The candidate must have proven experience in regulated, enterprise environments with change control, patching, and lifecycle processes; be proficient in automation (Ansible; Chef knowledge desirable), Python/Bash scripting; and able to act as a subject matter expert for OS security, CIS hardening, and enforcement of best practices for configuration, privileges, and access management. Enterprise RHEL/OS security SME: Secure configuration, package/software management, auditing, performance tuning, kernel/module handling, patching, monitoring, and lifecycle management.