{"schemaVersion":"jobsearcher.job.v1","id":"c0a8c82c60a06d53082931ca","url":"https://jobsearcher.com/jobs/c0a8c82c60a06d53082931ca","canonicalUrl":"https://jobsearcher.com/jobs/c0a8c82c60a06d53082931ca","title":"SecDevOps Engineer (Jr.)","description":"About Knox\nKnox runs the largest Federal and DoW managed cloud, building and operating secure cloud and AI environments that support the U.S. government’s most critical missions — from national security and public safety to essential public services. Our customers rely on Knox to deploy production systems that meet the highest standards for security, reliability, and compliance.\nWork at Knox is high-impact and purpose-driven. The problems we solve are high stakes, the expectations are high, and the results are visible. Speed, rigor, and trust matter here - because the environments we secure cannot fail. Your contributions are visible, your expertise is relied upon, and the impact of your work is immediate and measurable. We operate at federal scale, securing some of the most sensitive government environments in the country - because the systems we build must perform without fail.\nThe Junior SecDevOps Engineer supports the maintenance, monitoring, and security auditing of Knox’s cloud infrastructure and CI/CD pipelines across AWS, Azure, and GCP. Operating on-site in Washington, DC, within our FedRAMP-authorized boundaries, this role focuses on day-to-day identity administration, configuration monitoring, and vulnerability triage—helping ensure secure, repeatable operations across federal cloud environments under the direct mentorship of senior engineers.\nThe ideal candidate has strong technical fundamentals (Linux, basic networking, Git, and scripting), a passionate curiosity for cloud security and automation, and a strong security-first mindset. This is a growth-oriented role designed to build elite technical expertise in Zero Trust architectures, automated compliance engineering, and multi-cloud environments.\nRole Focus & Technical Matrix:\nZero Trust & Identity: Monitoring Zscaler connectors, HashiCorp & Vault basic secret updates.\nInfrastructure as Code: Running pre-written Terraform plans, Git PR workflows, fundamental CloudFormation playbooks.\nSecurity & Compliance: FedRAMP baselines, sorting Wiz/Qualys vulnerability alerts, basic CrowdStrike endpoint checks\nObservability & Ops: Grafana dashboard upkeep, CloudWatch metrics, ServiceNow ticketing, shadow on-call protocols\nKey Responsibilities:\nZero Trust & Identity Operations\nAssist in monitoring Zero Trust Network Access tools (Zscaler ZPA / PRA), verifying\napplication connectors and remote access pathways remain operational.\nSupport secrets management workflows within HashiCorp Vault, including basic\ncredential generation, entry updates, and confirming automated rotations execute without\nerror.\nReview basic IAM permissions and cloud role policies to ensure alignment with least-\nprivilege models under senior engineering review.\nInfrastructure & Automation Support\nRun, test, and troubleshoot pre-defined Terraform modules across development and\nstaging environments in AWS, Azure, or GCP.\nIdentify and log configuration drift or environment resource issues, assisting senior\nengineers with standard infrastructure patching and remediation tasks.\nReview cloud security groups, public endpoint configurations, and basic network routes to cross-check them against compliance baselines.\nCI/CD & Pipeline Maintenance\nMonitor and triage failing CI/CD pipeline runs within GitHub Actions, GitLab CI, or Azure\nDevOps, escalating systemic errors to the team.\nReview automated security scan readouts (SAST, SCA, and container scans) embedded\nin the pipeline.\nAssist in updating, building, and running security base-image layers for containers\n(Docker) destined for managed Kubernetes clusters (EKS, AKS, GKE).\nCompliance Monitoring & Change Administration\nAssist compliance with the programmatic gathering of audit evidence for ongoing\nFedRAMP Continuous Monitoring (ConMon) cycles, specifically targeting CM-2, CM-6,\nAU-2, and SC-12 controls.\nAssist with Plan of Action and Milestones (POA&M) ticket creation, tracking remediation\ndeadlines across the platform.\nDraft and submit technical change requests within ServiceNow, ensuring correct structural\ndocumentation for review by the Change Advisory Board (CAB).\nObservability & Incident Support\nMaintain and adjust basic Grafana and CloudWatch dashboards, ensuring alert\nnotifications are mapped accurately to operational notification streams.\nMonitor standard system health indicators, performing low-severity alert triaging to\nprevent production fatigue.\nMaintain open telemetry operations for ongoing application monitoring\nParticipate in a shadow on-call rotation capacity (PagerDuty) alongside senior engineers\nto develop live diagnostic and real-time incident resolution skills.\n\nQualifications\nRequired Experience & Core Aptitude\nExperience: 1–2 years of experience in an entry-level technical role (e.g., IT Support,\nJunior Systems Administrator, Helpdesk/NOC, Cyber Operations, or relevant cloud\nengineering internship/bootcamp).\nLocation: Must be able to work fully on-site at our Washington, DC office.\nLinux Fundamentals: Comfortable navigating the Linux command line (Bash), managing\nfile permissions, viewing system logs, and executing basic terminal commands.