SQL Server Security & Database Hardening Consultant
Position Overview
We are seeking an experienced SQL Server Security & Database Hardening Consultant to lead a comprehensive security assessment, hardening, and remediation initiative across an enterprise Microsoft SQL Server environment. The consultant will evaluate current database security posture, identify vulnerabilities and operational risks, recommend corrective actions, and support implementation efforts to improve overall security, compliance, and administrative governance.
This role requires deep expertise in Microsoft SQL Server security, database administration best practices, patching, encryption, auditing, access management, and remediation planning. The ideal candidate will be capable of working collaboratively with infrastructure, cybersecurity, application, and operations teams to deliver practical and prioritized recommendations aligned with agency operational constraints and business needs.
Key Responsibilities
SQL Server Security Assessment & Hardening
Conduct comprehensive security assessments of Microsoft SQL Server environments, including production and development instances.
Review SQL Server authentication, authorization, and administrative access controls.
Evaluate least-privilege implementation, service account usage, and role-based access governance.
Assess SQL Server attack surface and identify unnecessary features, services, protocols, or insecure configurations.
Recommend and support implementation of SQL Server hardening standards and security best practices.
Patch & Vulnerability Management
Review SQL Server versions, editions, cumulative updates, service packs, and patch levels.
Identify unsupported or vulnerable SQL Server components and provide remediation recommendations.
Perform or facilitate SQL vulnerability assessments using approved or native tools.
Develop prioritized remediation roadmaps for high- and medium-risk findings.
Advise on sustainable patch governance and ongoing vulnerability management practices.
Encryption & Data Protection
Assess protections for data at rest and data in transit.
Evaluate implementation feasibility for Transparent Data Encryption (TDE), SSL/TLS encryption, and Always Encrypted technologies.
Identify application compatibility considerations and operational dependencies related to encryption initiatives.
Recommend best practices for securing sensitive or regulated data.
Auditing, Monitoring & Recovery
Review SQL Server auditing, monitoring, and logging configurations.
Evaluate capabilities for detecting failed logins, privilege escalations, schema changes, and suspicious activity.
Assess backup security controls, backup encryption, restore testing, and recovery validation processes.
Recommend sustainable monitoring and operational support practices.
Governance & Operational Support
Review separation of duties and privileged access governance across database administration and application support functions.
Identify risks related to insufficient DBA operational support or administrative ownership gaps.
Collaborate with agency stakeholders, infrastructure teams, cybersecurity personnel, and application owners.
Support remediation activities, configuration validation, documentation, and knowledge transfer sessions.
Required Qualifications
8+ years of experience administering and securing Microsoft SQL Server environments.
Strong expertise in SQL Server security, hardening, patch management, auditing, and encryption technologies.
Experience conducting security assessments and remediation planning for enterprise database environments.
Deep understanding of:
o SQL Server authentication and authorization
o SQL Server Audit and Extended Events
o Transparent Data Encryption (TDE)
o SSL/TLS configuration
o Service account management
o SQL Server vulnerability assessment tools
o Backup and recovery security practices
Experience working with Windows Server and Active Directory environments.
Strong knowledge of database governance, compliance, and least-privilege principles.
Ability to develop technical documentation, risk assessments, and executive-level reporting.
Strong communication and stakeholder coordination skills.
Preferred Qualifications
Experience supporting public sector or government environments.
Familiarity with Archibus or enterprise facilities management platforms.
Experience with Policy-Based Management and SQL Server configuration automation.
Knowledge of cybersecurity frameworks and regulatory compliance standards.
Microsoft SQL Server certifications or related cybersecurity certifications preferred.
By continuing you agree to our Terms & Privacy Policy.