Automation & Security Engineer

Hybrid in Dulles, VA, US • Posted 4 hours ago • Updated 4 hours ago
Contract Independent
Contract W2
9 Months
Hybrid
Depends on Experience
Company Branding Image
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • SENIOR VMWARE ENGINEER
  • INFRASTRUCTURE AUTOMATION ENGINEER
  • SYSTEMS ENGINEER
  • PLATFORM ENGINEER
  • AUTOMATION ENGINEER
  • VMWARE ENGINEER
  • VMWARE ARIA AUTOMATION
  • VREALIZE AUTOMATION
  • VRA
  • POWERSHELL
  • POWERCLI
  • SQL SERVER
  • STIG
  • DISA STIG
  • SALTSTACK
  • SALT

Summary

Varmoda is seeking an experienced Senior Infrastructure Automation & SQL Security Engineer to design and implement secure automation frameworks for enterprise infrastructure and Microsoft SQL Server environments. This role will automate database provisioning, configuration, patching, upgrades, security enforcement, compliance validation, and remediation across regulated production environments.

The ideal candidate will bring strong expertise in PowerShell, VMware Aria Automation, SaltStack, Microsoft SQL Server security, STIG implementation, and IT service-management integrations. This individual will collaborate with database, infrastructure, security, and platform engineering teams to improve automation, strengthen compliance, reduce configuration drift, and support highly available SQL Server platforms.

