{"schemaVersion":"jobsearcher.job.v1","id":"9e8cdc5e0a6e64786b6c0f59","url":"https://jobsearcher.com/jobs/9e8cdc5e0a6e64786b6c0f59","canonicalUrl":"https://jobsearcher.com/jobs/9e8cdc5e0a6e64786b6c0f59","title":"SecDevOps Engineer","description":"About Knox\nKnox runs the largest Federal managed cloud, building and operating secure cloud and AI environments that support the U.S. government’s most critical missions — from national security and public safety to essential public services. Our customers rely on Knox to deploy production systems that meet the highest standards for security, reliability, and compliance.\n\nWork at Knox is high-impact and purpose-driven. The problems we solve are high-stakes, the expectations are high, and the results are visible. Speed, rigor, and trust matter here - because the environments we secure cannot fail. Your contributions are visible, your expertise is relied upon, and the impact of your work is immediate and measurable. We operate at federal scale, securing some of the most sensitive government environments in the country - because the systems we build must perform without fail.\nThe Role\nThe SecDevOps Engineer designs, automates, and maintains Knox’s secure cloud infrastructure and CI/CD pipelines across AWS, Azure, and GCP within our FedRAMP-authorized, multi-tenant boundaries. Day-to-day, the work centers on Zero Trust access, continuous monitoring, cloud security posture, and observability — keeping secure, compliant, and repeatable operations running across federal cloud environments.\nThe ideal candidate combines hands-on cloud architecture experience, automation expertise, and a deep security-operations mindset. This role bridges the gap between core cloud engineering and rigorous federal compliance, embedding security controls directly into the deployment fabric using Infrastructure as Code (IaC) and Policy-as-Code frameworks.\nRole Focus & Technical Matrix\nZero Trust & Identity - Zscaler (ZPA / PRA), HashiCorp Vault, Okta, Azure AD / Entra ID, AWS IAM Identity Center\nInfrastructure as Code - Terraform (Primary), Ansible, CloudFormation, GitOps (ArgoCD / Helm)\nSecurity & Compliance- FedRAMP (IL4 boundaries), NIST 800-53, Wiz, Qualys, CrowdStrike,\nOPA, HashiCorp Sentinel\nObservability & Ops- Grafana, Prometheus, CloudWatch, PagerDuty, ServiceNow (CAB / eCAB)\nKey Responsibilities\nZero Trust & Access Management\nSupport and operate Zero Trust Network Access (Zscaler ZPA / PRA) architectures including app connectors, privileged remote access, and private application access boundaries.\nManage privileged credentials, API tokens, and secrets lifecycle using HashiCorp Vault, establishing automated credential flows and programmatic rotation.\nIntegrate and maintain federated identity providers (Okta, Azure AD / Entra ID, AWS IAM Identity Center) and actively support ongoing multi-cloud identity migrations.\nEnforce strict least-privilege access models and machine-to-machine credential rotation policies across all automation systems.\nCloud Infrastructure & Secure Automation\nBuild and manage multi-tenant infrastructure across AWS, Azure, and GCP using Infrastructure as Code (Terraform primary; Ansible and CloudFormation as needed).\nAutomate end-to-end provisioning, configuration management, and environment deployment workflows via secure CI/CD and GitOps paradigms.\nManage cloud networking, IAM topologies, and security group configurations tailored strictly to FedRAMP controls and Impact Level 4 (IL4) boundaries.\nCI/CD, Policy-as-Code & Container Security\nDevelop and maintain secure CI/CD pipelines utilizing GitHub Actions, GitLab CI, Azure DevOps, or Jenkins.\nIntegrate Policy-as-Code frameworks (OPA, HashiCorp Sentinel, or Azure Policy) into pipeline gates to enforce organizational compliance before infrastructure provisioning.\nEmbed automated static application security testing (SAST), software composition analysis (SCA), and container vulnerability scans into active deployment workflows.\nBuild, deploy, and troubleshoot containerized workloads within managed Kubernetes environments (EKS, AKS, GKE) using Helm, ArgoCD, or Kustomize.\nContinuous Monitoring, Vulnerability & Compliance\nSupport FedRAMP Continuous Monitoring (ConMon) cycles, managing incident tickets, Plan of Action and Milestones (POA&M) tracking, and technical remediation follow-through.\nMaintain IaC, pipeline architectures, and operating configurations compliant with FedRAMP and NIST 800-53 standards.\nAutomate programmatic audit evidence generation for specific control requirements, including CM-2 (Baseline Configurations), CM-6 (Configuration Settings), AU-2 (Event Logging), and SC-12 (Cryptographic Key Establishment and Management).\nParticipate in formal enterprise change management processes via ServiceNow, preparing documentation for Technical Change Reviews and Change Advisory Board (CAB/eCAB) workflows.\nObservability & Incident Reliability\nDeploy and maintain centralized dashboards, alert definitions, log aggregation, and metrics/APM architectures using Grafana, Prometheus, or cloud-native tooling.\nDefine, track, and report on Service Level Indicators (SLIs) and Service Level Objectives (SLOs) for critical secure services.\nParticipate in the team's operational on-call rotation (PagerDuty), driving rapid incident resolution, root-cause analyses, and P1 war room execution.