607,540open jobs
29,092companies
85,853added this week
Browse all
Salary
$28k – $81k per year (Estimated)
Location
In office
Employment
Full-Time
Overview
Company
Impact
Profile match

You will own the library of technical security standards, hardening baselines, and design governance processes that keep CP Axtra's infrastructure secure by default. Think of yourself as the person who takes the architect's blueprint and turns it into the building code that every project must follow.

This means writing CIS-aligned hardening guides for Windows, Linux, databases, and cloud services; running POCs to validate that security controls work without breaking production; and building automated compliance checks that catch drift before auditors do. You'll work closely with infrastructure, cloud, and DevOps teams - your standards need to be practical enough that teams adopt them willingly, not just because policy says so.

You'll also lead technical testing efforts - validating security configurations, running internal technical assessments, and ensuring that what's documented as 'standard' is actually what's deployed.

Key Responsibilities:

You will own the library of technical security standards, hardening baselines, and design governance processes that keep CP Axtra's infrastructure secure by default. Think of yourself as the person who takes the architect's blueprint and turns it into the building code that every project must follow.

This means writing CIS-aligned hardening guides for Windows, Linux, databases, and cloud services; running POCs to validate that security controls work without breaking production; and building automated compliance checks that catch drift before auditors do. You'll work closely with infrastructure, cloud, and DevOps teams - your standards need to be practical enough that teams adopt them willingly, not just because policy says so.

You'll also lead technical testing efforts - validating security configurations, running internal technical assessments, and ensuring that what's documented as 'standard' is actually what's deployed.

KEY RESPONSIBILITIES

· Develop and maintain technical security hardening baselines for all major platforms - Windows Server, RHEL/Ubuntu, databases (Oracle, MSSQL, PostgreSQL), and cloud services across GCP, Azure, AWS

· Translate security architecture decisions into implementable standards documents with clear acceptance criteria, configuration examples, and validation scripts

· Run proof-of-concept testing for new security controls and technologies, documenting performance impact, integration requirements, and operational considerations

· Build and maintain automated compliance scanning - ensuring hardening baselines are continuously validated against deployed configurations using tools like Tenable, Qualys, or cloud-native benchmarks

· Conduct technical security configuration reviews for new infrastructure deployments, cloud landing zones, and major application releases before go-live

· Manage the security standards lifecycle - regular reviews, version control, exception management, and sunset processes for deprecated standards

· Partner with infrastructure and DevOps teams to embed security baselines into golden images, Terraform modules, and CI/CD templates

· Produce technical testing reports for firewall rule reviews, network segmentation validation, and access control configuration assessments

· Maintain a standards adoption dashboard - tracking which teams have implemented which baselines and where gaps exist

Requirements

TECHNICAL REQUIREMENTS

· Hardening frameworks: CIS Benchmarks (Windows, Linux, cloud), NIST SP 800-123, vendor-specific security guides

· Scanning and compliance: Tenable Nessus/Tenable.io, Qualys VMDR, cloud-native compliance tools

· Operating systems: Windows Server 2016/2019/2022, RHEL 8/9, Ubuntu - deep configuration knowledge

· Cloud platforms: GCP, Azure, AWS - security configuration and baseline management at the service level

· Scripting: PowerShell, Bash, Python - for compliance validation, automated checks, and reporting

· IaC familiarity: Terraform, Ansible - understanding security integration points

MUST-HAVE REQUIREMENTS

These are non-negotiable. If you do not meet all of these, this role is not the right fit.

· 5+ years in information security with hands-on experience in infrastructure hardening, security configuration, and technical standards development

· Deep knowledge of CIS Benchmarks or DISA STIGs - you've implemented these on real systems, not just read the PDFs

· Hands-on experience with at least two: Windows Server hardening, Linux hardening, database security configuration, or cloud security baselines

· Experience with vulnerability scanning and compliance tools - Tenable, Qualys, or cloud-native equivalents (AWS Config, Azure Policy, GCP Security Health Analytics)

· Ability to write clear technical documentation that infrastructure teams can implement without hand-holding

· Working proficiency in scripting (PowerShell, Bash, or Python) for configuration validation and automation

NICE-TO-HAVE

These will set you apart from other candidates:

· Experience with infrastructure-as-code security - writing security-hardened Terraform modules or Ansible playbooks

· Familiarity with container and Kubernetes security hardening (CIS Kubernetes Benchmark, pod security standards)

· CompTIA Security+, CIS Benchmarks certification, or relevant cloud security certifications (AZ-500, GCP Professional Cloud Security Engineer)

· Experience in retail or high-availability environments where security hardening must balance with uptime requirements

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
607,540 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$135k – $153k per year • In office • 5+ years exp • Bachelor's Degree
Python
SQL
AI/ML
AI Agents
LLM Guardrails
DevOps
Terraform
CloudFormation
CI/CD
AWS
Management
Agile
Apply
$60k – $109k per year (Estimated) • In office
Python
Go
Java
Scala
Databases
ElasticSearch
AI/ML
Prompt Engineering
LLM
DevOps
Terraform
CI/CD
Docker
Kubernetes
Platform Engineering
Apply
$63k – $160k per year (Estimated) • In office • Internship • Master's Degree
Python
C++
Apply
Developer Internship 4 months ago
$39k – $64k per year (Estimated) • In office • Internship • Bachelor's Degree
Java
SQL
C++
Bash
Perl
Apply
Design Engineer II 7 hours ago
$23k – $49k per year (Estimated) • In office • Full-Time • 1+ year exp • Bachelor's Degree • Nanjing
Python
C++
SystemVerilog
Chips/EDA
Cadence Palladium
Apply
$43k – $89k per year (Estimated) • In office • Full-Time
Apply
$33k – $86k per year (Estimated) • Remote/Hybrid
JavaScript
TypeScript
Node JS
Databases
Oracle
DevOps
Rest API
Management
Scrum
Apply
$34k – $89k per year (Estimated) • In office • Bangkok
Python
TypeScript
SQL
Databases
Databricks
AI/ML
Prompt Engineering
LLM
RAG
DevOps
Rest API
Azure
Apply
$58k – $119k per year (Estimated) • In office • Full-Time • Bangkok
JavaScript
TypeScript
Node JS
Node JS
Nest.JS
Express
Frontend
React.js
Mobile
React Native
DevOps
CI/CD
Management
Agile
Apply
$34k – $74k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Bangkok
Management
Agile
Apply
See all jobs
This is one of many
607,540 more open roles from verified company boards, updated every day.