City : Austin
State : Texas
Neos is Seeking a CIS Baseline & Server Image Security Engineer for a contract role with our client in Austin, TX.
***ONSITE - ONLY CANDIDATES CURRENTLY RESIDING IN THE AUSTIN, TX AREA (within 50 miles) WILL BE CONSIDERED***
This role is Onsite (Austin, TX 78744)
No calls, no emails, please respond directly to the "apply" link with your resume and contact details.
The CIS Baseline & Server Image Security Engineer is responsible for designing, maintaining, and implementing Center for Internet Security (CIS)-aligned security baselines and hardened server images for enterprise server operating systems. This role focuses on modern server platforms including Windows Server 2025 and Red Hat Enterprise Linux (RHEL).
The position works closely with Cyber Security Operations Center (CSOC) and multiple ITD infrastructure and engineering teams to ensure CIS benchmarks, security baselines, and gold images remain current, approved, and aligned with TxDOT's required security posture. The role ensures that server operating system images reflect approved security controls while remaining operationally supportable.
Primary Responsibilities
CIS Baseline Development & Maintenance
Create, customize, and maintain CIS security baselines for:
Windows Server 2025
Red Hat Enterprise Linux (RHEL)
Monitor CIS benchmark releases and security advisories to ensure baselines are reviewed and updated as required.
Translate CIS benchmarks into:
Group Policy Objects (GPOs)
Local security policies
Configuration standards and baseline documentation
Maintain versioned baseline artifacts, approval records, and supporting documentation.
Server Image Hardening & Standardization
Design and maintain secure, standardized ("gold") server operating system images that incorporate approved CIS baselines.
Integrate CIS baseline controls into:
Server build images
Post-build configuration processes
Validate that baseline settings are consistently applied across newly deployed server systems.
Support image updates as new operating system releases or CIS benchmark versions are published.
Security Alignment & CSOC Collaboration
Work closely with CSOC & SRM to:
Review baseline changes
Validate security posture
Address findings related to configuration standards and benchmarks
Participate in security, baseline review, and posture validation meetings with CSOC.
Ensure CIS baseline decisions align with TxDOT & DIR STS security governance and risk management expectations.
Cross Team Coordination
Collaborate with ITD teams including:
Server Operations
Platform Engineering
Change Management
Vulnerability Management
Provide guidance on baseline impacts to operations and applications.
Support discussions related to baseline compliance, remediation strategy, and future platform alignment.
Exception & Risk Management Support
Identify scenarios where CIS baseline settings require exceptions due to operational or application constraints.
Support documentation of:
Risk decisions
Approved exceptions
Compensating controls
Maintain baseline exception artifacts in alignment with security governance processes.
Minimum Yrs of Experience, Skills, and Qualifications
Required Qualifications
Hands on experience developing and maintaining CIS security baselines for server operating systems.
Strong knowledge of:
Windows Server security configuration (including GPO based enforcement)
Linux security hardening, particularly RHEL
Experience integrating security baselines into server images or standardized builds.
Ability to work cross functionally with security and infrastructure teams.
Strong documentation, communication, and organizational skills.
Preferred Skills and Qualifications
Preferred Qualifications
Experience supporting CIS baselines in a government, regulated, or large enterprise environment.
Prior experience collaborating directly with a Cyber Security Operations Center (CSOC).
Familiarity with vulnerability management, configuration compliance, or audit activities.
Experience supporting multiple server OS versions and lifecycle transitions.
Deliverables & Success Measures
Approved, versioned CIS baselines for supported server operating systems.
Secure, standardized server OS images reflecting current CIS benchmarks.
Documented baseline updates and exception decisions aligned with CSOC and ITD standards.
Improved consistency and security posture across enterprise server platforms.
#DICE
#LI-MB
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
- Dice Id: 10111245
- Position Id: a0FRb00000G4kizMAB
- Posted 8 hours ago