Senior Platform / DevSecOps + Security Engineer
ARCHIVED
We can't find an active application page for this role right now. It may reopen or be listed elsewhere. Use Next Steps to search for an active apply link and similar live jobs.
Location: RemoteClearance: Active DoD Secret clearance requiredEmployment Type: Full-Time (W-2)Citizenship: U.S. Citizenship requiredIntelliTech is seeking a Senior Platform / DevSecOps + Security Engineer to lead the infrastructure modernization, security hardening, authorization pathway, and production promotion of a Government-owned digital twin application deployed in an Army cloud environment. The application is a supply chain simulation platform built on Python, FastAPI, React, and MongoDB and currently operates as a monolithic Docker deployment. This role will help transition it into a production-grade, containerized, split-service architecture aligned to Army cloud platform requirements, DevSecOps delivery practices, and production promotion gates.This is a hands-on role on a lean, senior team. The ideal candidate will architect deployment infrastructure, build CI/CD pipelines, harden the application for production, support authorization evidence development, and help lead promotion from development through production. This individual will work directly with Army platform teams, security stakeholders, and identity management teams to ensure the application is secure, scalable, supportable, and ready for operational use.Key ResponsibilitiesInfrastructure and Deployment ArchitectureTransition the application from a single-host Docker deployment to a split-service containerized architecture using Amazon EKS, ECS, or another approved orchestration modelDesign and implement multi-tier environment separation across development, test/staging, and productionPackage frontend, backend API, and simulation worker services as independently deployable container artifactsImplement infrastructure-as-code using Terraform, CloudFormation, or approved equivalents for repeatable provisioning and configuration managementDesign the distributed execution model allowing simulation workers to scale independently from the API tier with bounded concurrency and isolation controlsConfigure managed platform services for persistence, caching, object storage, secrets management, and observabilityCI/CD and Release EngineeringBuild and maintain CI/CD pipelines using approved toolchains such as GitLab CI, GitHub Actions, or government-provided platform toolingIntegrate automated build, test, container scanning, dependency scanning, SAST, and DAST into the delivery pipelineImplement promotion workflows with quality and security gates for development-to-staging and staging-to-production transitionsGenerate and maintain software bill of materials (SBOM) and dependency inventories as part of the build processDesign rollback and recovery procedures for failed deployments, including restoration of prior known-good versionsSecurity Hardening and ComplianceHarden container images and dependency baselines in alignment with STIG requirements and approved security standardsImplement managed secrets storage, encryption in transit and at rest, least-privilege IAM policies, and appropriate network segmentationIntegrate vulnerability scanning into release workflows and support remediation trackingSupport closure of security findings through remediation, compensating controls, and evidence updatesEnsure artifact retention and traceability sufficient to support promotion approval and auditabilityIdentity and Access ManagementIntegrate the application with CAC-enabled SSO and the identity provider required by the target environment using SAML, OIDC, or platform-specific approachesReplace local account models with externalized authentication through approved identity servicesImplement role-based access controls for analyst, administrator, and system functionsEnsure user actions are traceable to authenticated identitiesAuthorization and Production PromotionSupport the application-specific authorization effort from evidence planning through submission and remediationProduce and maintain authorization artifacts such as architecture diagrams, data flows, SBOMs, scan evidence, logging and monitoring descriptions, and operational runbooksAlign evidence to the platform’s inheritance model where applicable rather than building a fully standalone compliance packageCoordinate with government security stakeholders on evidence expectations, findings, and remediationLead technical execution for promotion from development into production through approved DevSecOps pipelines and release gatesOperations and SustainmentImplement centralized logging, metrics, alarms, and service health monitoring across all application componentsDevelop operational runbooks for deployment, monitoring, incident response, scaling, and maintenanceProduce administrator and operator documentation, troubleshooting guides, and sustainment handoff materialsSupport training and transition activities at the conclusion of the implementation periodRequired QualificationsBachelor’s degree in Computer