\nQualifications\nRequired Experience & Skills\nExperience: 3–5 years of dedicated professional experience in SecDevOps, Cloud Security Engineering, DevOps, or Platform Engineering.\nCloud Infrastructure: Hands-on production experience with at least one major hyperscaler (AWS preferred), with functional exposure to Azure and/or GCP environments.\nAutomation & Scripting: High proficiency in Terraform and robust scripting capabilities (Python, Bash, or PowerShell); familiarity with Ansible is preferred.\nIdentity & Secrets: Practical experience managing enterprise identity/access tooling (Okta, Entra ID) and secrets management platforms (HashiCorp Vault, AWS KMS, or Azure Key Vault).\nSecurity Tooling: Familiarity operating endpoint protection (EDR), cloud security posture management (CSPM), or vulnerability scanning platforms (e.g., CrowdStrike, Wiz, Qualys).\nContainers: Experience building, configuring, and troubleshooting containerized environments (Docker, Kubernetes).\nCompliance Alignment: A strong conceptual or practical understanding of FedRAMP, NIST 800-53, or SOC 2 compliance frameworks.\nPreferred Certifications\nHashiCorp Certified: Terraform Associate\nAWS Certified SysOps Administrator or Solutions Architect (Associate)\nCompTIA Security+ or equivalent security credential\nMicrosoft Certified: Azure Administrator Associate\nCompensation Range: $125k-$130k based on experience plus bonus potential\nHiring Requirement: Due to the nature of our work with federal government clients and compliance with applicable regulations, this position requires U.S. citizenship. Dual citizenship is not permitted for this role. Candidates must be able to provide documentation verifying sole U.S. citizenship status as part of the background check process.\nAny offer of employment is contingent upon the successful completion of all required pre-employment screenings, including a background check, in accordance with applicable laws and government contract requirements.\nBenefits & Perks\nKnox offers a competitive employee benefits package including Medical, Dental, Vision, Life & Disability, unlimited PEO, and an employee funded 401k plan. Please note, benefits are subject to change.\nWe are an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. Employment decisions are made without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, veteran status, or any other legally protected status.","company":"Knox Systems","rawCompany":"knox systems","city":"Washington","state":"DC","isRemote":false,"isActive":true,"createdAt":"2026-08-03T16:25:49.250Z","occupations":[{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"SecDevOps Engineer","description":"About Knox\nKnox runs the largest Federal managed cloud, building and operating secure cloud and AI environments that support the U.S. government’s most critical missions — from national security and public safety to essential public services. Our customers rely on Knox to deploy production systems that meet the highest standards for security, reliability, and compliance.\n\nWork at Knox is high-impact and purpose-driven. The problems we solve are high-stakes, the expectations are high, and the results are visible. Speed, rigor, and trust matter here - because the environments we secure cannot fail. Your contributions are visible, your expertise is relied upon, and the impact of your work is immediate and measurable. We operate at federal scale, securing some of the most sensitive government environments in the country - because the systems we build must perform without fail.\nThe Role\nThe SecDevOps Engineer designs, automates, and maintains Knox’s secure cloud infrastructure and CI/CD pipelines across AWS, Azure, and GCP within our FedRAMP-authorized, multi-tenant boundaries. Day-to-day, the work centers on Zero Trust access, continuous monitoring, cloud security posture, and observability — keeping secure, compliant, and repeatable operations running across federal cloud environments.\nThe ideal candidate combines hands-on cloud architecture experience, automation expertise, and a deep security-operations mindset. This role bridges the gap between core cloud engineering and rigorous federal compliance, embedding security controls directly into the deployment fabric using Infrastructure as Code (IaC) and Policy-as-Code frameworks.\nRole Focus & Technical Matrix\nZero Trust & Identity - Zscaler (ZPA / PRA), HashiCorp Vault, Okta, Azure AD / Entra ID, AWS IAM Identity Center\nInfrastructure as Code - Terraform (Primary), Ansible, CloudFormation, GitOps (ArgoCD / Helm)\nSecurity & Compliance- FedRAMP (IL4 boundaries), NIST 800-53, Wiz, Qualys, CrowdStrike,\nOPA, HashiCorp Sentinel\nObservability & Ops- Grafana, Prometheus, CloudWatch, PagerDuty, ServiceNow (CAB / eCAB)\nKey Responsibilities\nZero Trust & Access Management\nSupport and operate Zero Trust Network Access (Zscaler ZPA / PRA) architectures including app connectors, privileged remote access, and private application access boundaries.\nManage privileged credentials, API tokens, and secrets lifecycle using HashiCorp Vault, establishing automated credential flows and programmatic rotation.\nIntegrate and maintain federated identity providers (Okta, Azure AD / Entra ID, AWS IAM Identity Center) and actively support ongoing multi-cloud identity migrations.