Infrastructure & Security Engineer
Summary: The Infrastructure & Security Engineer is a hands-on individual contributor with responsibilities split approximately evenly between infrastructure engineering and operations, and cybersecurity engineering and compliance. The role leads, owns, designs, administers, secures, and continuously improves SOLID's corporate and program-specific technology environments, including cloud services, servers, virtual machines, identity platforms, endpoints, networks, firewalls, backups, and monitoring tools. The position also supports Department of Defense Risk Management Framework and other federal cybersecurity requirements, including system hardening, vulnerability management, continuous monitoring, incident response, and Authority to Operate documentation. This role works with internal departments, customers, vendors, cybersecurity personnel, and software engineering teams to translate requirements into secure, practical, and sustainable solutions.
Essential Job Functions / Responsibilities / Duties
Infrastructure Engineering and Operations (40%)
- Design, implement, administer, and improve secure, scalable, resilient, and supportable infrastructure across corporate and program environments.
- Manage cloud services, servers, virtual machines, networks, firewalls, identity platforms, endpoints, VPN services, backups, collaboration platforms, and monitoring tools.
- Perform provisioning, configuration, patching, upgrading, monitoring, troubleshooting, backup validation, capacity planning, and other systems administration activities.
- Develop scripts, automation, and repeatable processes to improve deployment, configuration, monitoring, evidence collection, and administration.
- Maintain system documentation, inventories, diagrams, configuration records, operating procedures, and core IT service management processes.
- Support disaster recovery, business continuity, and Continuity of Operations planning, documentation, testing, and corrective actions.
- Evaluate technologies and coordinate with vendors and service providers to improve performance, security, reliability, service quality, and cost effectiveness.
Cybersecurity Engineering and Compliance (40%)
- Implement, maintain, assess, and document cybersecurity controls applicable to SOLID's corporate and program environments.
- Support RMF activities throughout the system lifecycle, including control implementation, assessment, authorization, and continuous monitoring.
- Develop and maintain ATO packages, security plans, control implementation statements, network and data-flow diagrams, configuration evidence, POA&Ms, and related artifacts.
- Perform system hardening, maintain secure configuration baselines, and manage vulnerability identification, prioritization, remediation, validation, and reporting.
- Review security scans, alerts, logs, and configuration findings; coordinate corrective actions and support incident investigation, containment, remediation, and lessons learned.
- Coordinate security assessments, penetration testing, tabletop exercises, internal audits, and customer or third-party reviews.
- Support secure handling of CUI, PII, and other sensitive information, including Zero Trust, least privilege, MFA, identity and access management, endpoint security, and periodic permission reviews.
- Evaluate proposed technologies, system changes, and integrations for security and compliance impacts and remain current on relevant threats and federal cybersecurity requirements.
Engineering and Stakeholder Collaboration (20%)
- Gather and analyze operational, business, cybersecurity, and technical requirements and translate them into practical infrastructure and security solutions.
- Collaborate with software engineers and DevOps personnel to incorporate security into development, deployment, system integration, and CI/CD processes.
- Communicate technical risks, constraints, recommendations, and alternatives clearly to technical and nontechnical stakeholders.
- Perform other related duties as organizational and program needs require.