Science, Information Systems, Engineering, Cybersecurity, or a related technical discipline and 8+ years of relevant experience; or Master’s degree in a related field and 6+ years of relevant experienceActive DoD Secret clearance8+ years of professional experience in DevOps, platform engineering, infrastructure engineering, or cloud engineering rolesHands-on experience supporting ATO or cATO-related processes, including authorization evidence development, security findings remediation, and working with assessors or platform security stakeholdersExperience deploying and operating applications in DoD or other accredited government cloud environments such as Army ECMAStrong experience with container orchestration using Amazon EKS, ECS, Kubernetes, or similar platformsStrong experience with infrastructure as code, including Terraform, CloudFormation, Helm, or similar toolingExperience designing and maintaining CI/CD pipelines with integrated automated testing, scanning, and promotion controlsExperience with security hardening, including STIG-aligned practices, vulnerability remediation, SBOM generation, and secure container/image managementExperience with AWS services such as EC2, EKS/ECS, S3, IAM, KMS, Secrets Manager, SSM, CloudWatch, VPC/networking, Redis/ElastiCache, and document or relational persistence servicesExperience integrating identity and access management solutions such as SSO, SAML, OIDC, RBAC, or CAC-enabled access patternsStrong communication skills and the ability to work directly with technical, operational, and security stakeholdersPreferred QualificationsDirect experience supporting Army cloud environments or similar government-managed enterprise cloud platformsExperience with RMF, eMASS, and inherited authorization modelsExperience operating in IL4 / IL5 or similarly regulated environmentsExperience with container security and vulnerability scanning tools such as Prisma Cloud, Anchore, Twistlock, or similar platformsFamiliarity with Docker Compose to Kubernetes migration patternsExperience with MongoDB to DocumentDB migration or similar managed database transition effortsExperience supporting Python / FastAPI application deployment and performance tuningPrior experience supporting Army, logistics, manufacturing, industrial base, or enterprise platform modernization programsCertifications such as Security+, CISSP, or relevant cloud / Kubernetes certificationsTech StackOrchestration: Amazon EKS or ECS, Kubernetes, HelmIaC: Terraform, CloudFormationCI/CD: GitLab CI, GitHub Actions, or government-approved toolingCloud: AWS services including EC2, EKS/ECS, S3, IAM, KMS, Secrets Manager, SSM, CloudWatch, Redis/ElastiCache, and managed persistence servicesContainers: Docker, multi-stage builds, hardened base imagesSecurity: STIG-aligned hardening, vulnerability scanning, SBOM generation, DAST / SASTIdentity: CAC / SSO, SAML, OIDC, RBACMonitoring: CloudWatch, Prometheus / Grafana where approved, centralized loggingAuthorization: RMF, eMASS, inherited authorization packages, ATO / cATO evidence supportApplication: Python 3.11+, FastAPI, React, MongoDB / DocumentDBInterview ProcessVideo interview required and may include a technical assessment.Candidates should be prepared to discuss:their experience designing and operating secure cloud infrastructure and CI/CD pipelineshow they have supported authorization, compliance, or security evidence effortsexamples of applications they have containerized, hardened, and promoted to productiontheir experience with AWS, Kubernetes, IaC, scanning, and release automationhow they have handled identity integration, observability, and secure operations in regulated environmentsCompensation And BenefitsIntelliTech is committed to fair and equitable compensation practices. Actual compensation packages are based on several factors unique to each candidate, including but not limited to job-related skills, depth of experience, relevant certifications and training, and specific work location. Based on these factors, IntelliTech utilizes the full width of the salary range.IntelliTech provides a comprehensive benefits package designed to support employees’ well-being and professional growth, including health, dental, and vision insurance, a 401(k), paid time off, professional development opportunities, and flexible work arrangements to support work-life balance.About IntelliTechIntelliTech is a dynamic and forward-thinking small business specializing in Full Stack Engineering, Data Analytics, Cloud Solutions, and DevSecOps services. Our mission is to empower government and commercial clients to solve complex technical challenges through practical, innovative, and mission-focused engineering solutions.Equal Opportunity EmployerAt IntelliTech, we are committed to building a diverse and inclusive workplace. We believe that a variety of perspectives and backgrounds leads to stronger teams and better solutions. IntelliTech is an Equal Opportunity Employer and does not discriminate on the basis of race, religion, gender, age, disability, or veteran status. We encourage all qualified candidates to apply.Powered by JazzHRBGSBAyZq6V