DevSecOps Architect
Job Title: Principal Platform / DevSecOps Architect
Place of Performance: Chantilly, VA
Employment Type: Full-Time
Experience Required: Minimum 10 years of relevant experience, including at least 8 years of AWS engineering experience
Job Summary We are seeking a Principal Platform / DevSecOps Architect to serve as a hands-on technical architect responsible for designing, building, operating, and continuously improving secure AWS-based application platforms.
The successful candidate will provide technical leadership across Kubernetes/EKS, GitLab CI/CD, GitOps, Infrastructure as Code, containerization, DevSecOps, networking, identity, security, and platform observability while developing automated, reusable, secure, and maintainable platform solutions.
Key Responsibilities Architect, operate, and troubleshoot production Kubernetes environments, primarily Amazon EKS .
Design, develop, and maintain sophisticated GitLab CI/CD pipelines and reusable pipeline templates.
Implement GitOps practices for Kubernetes applications and infrastructure.
Build and maintain secure AWS infrastructure using Infrastructure as Code (IaC) .
Develop reusable Helm charts, Kubernetes manifests, deployment patterns, and platform automation .
Support containerized applications using Docker .
Integrate security scanning, secrets management, IAM, and other DevSecOps controls into delivery pipelines.
Troubleshoot complex issues spanning applications, containers, Kubernetes, AWS, networking, certificates, and identity.
Support authentication and authorization capabilities, including:
IAM
RBAC
OAuth2/OIDC
LDAP
TLS/mTLS
Certificate-based authentication
Improve logging, monitoring, auditing, and overall platform observability .
Automate recurring operational tasks and convert manual processes into reusable platform solutions.
Develop standardized deployment, pipeline, and infrastructure templates.
Document technical solutions, operational procedures, and architecture decisions.
Mentor engineers across development, infrastructure, platform, and security teams.
Lead technical troubleshooting and resolution across multiple technology layers.
Required Qualifications Active Top Secret/SCI security clearance , with the ability to obtain and maintain a polygraph.
Minimum 10 years of experience in software engineering, cloud engineering, DevOps, DevSecOps, platform engineering, or related technical disciplines.
Minimum 8 years of AWS engineering experience .
Strong hands-on production experience with Kubernetes , preferably Amazon EKS .
Deep experience building and troubleshooting GitLab CI/CD pipelines .
Networking
IAM
Compute
Storage
Load balancing
Monitoring
Strong Docker and containerization experience.
Experience with GitOps and Infrastructure as Code .
Experience creating reusable deployment, pipeline, and infrastructure templates.
Strong Linux, networking, and command-line troubleshooting skills.
Software development or scripting experience with Python, Go, Java, Ruby, Bash, or comparable languages .
Strong understanding of:
IAM and RBAC
Authentication and authorization
TLS and certificates
DNS
HTTP
Routing
Load balancing
Ability to independently troubleshoot complex systems across multiple technology layers.
Strong technical communication, documentation, and collaboration skills.
Preferred Qualifications & Certifications Security or DevSecOps certifications .
Experience with:
Terraform
CloudFormation
Experience with Keycloak, LDAP, OAuth2/OIDC, PKI, CAC/PIV, or client-certificate authentication .
Experience with Prometheus/Grafana, CloudWatch, ELK/OpenSearch , or comparable observability platforms.
Experience integrating security scanning and compliance controls into CI/CD environments.
Experience working in regulated or security-sensitive environments .
Additional Requirements Must maintain the required Top Secret/SCI security clearance and meet applicable polygraph requirements.
#J-18808-Ljbffr