Security Engineer

Clouddelivered — Australia · Posted ~21 hours ago

Skills

CIS Benchmark Level 1 hardening Windows Server Linux Puppet GitHub security hardening security baseline implementation troubleshooting CIS Benchmarks

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A hands-on security engineering role embedded in a critical infrastructure environment. You will harden Windows and Linux server fleets against CIS Benchmark Level 1 controls, translate approved security baselines into maintainable configuration management code, manage changes through Git-based workflows, and troubleshoot operational impacts in collaboration with infrastructure and cybersecurity teams.

Highlights

Hands-on cybersecurity role protecting critical infrastructure through server hardening and security baseline implementation. The position offers practical work across Windows and Linux environments, configuration management, Git-based change control, and collaboration with infrastructure and cybersecurity teams.

Description

Key RequirementsHands-on experience implementing CIS Benchmark Level 1 hardening across Windows and Linux server fleets — you know the controls, not just the theory.Proven ability to translate security baselines into maintainable Puppet configuration and manage changes via GitHub pull requests.Demonstrated ability to assess operational and application impact of hardening controls, and troubleshoot issues when things break. The GigG'day, security trailblazers! Picture this: you're embedded in a critical infrastructure environment, rolling up your sleeves to harden a real-world Windows and Linux server fleet against CIS Benchmark Level 1 controls. This isn't a 'set and forget' gig — it's hands-on, high-impact work where your decisions directly protect essential energy infrastructure. You'll be translating approved hardening controls into clean, maintainable Puppet configuration, shepherding changes through GitHub pull requests, and collaborating with Cloud Infrastructure, Cyber Security, application owners and project stakeholders to test, validate and safely deploy baseline settings. When hardening breaks something (and it will), you'll be the one who knows exactly why — and how to fix it. We know because we do. Our crew has lived this work — we understand the difference between someone who can recite a CIS benchmark and someone who's actually wrestled a production Linux fleet into compliance without taking down a critical service. We're looking for the latter. If you tick the essentials below, we'll help you nail this one. Talk to us: Cloud DeliveredTristan ColemanDan HarrisonUrsan Sachdeva Essential CriteriaThe following requirements are: Experience implementing CIS Benchmark Level 1 server hardening across Windows and Linux server fleets.Ability to translate approved hardening controls into maintainable Puppet configuration.Experience managing changes through GitHub pull requests.Ability to work with Cloud Infrastructure, Cyber Security, application owners and project stakeholders to test, validate and safely deploy baseline settings.Understanding of the purpose of each control, the operational and application impact of applying it, and the troubleshooting steps required when hardening introduces system, service or application issues. Screening Questions YOU WILL BE ASKED:Seriously, don't bother if you don't think you'll pass these questions. Can you attend onsite at Hobart location?(Expected answer: yes / no)Do you live in NSW, TAS, VIC?(Expected answer: yes / no)Are you an Australian Permanent Resident or Citizen with full work rights?(Expected answer: yes / no)How many years of total experience do you have working in regulated enterprise environments?(Expected answer: a number)How many years of experience do you have implementing CIS Benchmark Level 1 server hardening?(Expected answer: a number)How many years of experience do you have hardening Windows server environments?(Expected answer: a number)How many years of experience do you have hardening Linux server environments?(Expected answer: a number)How many years of experience do you have writing and maintaining Puppet configuration for server hardening or compliance?(Expected answer: a number)How many years of experience do you have managing infrastructure changes via GitHub pull requests?(Expected answer: a number)On a scale of 1 to 10, how would you rate your ability to assess and communicate the operational and application impact of applying hardening controls to production systems?(Expected answer: a rating)