· Hardening frameworks: CIS Benchmarks (Windows, Linux, cloud), NIST SP 800-123, vendor-specific security guides
· Scanning and compliance: Tenable Nessus/Tenable.io, Qualys VMDR, cloud-native compliance tools
· Operating systems: Windows Server 2016/2019/2022, RHEL 8/9, Ubuntu — deep configuration knowledge
· Cloud platforms: GCP, Azure, AWS — security configuration and baseline management at the service level
· Scripting: PowerShell, Bash, Python — for compliance validation, automated checks, and reporting
· IaC familiarity: Terraform, Ansible — understanding security integration points
These are non-negotiable. If you do not meet all of these, this role is not the right fit.
· 5+ years in information security with hands-on experience in infrastructure hardening, security configuration, and technical standards development
· Deep knowledge of CIS Benchmarks or DISA STIGs — you’ve implemented these on real systems, not just read the PDFs
· Hands-on experience with at least two: Windows Server hardening, Linux hardening, database security configuration, or cloud security baselines
· Experience with vulnerability scanning and compliance tools — Tenable, Qualys, or cloud-native equivalents (AWS Config, Azure Policy, GCP Security Health Analytics)
· Ability to write clear technical documentation that infrastructure teams can implement without hand-holding
· Working proficiency in scripting (PowerShell, Bash, or Python) for configuration validation and automation