OS Image Factory Engineer (R-00195)

Socket.dev

United States

Remote

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive salary
Excellent medical coverage
401k with company match
PTO + 11 paid holidays
Phone & home internet stipend
Parental leave
Training and certifications

Job summary

True Zero Technologies is seeking an OS image factory engineer to design, build, and maintain standardized images for RHEL and Windows. You will implement automated pipelines, enforce security through STIGs, and ensure artifact governance across the software supply chain.

Work in a governed environment (AWS GovCloud) with OpenSCAP validation, image signing, and attestation to support Zero Trust requirements. Strong collaboration with platform, cloud, and cybersecurity teams is essential.

Qualifications

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or related.
  • Experience with OS image engineering for RHEL and Windows.
  • Hands-on experience with container image creation, management, scanning and lifecycle.
  • Experience with EC2 Image Builder, Packer, or similar image automation tools.
  • Strong CI/CD experience for infrastructure artifacts.
  • Hands-on Ansible for config management and automation.
  • Experience integrating vulnerability scanning and policy enforcement.
  • Experience with DISA STIG hardening and OpenSCAP validation.
  • Knowledge of FIPS-enabled configurations.
  • Experience with image signing and attestation in a software supply chain.

Responsibilities

  • Design, build, and maintain standardized OS images for RHEL and Windows.
  • Develop and manage container image build, validation, and lifecycle processes.
  • Create automated image pipelines using EC2 Image Builder and Packer.
  • Build CI/CD pipelines for image creation, testing, security validation, and retirement.
  • Use Ansible for configuration management and hardening.
  • Integrate vulnerability scanning and security validation into pipelines.
  • Implement DISA STIG hardening and OpenSCAP validation.
  • Produce FIPS-enabled builds where required and implement image signing.
  • Maintain image artifacts, versions, and retention policies.
  • Ensure traceability between source config, builds, and released artifacts.

Skills

OS image engineering
RHEL
Windows image
CI/CD pipelines
Ansible
Vulnerability scanning
OpenSCAP
DISA STIG
Image signing
Artifact management
AWS GovCloud
HashiCorp Packer
Security governance
Software supply chain

Education

Bachelor’s degree in Cybersecurity/CS/IT/IS

Tools

EC2 Image Builder
HashiCorp Packer
OpenSCAP
DISA STIG validation
Image signing tooling

Job description

True Zero Technologies, a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the quality of its outcomes. True Zero recognizes that those outcomes begin and end with our people, and that is what we have built a community of like-minded, driven, and passionate individuals and innovators who are aligned in a common goal of delivering top-tier services to our customers. Our culture and commitment have been recognized through numerous accolades, including being named one of the Best Places to Work in 2023 in two categories (“Prosperous and Thriving” ($5MM–$50MM in gross revenue) and “Mid-Atlantic Region” (DC, DE, MD, NC, VA, WV)), and again in 2025 as a Best Places to Work honoree. In addition, True Zero earned coveted spots on the Inc. 5000 list of fastest-growing companies in America in 2022, 2023, and 2025, a testament to our sustained growth driven by our people-first approach and unwavering dedication to excellence.

The OS Image Factory Engineer designs, builds, and maintains a standardized image factory that produces secure, repeatable, and version-controlled operating system and container images for enterprise and government environments. The role is responsible for delivering STIG-hardened RHEL, Windows, and container images through fully automated CI/CD pipelines with integrated security scanning, policy enforcement, validation, artifact management, and lifecycle controls.

This position ensures that images are consistently built, tested, signed, promoted, maintained, and retired using approved engineering and governance processes. The engineer will support AWS GovCloud and Zero Trust requirements by incorporating DISA STIG hardening, OpenSCAP validation, FIPS-enabled configurations, image signing, and software supply chain attestation into the image creation process.

