{"schemaVersion":"jobsearcher.job.v1","id":"e8cdc10c8f81bb8f4e53b08f","url":"https://jobsearcher.com/jobs/e8cdc10c8f81bb8f4e53b08f","canonicalUrl":"https://jobsearcher.com/jobs/e8cdc10c8f81bb8f4e53b08f","title":"Automation & Security Engineer","description":"Varmoda is seeking an experienced Senior Infrastructure Automation & SQL Security Engineer to design and implement secure automation frameworks for enterprise infrastructure and Microsoft SQL Server environments. This role will automate database provisioning, configuration, patching, upgrades, security enforcement, compliance validation, and remediation across regulated production environments.\n\nThe ideal candidate will bring strong expertise in PowerShell, VMware Aria Automation, SaltStack, Microsoft SQL Server security, STIG implementation, and IT service-management integrations. This individual will collaborate with database, infrastructure, security, and platform engineering teams to improve automation, strengthen compliance, reduce configuration drift, and support highly available SQL Server platforms.\n\nKey Responsibilities\n\nDesign, develop, implement, and maintain automation frameworks supporting Microsoft SQL Server provisioning, configuration, patching, and upgrades.\nAutomate repeatable infrastructure and database administration processes to improve consistency, reliability, and operational efficiency.\nDevelop reusable automation components, scripts, templates, and workflows that support enterprise production environments.\nEstablish automation standards covering error handling, logging, validation, reporting, recovery, and maintainability.\nEvaluate existing manual and automated processes and recommend opportunities for optimization.\nEnsure automation solutions align with approved infrastructure, database, security, and operational standards.\nMaintain technical documentation for automation frameworks, dependencies, configurations, and operating procedures.\nDevelop and maintain advanced PowerShell scripts and modules for infrastructure administration, database operations, security enforcement, and configuration management.\nBuild reusable PowerShell functions that support standardized provisioning, patching, compliance, and remediation activities.\nAutomate security configuration validation across SQL Server and supporting infrastructure.\nImplement appropriate logging, exception handling, reporting, notification, and rollback capabilities.\nTest and validate PowerShell automation before deployment into enterprise production environments.\nMaintain PowerShell code through approved source-control, code-review, and release-management processes.\nTroubleshoot script failures, environmental dependencies, authentication issues, and configuration conflicts.\nDesign, develop, implement, and maintain automation workflows using VMware Aria Automation, formerly known as vRealize Automation.\nBuild service catalog items, blueprints, templates, workflows, and orchestration components supporting infrastructure and application delivery.\nAutomate provisioning and configuration of virtual infrastructure supporting SQL Server and related enterprise platforms.\nIntegrate VMware Aria Automation with configuration-management, security, monitoring, and IT service-management solutions.\nMaintain reusable deployment patterns that support consistency across development, testing, staging, and production environments.\nTroubleshoot workflow execution, provisioning, integration, and platform-configuration issues.\nDocument VMware Aria Automation architecture, workflows, dependencies, and support procedures.\nIntegrate automation workflows with IT service-management platforms to support approvals, change tracking, implementation evidence, and auditability.\nAutomate the creation and updating of incidents, service requests, change records, tasks, and configuration information where appropriate.\nEnsure automated deployments and remediation activities follow established change-management and release-governance requirements.\nMaintain traceability between automation executions, approvals, configuration changes, remediation activities, and resulting system states.\nImplement controls that prevent unapproved or unauthorized infrastructure changes.\nSupport audit requests by producing records of approvals, automation executions, changes, and validation results.\nCollaborate with service-management teams to improve workflow integration and operational reporting.\nImplement and maintain Microsoft SQL Server security hardening aligned with applicable STIGs and organizational security baselines.\nAutomate the evaluation and enforcement of SQL Server security configurations.\nReview database settings, authentication, authorization, permissions, encryption, auditing, network connectivity, and privileged access.