Key Responsibilities

  • Infrastructure and Database Automation
  • Design, develop, implement, and maintain automation frameworks supporting Microsoft SQL Server provisioning, configuration, patching, and upgrades.
  • Automate repeatable infrastructure and database administration processes to improve consistency, reliability, and operational efficiency.
  • Develop reusable automation components, scripts, templates, and workflows that support enterprise production environments.
  • Establish automation standards covering error handling, logging, validation, reporting, recovery, and maintainability.
  • Evaluate existing manual and automated processes and recommend opportunities for optimization.
  • Ensure automation solutions align with approved infrastructure, database, security, and operational standards.
  • Maintain technical documentation for automation frameworks, dependencies, configurations, and operating procedures.
  • PowerShell Development
  • Develop and maintain advanced PowerShell scripts and modules for infrastructure administration, database operations, security enforcement, and configuration management.
  • Build reusable PowerShell functions that support standardized provisioning, patching, compliance, and remediation activities.
  • Automate security configuration validation across SQL Server and supporting infrastructure.
  • Implement appropriate logging, exception handling, reporting, notification, and rollback capabilities.
  • Test and validate PowerShell automation before deployment into enterprise production environments.
  • Maintain PowerShell code through approved source-control, code-review, and release-management processes.
  • Troubleshoot script failures, environmental dependencies, authentication issues, and configuration conflicts.
  • VMware Aria Automation
  • Design, develop, implement, and maintain automation workflows using VMware Aria Automation, formerly known as vRealize Automation.
  • Build service catalog items, blueprints, templates, workflows, and orchestration components supporting infrastructure and application delivery.
  • Automate provisioning and configuration of virtual infrastructure supporting SQL Server and related enterprise platforms.
  • Integrate VMware Aria Automation with configuration-management, security, monitoring, and IT service-management solutions.
  • Maintain reusable deployment patterns that support consistency across development, testing, staging, and production environments.
  • Troubleshoot workflow execution, provisioning, integration, and platform-configuration issues.
  • Document VMware Aria Automation architecture, workflows, dependencies, and support procedures.
  • ITSM Integration and Change Governance
  • Integrate automation workflows with IT service-management platforms to support approvals, change tracking, implementation evidence, and auditability.
  • Automate the creation and updating of incidents, service requests, change records, tasks, and configuration information where appropriate.
  • Ensure automated deployments and remediation activities follow established change-management and release-governance requirements.
  • Maintain traceability between automation executions, approvals, configuration changes, remediation activities, and resulting system states.
  • Implement controls that prevent unapproved or unauthorized infrastructure changes.
  • Support audit requests by producing records of approvals, automation executions, changes, and validation results.
  • Collaborate with service-management teams to improve workflow integration and operational reporting.
  • SQL Server Security Hardening
  • Implement and maintain Microsoft SQL Server security hardening aligned with applicable STIGs and organizational security baselines.
  • Automate the evaluation and enforcement of SQL Server security configurations.
  • Review database settings, authentication, authorization, permissions, encryption, auditing, network connectivity, and privileged access.
  • Identify security gaps and implement approved remediation measures.
  • Develop and maintain organization-specific SQL Server security baselines.
  • Support the interpretation and application of security controls across SQL Server environments.
  • Collaborate with database administrators, cybersecurity professionals, and platform engineers to address security findings.
  • Validate that security changes do not adversely affect application functionality, availability, or performance.
  • STIG and Security Baseline Engineering
  • Apply, maintain, and automate STIGs or equivalent hardened security baselines across Microsoft SQL Server and supporting infrastructure.
  • Author and tailor organization-specific SQL Server STIG requirements aligned with NIST SP 800-53 Revision 5 controls.
  • Translate security requirements into technical checks, configuration rules, automated enforcement, and validation criteria.
  • Maintain mappings among security controls, technical requirements, automation rules, findings, and remediation evidence.
  • Review security baseline updates and evaluate their effect on existing automation and production systems.
  • Develop exceptions or compensating-control documentation when approved configurations cannot be implemented as written.
  • Support security reviews, control assessments, vulnerability-management activities, and audit preparation.
  • Maintain baseline documentation, implementation guidance, testing procedures, and compliance evidence.
  • SaltStack Compliance Automation
  • Use SaltStack to automate security configuration, STIG compliance validation, and remediation.
  • Develop and maintain Salt states, pillars, formulas, orchestration workflows, and related configuration artifacts.
  • Implement automated checks that identify deviations from approved SQL Server and infrastructure security baselines.
  • Automate remediation of approved configuration findings while preserving operational stability.
  • Integrate SaltStack automation with reporting, monitoring, ITSM, and security-management processes.
  • Test SaltStack changes in controlled environments before production implementation.
  • Troubleshoot Salt execution, agent, connectivity, configuration, and remediation failures.
  • Maintain SaltStack code, documentation, dependencies, and version-control practices.
  • Compliance Monitoring and Configuration Drift
  • Continuously monitor the security and compliance posture of SQL Server and supporting infrastructure.
  • Detect configuration drift from approved security baselines and operational standards.
  • Investigate the source and potential impact of unauthorized or unexpected configuration changes.
  • Implement automated alerts, validation checks, and remediation workflows for identified drift.
  • Differentiate legitimate approved changes from unauthorized or noncompliant configurations.
  • Track findings, remediation status, exceptions, and recurring compliance issues.
  • Recommend preventive controls when repeated configuration drift is identified.
  • Support regulated production environments through consistent monitoring and evidence collection.
  • Security Reporting and Audit Support
  • Develop security and compliance dashboards that provide visibility into baseline status, findings, remediation, exceptions, and trends.
  • Produce recurring reports covering SQL Server security posture, configuration drift, patch status, and remediation progress.
  • Generate audit artifacts demonstrating control implementation, automated validation, approvals, and remediation activities.
  • Maintain clear traceability between technical findings and applicable security requirements.
  • Support security assessments, internal reviews, external audits, and compliance-validation activities.
  • Present technical security information clearly to engineering, cybersecurity, audit, and leadership stakeholders.
  • Ensure reporting is accurate, repeatable, and supported by verifiable technical evidence.
  • High Availability and Resiliency
  • Support automation for highly available and resilient SQL Server platforms in coordination with database and platform engineers.
  • Automate configuration and validation activities for SQL Server high-availability environments.
  • Ensure automation workflows account for clustered, replicated, or redundant system components.
  • Support patching and upgrade processes designed to minimize service interruptions.
  • Develop automated health checks and post-change validation for resilient SQL Server platforms.
  • Assist with recovery, failover, rollback, and continuity testing.
  • Document high-availability dependencies, automation sequences, validation procedures, and recovery requirements.
  • Collaborate with technical teams to improve the reliability and recoverability of database platforms.

