Linux Security Engineer
IBM · Alexandria, VA · 2 wk ago
HybridFull-time
About the role
As a Linux Security Engineer in Infrastructure Security, you play a crucial role in helping maintain the security posture for supporting the mission of a progressive Federal agency. You’ll work with leading companies across industries, helping them shape their hybrid cloud and AI journeys, with access to robust IBM technology, Red Hat, and strategic partners to drive meaningful change and accelerate client impact.
Responsibilities
- Perform security hardening and rule creation for Linux environments, including reviewing new and re-evaluating existing configuration settings and rules to verify security posture and eliminate unnecessary risk.
- Review existing configuration settings to identify potential security vulnerabilities and propose settings or architectural changes to address these vulnerabilities.
- Audit firmware versions and configuration settings for all Linux endpoints to eliminate vulnerabilities and ensure network devices are deployed in accordance with vendor recommendations, industry best practices, DoD Security Technical and Implementation Guides (STIG), and DHS configuration guidance.
- Analyze security incidents and provide recommendations for improvement.
- Deliver consulting services to help clients achieve a superior security posture and effectively manage security incidents.
- Create remediation recommendations and roadmaps to address identified security vulnerabilities and incidents.
- Demonstrate and explain technical concepts to both technical and non-technical audiences.
- Communicate clearly with customers and teammates, providing recommendations for improvements to existing software applications.
Requirements
- Expertise in installing, configuring, operating, and patching Linux servers and managing Linux-based applications.
- Advanced knowledge of configuration management tools (e.g., Ansible, Chef, Puppet, SaltStack) and Linux/Windows administration in medium–large enterprises.
- Strong shell scripting experience (ssh, scp, rsync, sudo) with hands-on work in containerization and orchestration tools (Docker, Podman, Kubernetes, ECS/EKS, Fargate, Singularity).
- Advanced understanding of clustering, load balancing, replication services, and automation using Python with frameworks such as Flask, Django, or FastAPI.
- Familiarity with container security tools (Twistlock, Falco, Clair).
- Active RHCE or equivalent certification/experience.
- Ability to obtain and maintain Public Trust clearance.
- Experience supporting federal agencies.
- Understanding of monitoring tools such as New Relic or Nagios.
Preferred Qualifications
- Able to perform security hardening, reviewing new and re-evaluating existing configuration settings and rules to verify an organization’s security posture and eliminate unnecessary risk in all environments.
Preferred Education: Bachelor's Degree