\nIdentify security gaps and implement approved remediation measures.\nDevelop and maintain organization-specific SQL Server security baselines.\nSupport the interpretation and application of security controls across SQL Server environments.\nCollaborate with database administrators, cybersecurity professionals, and platform engineers to address security findings.\nValidate that security changes do not adversely affect application functionality, availability, or performance.\nSTIG and Security Baseline Engineering\nApply, maintain, and automate STIGs or equivalent hardened security baselines across Microsoft SQL Server and supporting infrastructure.\nAuthor and tailor organization-specific SQL Server STIG requirements aligned with NIST SP 800-53 Revision 5 controls.\nTranslate security requirements into technical checks, configuration rules, automated enforcement, and validation criteria.\nMaintain mappings among security controls, technical requirements, automation rules, findings, and remediation evidence.\nReview security baseline updates and evaluate their effect on existing automation and production systems.\nDevelop exceptions or compensating-control documentation when approved configurations cannot be implemented as written.\nSupport security reviews, control assessments, vulnerability-management activities, and audit preparation.\nMaintain baseline documentation, implementation guidance, testing procedures, and compliance evidence.\nUse SaltStack to automate security configuration, STIG compliance validation, and remediation.\nDevelop and maintain Salt states, pillars, formulas, orchestration workflows, and related configuration artifacts.\nImplement automated checks that identify deviations from approved SQL Server and infrastructure security baselines.\nAutomate remediation of approved configuration findings while preserving operational stability.\nIntegrate SaltStack automation with reporting, monitoring, ITSM, and security-management processes.\nTest SaltStack changes in controlled environments before production implementation.\nTroubleshoot Salt execution, agent, connectivity, configuration, and remediation failures.\nMaintain SaltStack code, documentation, dependencies, and version-control practices.\nContinuously monitor the security and compliance posture of SQL Server and supporting infrastructure.\nDetect configuration drift from approved security baselines and operational standards.\nInvestigate the source and potential impact of unauthorized or unexpected configuration changes.\nImplement automated alerts, validation checks, and remediation workflows for identified drift.\nDifferentiate legitimate approved changes from unauthorized or noncompliant configurations.\nTrack findings, remediation status, exceptions, and recurring compliance issues.\nRecommend preventive controls when repeated configuration drift is identified.\nSupport regulated production environments through consistent monitoring and evidence collection.\nDevelop security and compliance dashboards that provide visibility into baseline status, findings, remediation, exceptions, and trends.\nProduce recurring reports covering SQL Server security posture, configuration drift, patch status, and remediation progress.\nGenerate audit artifacts demonstrating control implementation, automated validation, approvals, and remediation activities.\nMaintain clear traceability between technical findings and applicable security requirements.\nSupport security assessments, internal reviews, external audits, and compliance-validation activities.\nPresent technical security information clearly to engineering, cybersecurity, audit, and leadership stakeholders.\nEnsure reporting is accurate, repeatable, and supported by verifiable technical evidence.\nSupport automation for highly available and resilient SQL Server platforms in coordination with database and platform engineers.\nAutomate configuration and validation activities for SQL Server high-availability environments.\nEnsure automation workflows account for clustered, replicated, or redundant system components.\nSupport patching and upgrade processes designed to minimize service interruptions.\nDevelop automated health checks and post-change validation for resilient SQL Server platforms.\nAssist with recovery, failover, rollback, and continuity testing.\nDocument high-availability dependencies, automation sequences, validation procedures, and recovery requirements.\nCollaborate with technical teams to improve the reliability and recoverability of database platforms.\n\nRequired Qualifications\n\nMinimum 6 years of hands-on experience in enterprise infrastructure automation and security engineering supporting production environments.\nAdvanced proficiency with PowerShell scripting for infrastructure automation, database administration, security enforcement, and configuration management.