United States Department of Defense (DoD)unmatched
    • VPN (Virtual Private Network)unmatched
    • Validation Planunmatched
    • Virtual Machine (VM)unmatched
    • Virtualizationunmatched
    • Windows PowerShellunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder