Knox Systems
SecDevOps Engineer (Mid-Level 3)
United States | Arlington, VA · Mid · Contract
No sponsorship$53k-$800kDetected 20 days ago
PythonBashPowerShellGitAWSGCPAzureCloud PlatformsDockerKubernetesTerraformAnsibleHelmCI/CDGitHub ActionsPrometheusGrafanaDevOpsCybersecurityComplianceZero TrustArgo CDCompTIA
About the role
- Day-to-day, the work centers on Zero Trust access, continuous monitoring, cloud security posture, and observability - keeping secure, compliant, and repeatable operations running across federal cloud environments.
- The ideal candidate combines hands-on cloud architecture experience, automation expertise, and a deep security-operations mindset.
- This role bridges the gap between core cloud engineering and rigorous federal compliance, embedding security controls directly into the deployment fabric using Infrastructure as Code (IaC) and Policy-as-Code frameworks.
Responsibilities
- Manage privileged credentials, API tokens, and secrets lifecycle using HashiCorp Vault, establishing automated credential flows and programmatic rotation.
- Integrate and maintain federated identity providers (Okta, Azure AD / Entra ID, AWS IAM Identity Center) and actively support ongoing multi-cloud identity migrations.
- Build and manage multi-tenant infrastructure across AWS, Azure, and GCP using Infrastructure as Code (Terraform primary; Ansible and CloudFormation as needed).
- Manage cloud networking, IAM topologies, and security group configurations tailored strictly to FedRAMP controls and Impact Level 4 (IL4) boundaries.
- Develop and maintain secure CI/CD pipelines utilizing GitHub Actions, GitLab CI, Azure DevOps, or Jenkins.
- Build, deploy, and troubleshoot containerized workloads within managed Kubernetes environments (EKS, AKS, GKE) using Helm, ArgoCD, or Kustomize.
- Support FedRAMP Continuous Monitoring (ConMon) cycles, managing incident tickets, Plan of Action and Milestones (POA&M) tracking, and technical remediation follow-through.
- Maintain IaC, pipeline architectures, and operating configurations compliant with FedRAMP and NIST 800-53 standards.
- Deploy and maintain centralized dashboards, alert definitions, log aggregation, and metrics/APM architectures using Grafana, Prometheus, or cloud-native tooling.
Requirements
- Any offer of employment is contingent upon the successful completion of all required pre-employment screenings, including a background check, in accordance with applicable laws and government contract requirements.
- Your contributions are visible, your expertise is relied upon, and the impact of your work is immediate and measurable.
- Candidates must be able to provide documentation verifying sole U.S. citizenship status as part of the background check process.
- Identity & Secrets: Practical experience managing enterprise identity/access tooling (Okta, Entra ID) and secrets management platforms (HashiCorp Vault, AWS KMS, or Azure Key Vault).
- Security Tooling: Familiarity operating endpoint protection (EDR), cloud security posture management (CSPM), or vulnerability scanning platforms (e.g., CrowdStrike, Wiz, Qualys).
- Containers: Experience building, configuring, and troubleshooting containerized environments (Docker, Kubernetes).
- Compliance Alignment: A strong conceptual or practical understanding of FedRAMP, NIST 800-53, or SOC 2 compliance frameworks.
- HashiCorp Certified: Terraform Associate
- AWS Certified SysOps Administrator or Solutions Architect (Associate)
- CompTIA Security+ or equivalent security credential
- Microsoft Certified: Azure Administrator Associate
Nice to have
- Hands-on production experience with at least one major hyperscaler (AWS preferred), with functional exposure to Azure and/or GCP environments.
- High proficiency in Terraform and robust scripting capabilities (Python, Bash, or PowerShell)
- familiarity with Ansible is preferred.
- Cloud Infrastructure: Hands-on production experience with at least one major hyperscaler (AWS preferred), with functional exposure to Azure and/or GCP environments.
- Automation & Scripting: High proficiency in Terraform and robust scripting capabilities (Python, Bash, or PowerShell)
Skills
- 3-5 years of dedicated professional experience in SecDevOps, Cloud Security Engineering, DevOps, or Platform Engineering.
- A strong conceptual or practical understanding of FedRAMP, NIST 800-53, or SOC 2 compliance frameworks.
Compensation
- $53k-$800k
Benefits
- Knox offers a competitive employee benefits package including Medical, Dental, Vision, Life & Disability, unlimited PEO, and an employee funded 401k plan.
- Please note, benefits are subject to change.
- Employment decisions are made without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, veteran status, or any other legally protected status.
- Benefits & Perks
Equal opportunity
- We are an Equal Opportunity Employer.
Visa & Work Authorization
- citizenship
Apply directly at Knox Systems →Create a free account for alerts like thisView Knox Systems immigration profile
This listing is sourced directly from Knox Systems's careers page and normalized into a canonical job model.