\nHands-on experience designing and implementing automation workflows using VMware Aria Automation or vRealize Automation.\nExperience integrating automation workflows with IT service-management platforms for approvals, change tracking, execution records, and auditability.\nDemonstrated experience securing Microsoft SQL Server environments through automated security hardening and baseline enforcement.\nHands-on experience applying and maintaining STIGs or equivalent hardened security baselines.\nExperience authoring and tailoring organization-specific SQL Server STIGs aligned with NIST SP 800-53 Revision 5 controls.\nHands-on experience using SaltStack to implement automated compliance validation, configuration enforcement, and remediation.\nExperience designing automation for SQL Server provisioning, configuration, patching, and upgrades.\nExperience identifying and remediating configuration drift within regulated production environments.\nExperience creating security reports, compliance dashboards, control evidence, and audit artifacts.\nUnderstanding of Microsoft SQL Server security, including authentication, authorization, privileged access, encryption, auditing, and secure configuration.\nExperience supporting high-availability, resiliency, or recovery requirements for enterprise database platforms.\nStrong understanding of infrastructure-as-code, configuration-management, and automation principles.\nStrong troubleshooting, analytical, documentation, and problem-solving skills.\nAbility to communicate automation and cybersecurity concepts to technical and nontechnical audiences.\nAbility to collaborate effectively with database, infrastructure, cybersecurity, platform engineering, service-management, and audit teams.\n\nPreferred Qualifications\nBachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Systems, Engineering, or a related discipline.\nExperience administering or automating Microsoft SQL Server in large-scale enterprise environments.\nExperience with SQL Server high-availability technologies such as Always On Availability Groups or failover clustering.\nExperience with source-control and collaborative development platforms such as Git.\nExperience with automated testing, code review, release management, and CI/CD practices for infrastructure automation.\nFamiliarity with REST APIs, JSON, and integration development.\nExperience integrating VMware Aria Automation, SaltStack, PowerShell, and ITSM platforms.\nFamiliarity with vulnerability-management and security-scanning technologies.\nKnowledge of NIST cybersecurity controls, risk-management practices, and continuous monitoring.\nExperience supporting government, healthcare, financial services, defense, or another highly regulated environment.\nExperience preparing technical documentation and evidence for formal security-control assessments.\nFamiliarity with cloud or hybrid infrastructure automation.\nExperience developing operational and security metrics for executive dashboards.\n\nPreferred Certifications\n\nMicrosoft Certified: Windows Server Hybrid Administrator Associate\nMicrosoft Certified: Azure Database Administrator Associate\nVMware Certified Professional, Cloud Management and Automation\nVMware Aria Automation certification or relevant VMware credential\nCompTIA Security+\nCertified Information Systems Security Professional\nGIAC Security Essentials\nMicrosoft SQL Server certification\nSaltStack or enterprise configuration-management certification\nRelevant PowerShell, infrastructure automation, cybersecurity, or DevSecOps certification\n\nAbout Varmoda\n\nVarmoda is a federal IT solutions provider founded in 2020 and headquartered in McLean, Virginia, delivering citizen-centric public services across Financial Assistance, Public Benefits, and Security & Defense domains. Our five-layer architecture — Salesforce (Engagement), Databricks (Data), ServiceNow (Orchestration), Pega (Decisioning), and Oracle HR (Capacity) — puts data at the common thread of every solution we build for federal agencies and the citizens they serve. Varmoda holds CMMI Maturity Level 3, ISO 9001, ISO 20000, and ISO 27001 certifications, and is recognized as a V3 veteran-friendly employer.\n\nWhy Varmoda\n\nGrowth opportunity within a fast-scaling federal IT firm\nDirect impact on citizen-facing federal programs\nCompetitive benefits including 401k, health insurance, Paid Time Off, Life Insurance and others — customize per role/location\nVeteran-friendly (V3) workplace culture","company":"Varmoda Tech","rawCompany":"varmoda tech","city":"McLean","state":"VA","isRemote":false,"isActive":false,"createdAt":"2026-10-02T09:03:03.150Z","occupations":[{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1244.00","title":"Network and Computer Systems Administrators","slug":"network-and-computer-systems-administrators"},{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Automation & Security Engineer","description":"Varmoda is seeking an experienced Senior Infrastructure Automation & SQL Security Engineer to design and implement secure automation frameworks for enterprise infrastructure and Microsoft SQL Server environments. This role will automate database provisioning, configuration, patching, upgrades, security enforcement, compliance validation, and remediation across regulated production environments.\n\nThe ideal candidate will bring strong expertise in PowerShell, VMware Aria Automation, SaltStack, Microsoft SQL Server security, STIG implementation, and IT service-management integrations. This individual will collaborate with database, infrastructure, security, and platform engineering teams to improve automation, strengthen compliance, reduce configuration drift, and support highly available SQL Server platforms.\n\nKey Responsibilities\n\nDesign, develop, implement, and maintain automation frameworks supporting Microsoft SQL Server provisioning, configuration, patching, and upgrades.\nAutomate repeatable infrastructure and database administration processes to improve consistency, reliability, and operational efficiency.\nDevelop reusable automation components, scripts, templates, and workflows that support enterprise production environments.\nEstablish automation standards covering error handling, logging, validation, reporting, recovery, and maintainability.\nEvaluate existing manual and automated processes and recommend opportunities for optimization.\nEnsure automation solutions align with approved infrastructure, database, security, and operational standards.\nMaintain technical documentation for automation frameworks, dependencies, configurations, and operating procedures.\nDevelop and maintain advanced PowerShell scripts and modules for infrastructure administration, database operations, security enforcement, and configuration management.\nBuild reusable PowerShell functions that support standardized provisioning, patching, compliance, and remediation activities.\nAutomate security configuration validation across SQL Server and supporting infrastructure.\nImplement appropriate logging, exception handling, reporting, notification, and rollback capabilities.\nTest and validate PowerShell automation before deployment into enterprise production environments.\nMaintain PowerShell code through approved source-control, code-review, and release-management processes.\nTroubleshoot script failures, environmental dependencies, authentication issues, and configuration conflicts.\nDesign, develop, implement, and maintain automation workflows using VMware Aria Automation, formerly known as vRealize Automation.\nBuild service catalog items, blueprints, templates, workflows, and orchestration components supporting infrastructure and application delivery.\nAutomate provisioning and configuration of virtual infrastructure supporting SQL Server and related enterprise platforms.\nIntegrate VMware Aria Automation with configuration-management, security, monitoring, and IT service-management solutions.\nMaintain reusable deployment patterns that support consistency across development, testing, staging, and production environments.\nTroubleshoot workflow execution, provisioning, integration, and platform-configuration issues.\nDocument VMware Aria Automation architecture, workflows, dependencies, and support procedures.\nIntegrate automation workflows with IT service-management platforms to support approvals, change tracking, implementation evidence, and auditability.\nAutomate the creation and updating of incidents, service requests, change records, tasks, and configuration information where appropriate.\nEnsure automated deployments and remediation activities follow established change-management and release-governance requirements.\nMaintain traceability between automation executions, approvals, configuration changes, remediation activities, and resulting system states.\nImplement controls that prevent unapproved or unauthorized infrastructure changes.\nSupport audit requests by producing records of approvals, automation executions, changes, and validation results.\nCollaborate with service-management teams to improve workflow integration and operational reporting.\nImplement and maintain Microsoft SQL Server security hardening aligned with applicable STIGs and organizational security baselines.\nAutomate the evaluation and enforcement of SQL Server security configurations.\nReview database settings, authentication, authorization, permissions, encryption, auditing, network connectivity, and privileged access.\nIdentify security gaps and implement approved remediation measures.