\nEnforce strict least-privilege access models and machine-to-machine credential rotation policies across all automation systems.\nCloud Infrastructure & Secure Automation\nBuild and manage multi-tenant infrastructure across AWS, Azure, and GCP using Infrastructure as Code (Terraform primary; Ansible and CloudFormation as needed).\nAutomate end-to-end provisioning, configuration management, and environment deployment workflows via secure CI/CD and GitOps paradigms.\nManage cloud networking, IAM topologies, and security group configurations tailored strictly to FedRAMP controls and Impact Level 4 (IL4) boundaries.\nCI/CD, Policy-as-Code & Container Security\nDevelop and maintain secure CI/CD pipelines utilizing GitHub Actions, GitLab CI, Azure DevOps, or Jenkins.\nIntegrate Policy-as-Code frameworks (OPA, HashiCorp Sentinel, or Azure Policy) into pipeline gates to enforce organizational compliance before infrastructure provisioning.\nEmbed automated static application security testing (SAST), software composition analysis (SCA), and container vulnerability scans into active deployment workflows.\nBuild, deploy, and troubleshoot containerized workloads within managed Kubernetes environments (EKS, AKS, GKE) using Helm, ArgoCD, or Kustomize.\nContinuous Monitoring, Vulnerability & Compliance\nSupport FedRAMP Continuous Monitoring (ConMon) cycles, managing incident tickets, Plan of Action and Milestones (POA&M) tracking, and technical remediation follow-through.\nMaintain IaC, pipeline architectures, and operating configurations compliant with FedRAMP and NIST 800-53 standards.\nAutomate programmatic audit evidence generation for specific control requirements, including CM-2 (Baseline Configurations), CM-6 (Configuration Settings), AU-2 (Event Logging), and SC-12 (Cryptographic Key Establishment and Management).\nParticipate in formal enterprise change management processes via ServiceNow, preparing documentation for Technical Change Reviews and Change Advisory Board (CAB/eCAB) workflows.\nObservability & Incident Reliability\nDeploy and maintain centralized dashboards, alert definitions, log aggregation, and metrics/APM architectures using Grafana, Prometheus, or cloud-native tooling.\nDefine, track, and report on Service Level Indicators (SLIs) and Service Level Objectives (SLOs) for critical secure services.\nParticipate in the team's operational on-call rotation (PagerDuty), driving rapid incident resolution, root-cause analyses, and P1 war room execution.\nQualifications\nRequired Experience & Skills\nExperience: 3–5 years of dedicated professional experience in SecDevOps, Cloud Security Engineering, DevOps, or Platform Engineering.\nCloud Infrastructure: Hands-on production experience with at least one major hyperscaler (AWS preferred), with functional exposure to Azure and/or GCP environments.\nAutomation & Scripting: High proficiency in Terraform and robust scripting capabilities (Python, Bash, or PowerShell); familiarity with Ansible is preferred.\nIdentity & Secrets: Practical experience managing enterprise identity/access tooling (Okta, Entra ID) and secrets management platforms (HashiCorp Vault, AWS KMS, or Azure Key Vault).\nSecurity Tooling: Familiarity operating endpoint protection (EDR), cloud security posture management (CSPM), or vulnerability scanning platforms (e.g., CrowdStrike, Wiz, Qualys).\nContainers: Experience building, configuring, and troubleshooting containerized environments (Docker, Kubernetes).\nCompliance Alignment: A strong conceptual or practical understanding of FedRAMP, NIST 800-53, or SOC 2 compliance frameworks.\nPreferred Certifications\nHashiCorp Certified: Terraform Associate\nAWS Certified SysOps Administrator or Solutions Architect (Associate)\nCompTIA Security+ or equivalent security credential\nMicrosoft Certified: Azure Administrator Associate\nCompensation Range: $125k-$130k based on experience plus bonus potential\nHiring Requirement: Due to the nature of our work with federal government clients and compliance with applicable regulations, this position requires U.S. citizenship. Dual citizenship is not permitted for this role. Candidates must be able to provide documentation verifying sole U.S. citizenship status as part of the background check process.\nAny offer of employment is contingent upon the successful completion of all required pre-employment screenings, including a background check, in accordance with applicable laws and government contract requirements.\nBenefits & Perks\nKnox offers a competitive employee benefits package including Medical, Dental, Vision, Life & Disability, unlimited PEO, and an employee funded 401k plan. Please note, benefits are subject to change.\nWe are an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. Employment decisions are made without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, veteran status, or any other legally protected status.","datePosted":"2026-08-03T16:25:49.250Z","dateModified":"2026-08-03T16:25:49.250Z","hiringOrganization":{"@type":"Organization","name":"Knox Systems","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Washington","addressRegion":"DC","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"9e8cdc5e0a6e64786b6c0f59"},"url":"https://jobsearcher.com/jobs/9e8cdc5e0a6e64786b6c0f59"}}