Job Responsibilities
  • Design, build, and maintain standardized OS images for RHEL and Windows environments.
  • Develop and manage container image build, validation, promotion, and lifecycle processes.
  • Build automated image pipelines using EC2 Image Builder and/or HashiCorp Packer.
  • Develop and maintain CI/CD pipelines that automate image creation, testing, security validation, approval, promotion, and retirement.
  • Use Ansible for configuration management, operating system hardening, software installation, and repeatable image configuration.
  • Integrate vulnerability scanning and security assessment tools into image build and release pipelines.
  • Implement and maintain DISA STIG-hardened configurations for supported operating systems and validate compliance using OpenSCAP or equivalent approved tooling.
  • Produce and maintain FIPS-enabled builds where required by system and security requirements.
  • Implement image signing and attestation to support Zero Trust software supply chain integrity and verification.
  • Manage image artifacts, versions, metadata, dependencies, and retention policies within approved artifact registries and repositories.
  • Establish lifecycle processes for image creation, testing, release, patching, deprecation, and retirement.
  • Enforce image governance standards, release controls, approval workflows, and configuration baselines.
  • Maintain traceability between source configuration, build pipelines, security results, image versions, and released artifacts.
  • Partner with platform, cloud, cybersecurity, and application teams to ensure image standards meet operational, compliance, and deployment requirements.
  • Develop automated tests to verify image functionality, configuration, security posture, and readiness prior to release.
  • Maintain technical documentation, build standards, operating procedures, and image-factory governance processes.
  • Continuously improve image build times, reliability, repeatability, security controls, and pipeline automation.
Job Qualifications
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related technical discipline.
  • Demonstrated experience with OS image engineering for RHEL and Windows platforms.
  • Hands-on experience with container image creation, management, scanning, and lifecycle management.
  • Experience using EC2 Image Builder, HashiCorp Packer, or comparable image automation technologies.
  • Strong experience developing and maintaining CI/CD pipelines for infrastructure or system artifacts.
  • Hands-on experience with Ansible configuration management and automation.
  • Experience integrating vulnerability scanning, compliance validation, and security policy enforcement into automated pipelines.
  • Experience implementing DISA STIG hardening and performing compliance validation using OpenSCAP or comparable technologies.
  • Understanding of FIPS-enabled operating system and application configurations.
  • Experience implementing image signing, provenance, integrity validation, and attestation within a software supply chain.
  • Experience managing artifact repositories, container registries, image versions, retention policies, and artifact promotion workflows.
  • Strong understanding of configuration management, version control, release management, and infrastructure-as-code practices.
  • Experience operating in AWS GovCloud, government, defense, or other regulated cloud environments is preferred.
  • Familiarity with Zero Trust principles, particularly software supply chain integrity, trusted artifacts, and continuous verification.
  • Strong troubleshooting, documentation, governance, and cross-functional collaboration skills.
Preferred Certifications:
  • Red Hat Certified Engineer (RHCE)
  • Red Hat Certified Specialist in Containers
  • Red Hat Certified Specialist in Ansible Automation
  • Certified Kubernetes Administrator (CKA) or Certified Kubernetes Application Developer (CKAD)
  • Microsoft Certified: Windows Server Hybrid Administrator Associate

We’re actively searching for talented security and technology practitioners who are ready to experience the True Zero difference. As a True Zero team member, you’ll enjoy:

  • Competitive salary, paid twice per month
  • Best in class medical coverage
  • 100% of medical premiums covered by True Zero
  • Company wide new business incentive programs
  • Contribution Incentives (i.e. white papers, blog posts, internal webinars, etc.)
  • 3 weeks of PTO starting + 11 Paid Holidays Annually
  • 401k Program with 100% company match on the first 4%
  • Monthly reimbursement of Cell Phone and Home Internet costs
  • Paternity/Maternity Leave
  • Investment in training and certifications to broaden and deepen your technical skills
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cloud / DevSecOps Engineer (R-00200)
Senior Cloud / DevSecOps Engineer (R-00200)

Socket.dev • United States

Remote
USD 140,000 - 210,000
Competitive salary
Medical coverage
401k match
+3
Secrets Management Platform Engineer (R-00196)
Secrets Management Platform Engineer (R-00196)

Socket.dev • United States

Remote
USD 120,000 - 180,000
Competitive salary
Medical coverage
401k with company match
+3
PKI / Certificate Management Engineer (R-00198)
PKI / Certificate Management Engineer (R-00198)

Socket.dev • United States

Remote
USD 140,000 - 190,000
Competitive salary
Medical coverage
401k program
+1
Identity Management Engineer / Architect (R-00197)
Identity Management Engineer / Architect (R-00197)

Socket.dev • United States

Remote
USD 120,000 - 180,000
Competitive salary
Best medical coverage
Premium medical premiums covered by us
+3
Cloud Migration Engineer / Architect (R-00199)
Cloud Migration Engineer / Architect (R-00199)

Socket.dev • United States

Remote
USD 120,000 - 170,000
Competitive salary
Medical coverage
401k with company match
+2
AWS Workspaces SME (R-00225)
AWS Workspaces SME (R-00225)

Truezerotech • United States

On-site
USD 120,000 - 170,000
Competitive salary
Best in class medical coverage
100% medical premiums covered by True0
+7
OS Image Factory Engineer: Build Secure, Automated Images
OS Image Factory Engineer: Build Secure, Automated Images

Socket.dev • United States

Remote
USD 120,000 - 180,000
Competitive salary
Excellent medical coverage
401k with company match
+4
Security Engineer – Lead (R-00161)
Security Engineer – Lead (R-00161)

True Zero Technologies • Arlington (VA)

On-site
USD 100,000 - 140,000
Competitive salary
Best in class medical coverage
100% of medical premiums covered
+3
Endpoint Engineer - AI Desktop Deployment (R-00193)
Endpoint Engineer - AI Desktop Deployment (R-00193)

Socket.dev • United States

Remote
USD 120,000 - 160,000
Competitive compensation
Best-in-class medical coverage
401k with company match
+2
Elastic Engineer with TS Clearance (R-00056)
Elastic Engineer with TS Clearance (R-00056)

True Zero Technologies • Las Vegas (NM)

On-site
USD 110,000 - 150,000
Competitive salary
Best in class medical coverage
100% of medical premiums covered
+3