\nDevelop and maintain organization-specific SQL Server security baselines.\nSupport the interpretation and application of security controls across SQL Server environments.\nCollaborate with database administrators, cybersecurity professionals, and platform engineers to address security findings.\nValidate that security changes do not adversely affect application functionality, availability, or performance.\nSTIG and Security Baseline Engineering\nApply, maintain, and automate STIGs or equivalent hardened security baselines across Microsoft SQL Server and supporting infrastructure.\nAuthor and tailor organization-specific SQL Server STIG requirements aligned with NIST SP 800-53 Revision 5 controls.\nTranslate security requirements into technical checks, configuration rules, automated enforcement, and validation criteria.\nMaintain mappings among security controls, technical requirements, automation rules, findings, and remediation evidence.\nReview security baseline updates and evaluate their effect on existing automation and production systems.\nDevelop exceptions or compensating-control documentation when approved configurations cannot be implemented as written.\nSupport security reviews, control assessments, vulnerability-management activities, and audit preparation.\nMaintain baseline documentation, implementation guidance, testing procedures, and compliance evidence.\nUse SaltStack to automate security configuration, STIG compliance validation, and remediation.\nDevelop and maintain Salt states, pillars, formulas, orchestration workflows, and related configuration artifacts.\nImplement automated checks that identify deviations from approved SQL Server and infrastructure security baselines.\nAutomate remediation of approved configuration findings while preserving operational stability.\nIntegrate SaltStack automation with reporting, monitoring, ITSM, and security-management processes.\nTest SaltStack changes in controlled environments before production implementation.\nTroubleshoot Salt execution, agent, connectivity, configuration, and remediation failures.\nMaintain SaltStack code, documentation, dependencies, and version-control practices.\nContinuously monitor the security and compliance posture of SQL Server and supporting infrastructure.\nDetect configuration drift from approved security baselines and operational standards.\nInvestigate the source and potential impact of unauthorized or unexpected configuration changes.\nImplement automated alerts, validation checks, and remediation workflows for identified drift.\nDifferentiate legitimate approved changes from unauthorized or noncompliant configurations.\nTrack findings, remediation status, exceptions, and recurring compliance issues.\nRecommend preventive controls when repeated configuration drift is identified.\nSupport regulated production environments through consistent monitoring and evidence collection.\nDevelop security and compliance dashboards that provide visibility into baseline status, findings, remediation, exceptions, and trends.\nProduce recurring reports covering SQL Server security posture, configuration drift, patch status, and remediation progress.\nGenerate audit artifacts demonstrating control implementation, automated validation, approvals, and remediation activities.\nMaintain clear traceability between technical findings and applicable security requirements.\nSupport security assessments, internal reviews, external audits, and compliance-validation activities.\nPresent technical security information clearly to engineering, cybersecurity, audit, and leadership stakeholders.\nEnsure reporting is accurate, repeatable, and supported by verifiable technical evidence.\nSupport automation for highly available and resilient SQL Server platforms in coordination with database and platform engineers.\nAutomate configuration and validation activities for SQL Server high-availability environments.\nEnsure automation workflows account for clustered, replicated, or redundant system components.\nSupport patching and upgrade processes designed to minimize service interruptions.\nDevelop automated health checks and post-change validation for resilient SQL Server platforms.\nAssist with recovery, failover, rollback, and continuity testing.\nDocument high-availability dependencies, automation sequences, validation procedures, and recovery requirements.\nCollaborate with technical teams to improve the reliability and recoverability of database platforms.\n\nRequired Qualifications\n\nMinimum 6 years of hands-on experience in enterprise infrastructure automation and security engineering supporting production environments.\nAdvanced proficiency with PowerShell scripting for infrastructure automation, database administration, security enforcement, and configuration management.