Required Qualifications

  • Minimum 6 years of hands-on experience in enterprise infrastructure automation and security engineering supporting production environments.
  • Advanced proficiency with PowerShell scripting for infrastructure automation, database administration, security enforcement, and configuration management.
  • Hands-on experience designing and implementing automation workflows using VMware Aria Automation or vRealize Automation.
  • Experience integrating automation workflows with IT service-management platforms for approvals, change tracking, execution records, and auditability.
  • Demonstrated experience securing Microsoft SQL Server environments through automated security hardening and baseline enforcement.
  • Hands-on experience applying and maintaining STIGs or equivalent hardened security baselines.
  • Experience authoring and tailoring organization-specific SQL Server STIGs aligned with NIST SP 800-53 Revision 5 controls.
  • Hands-on experience using SaltStack to implement automated compliance validation, configuration enforcement, and remediation.
  • Experience designing automation for SQL Server provisioning, configuration, patching, and upgrades.
  • Experience identifying and remediating configuration drift within regulated production environments.
  • Experience creating security reports, compliance dashboards, control evidence, and audit artifacts.
  • Understanding of Microsoft SQL Server security, including authentication, authorization, privileged access, encryption, auditing, and secure configuration.
  • Experience supporting high-availability, resiliency, or recovery requirements for enterprise database platforms.
  • Strong understanding of infrastructure-as-code, configuration-management, and automation principles.
  • Strong troubleshooting, analytical, documentation, and problem-solving skills.
  • Ability to communicate automation and cybersecurity concepts to technical and nontechnical audiences.
  • Ability to collaborate effectively with database, infrastructure, cybersecurity, platform engineering, service-management, and audit teams.

    Preferred Qualifications
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Systems, Engineering, or a related discipline.
  • Experience administering or automating Microsoft SQL Server in large-scale enterprise environments.
  • Experience with SQL Server high-availability technologies such as Always On Availability Groups or failover clustering.
  • Experience with source-control and collaborative development platforms such as Git.
  • Experience with automated testing, code review, release management, and CI/CD practices for infrastructure automation.
  • Familiarity with REST APIs, JSON, and integration development.
  • Experience integrating VMware Aria Automation, SaltStack, PowerShell, and ITSM platforms.
  • Familiarity with vulnerability-management and security-scanning technologies.
  • Knowledge of NIST cybersecurity controls, risk-management practices, and continuous monitoring.
  • Experience supporting government, healthcare, financial services, defense, or another highly regulated environment.
  • Experience preparing technical documentation and evidence for formal security-control assessments.
  • Familiarity with cloud or hybrid infrastructure automation.
  • Experience developing operational and security metrics for executive dashboards.

Preferred Certifications

  • Microsoft Certified: Windows Server Hybrid Administrator Associate
  • Microsoft Certified: Azure Database Administrator Associate
  • VMware Certified Professional, Cloud Management and Automation
  • VMware Aria Automation certification or relevant VMware credential
  • CompTIA Security+
  • Certified Information Systems Security Professional
  • GIAC Security Essentials
  • Microsoft SQL Server certification
  • SaltStack or enterprise configuration-management certification
  • Relevant PowerShell, infrastructure automation, cybersecurity, or DevSecOps certification
  •  
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91170631
  • Position Id: 26-00376
  • Posted 4 hours ago

Company Info

About Varmoda Tech LLC

In today's digital world, safeguarding your business against cyber threats is essential. Varmoda Tech offers comprehensive cybersecurity services tailored to your needs. From assessing high-value assets to proactive threat detection and incident response, we're here to help you navigate the ever-evolving cyber landscape. Partner with us to fortify your digital defenses and keep your business secure.

Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

It looks like there aren't any Similar Jobs for this job yet.

Search all similar jobs