\nHands-on experience designing and implementing automation workflows using VMware Aria Automation or vRealize Automation.\nExperience integrating automation workflows with IT service-management platforms for approvals, change tracking, execution records, and auditability.\nDemonstrated experience securing Microsoft SQL Server environments through automated security hardening and baseline enforcement.\nHands-on experience applying and maintaining STIGs or equivalent hardened security baselines.\nExperience authoring and tailoring organization-specific SQL Server STIGs aligned with NIST SP 800-53 Revision 5 controls.\nHands-on experience using SaltStack to implement automated compliance validation, configuration enforcement, and remediation.\nExperience designing automation for SQL Server provisioning, configuration, patching, and upgrades.\nExperience identifying and remediating configuration drift within regulated production environments.\nExperience creating security reports, compliance dashboards, control evidence, and audit artifacts.\nUnderstanding of Microsoft SQL Server security, including authentication, authorization, privileged access, encryption, auditing, and secure configuration.\nExperience supporting high-availability, resiliency, or recovery requirements for enterprise database platforms.\nStrong understanding of infrastructure-as-code, configuration-management, and automation principles.\nStrong troubleshooting, analytical, documentation, and problem-solving skills.\nAbility to communicate automation and cybersecurity concepts to technical and nontechnical audiences.\nAbility to collaborate effectively with database, infrastructure, cybersecurity, platform engineering, service-management, and audit teams.\n\nPreferred Qualifications\nBachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Systems, Engineering, or a related discipline.\nExperience administering or automating Microsoft SQL Server in large-scale enterprise environments.\nExperience with SQL Server high-availability technologies such as Always On Availability Groups or failover clustering.\nExperience with source-control and collaborative development platforms such as Git.\nExperience with automated testing, code review, release management, and CI/CD practices for infrastructure automation.\nFamiliarity with REST APIs, JSON, and integration development.\nExperience integrating VMware Aria Automation, SaltStack, PowerShell, and ITSM platforms.\nFamiliarity with vulnerability-management and security-scanning technologies.\nKnowledge of NIST cybersecurity controls, risk-management practices, and continuous monitoring.\nExperience supporting government, healthcare, financial services, defense, or another highly regulated environment.\nExperience preparing technical documentation and evidence for formal security-control assessments.\nFamiliarity with cloud or hybrid infrastructure automation.\nExperience developing operational and security metrics for executive dashboards.\n\nPreferred Certifications\n\nMicrosoft Certified: Windows Server Hybrid Administrator Associate\nMicrosoft Certified: Azure Database Administrator Associate\nVMware Certified Professional, Cloud Management and Automation\nVMware Aria Automation certification or relevant VMware credential\nCompTIA Security+\nCertified Information Systems Security Professional\nGIAC Security Essentials\nMicrosoft SQL Server certification\nSaltStack or enterprise configuration-management certification\nRelevant PowerShell, infrastructure automation, cybersecurity, or DevSecOps certification\n\nAbout Varmoda\n\nVarmoda is a federal IT solutions provider founded in 2020 and headquartered in McLean, Virginia, delivering citizen-centric public services across Financial Assistance, Public Benefits, and Security & Defense domains. Our five-layer architecture — Salesforce (Engagement), Databricks (Data), ServiceNow (Orchestration), Pega (Decisioning), and Oracle HR (Capacity) — puts data at the common thread of every solution we build for federal agencies and the citizens they serve. Varmoda holds CMMI Maturity Level 3, ISO 9001, ISO 20000, and ISO 27001 certifications, and is recognized as a V3 veteran-friendly employer.\n\nWhy Varmoda\n\nGrowth opportunity within a fast-scaling federal IT firm\nDirect impact on citizen-facing federal programs\nCompetitive benefits including 401k, health insurance, Paid Time Off, Life Insurance and others — customize per role/location\nVeteran-friendly (V3) workplace culture","datePosted":"2026-10-02T09:03:03.150Z","dateModified":"2026-10-02T09:03:03.150Z","hiringOrganization":{"@type":"Organization","name":"Varmoda Tech","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"McLean","addressRegion":"VA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"e8cdc10c8f81bb8f4e53b08f"},"url":"https://jobsearcher.com/jobs/e8cdc10c8f81bb8f4e53b08f"}}