\nNetworking Core: Solid grasp of foundational networking concepts (DNS, TCP/IP,\nHTTP/HTTPS, SSH, Subnets, and basic firewall/security group rules).\nCloud & Version Control Exposure: Foundational exposure to public cloud concepts\n(AWS preferred) and basic Git workflows (cloning, branching, commits, Pull Requests).\nBasic Scripting: Ability to read and write fundamental scripts in Python or Bash to\nautomate repetitive tasks, parse logs, or interact with simple APIs.\nSecurity Mindset: Strong conceptual understanding of core security principles (Least\nPrivilege, Multi-Factor Authentication, IAM basics, Encryption).\nSoft Skills & Growth Mindset: High technical curiosity, excellent written documentation\nhabits, and a strong eagerness to learn directly from senior engineers on-site\nNice to Have (Bonus Experience / Technologies You Will Learn)\nExposure to Infrastructure as Code concepts (Terraform or CloudFormation).\nFamiliarity with container basics (Docker) or CI/CD pipelines (GitHub Actions, GitLab CI)\nBasic experience using ticketing or monitoring tools (Jira, ServiceNow, CloudWatch,\nGrafana)\nConceptual awareness of federal security or compliance frameworks (FedRAMP, NIST\n800-53, or SOC 2\nDesirable Certifications\nCompTIA Security+ or Linux+\nAWS Certified Cloud Practitioner or Solutions Architect (Associate)\nHashiCorp Certified: Terraform Associate (or actively pursuing)\nMicrosoft Certified: Azure Fundamentals\nHiring Requirement: Due to the nature of our work with federal government clients and compliance with applicable regulations, this position requires U.S. citizenship. Dual citizenship is not permitted for this role. Candidates must be able to provide documentation verifying sole U.S. citizenship status as part of the background check process.\nAny offer of employment is contingent upon the successful completion of all required pre-employment screenings, including a background check, in accordance with applicable laws and government contract requirements.\nCompensation Range: $90k to $110k plus bonus and equity.\nBenefits & Perks\nKnox offers a competitive employee benefits package including Medical, Dental, Vision, Life & Disability, unlimited PEO, and an employee funded 401k plan. Please note, benefits are subject to change.\nWe are an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. Employment decisions are made without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, veteran status, or any other legally protected status.","company":"Knox Systems","rawCompany":"knox systems","city":"Washington","state":"DC","isRemote":false,"isActive":false,"createdAt":"2026-08-06T15:43:29.511Z","occupations":[{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1244.00","title":"Network and Computer Systems Administrators","slug":"network-and-computer-systems-administrators"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"SecDevOps Engineer (Jr.)","description":"About Knox\nKnox runs the largest Federal and DoW managed cloud, building and operating secure cloud and AI environments that support the U.S. government’s most critical missions — from national security and public safety to essential public services. Our customers rely on Knox to deploy production systems that meet the highest standards for security, reliability, and compliance.\nWork at Knox is high-impact and purpose-driven. The problems we solve are high stakes, the expectations are high, and the results are visible. Speed, rigor, and trust matter here - because the environments we secure cannot fail. Your contributions are visible, your expertise is relied upon, and the impact of your work is immediate and measurable. We operate at federal scale, securing some of the most sensitive government environments in the country - because the systems we build must perform without fail.\nThe Junior SecDevOps Engineer supports the maintenance, monitoring, and security auditing of Knox’s cloud infrastructure and CI/CD pipelines across AWS, Azure, and GCP. Operating on-site in Washington, DC, within our FedRAMP-authorized boundaries, this role focuses on day-to-day identity administration, configuration monitoring, and vulnerability triage—helping ensure secure, repeatable operations across federal cloud environments under the direct mentorship of senior engineers.\nThe ideal candidate has strong technical fundamentals (Linux, basic networking, Git, and scripting), a passionate curiosity for cloud security and automation, and a strong security-first mindset. This is a growth-oriented role designed to build elite technical expertise in Zero Trust architectures, automated compliance engineering, and multi-cloud environments.\nRole Focus & Technical Matrix:\nZero Trust & Identity: Monitoring Zscaler connectors, HashiCorp & Vault basic secret updates.\nInfrastructure as Code: Running pre-written Terraform plans, Git PR workflows, fundamental CloudFormation playbooks.\nSecurity & Compliance: FedRAMP baselines, sorting Wiz/Qualys vulnerability alerts, basic CrowdStrike endpoint checks\nObservability & Ops: Grafana dashboard upkeep, CloudWatch metrics, ServiceNow ticketing, shadow on-call protocols\nKey Responsibilities:\nZero Trust & Identity Operations\nAssist in monitoring Zero Trust Network Access tools (Zscaler ZPA / PRA), verifying\napplication connectors and remote access pathways remain operational.\nSupport secrets management workflows within HashiCorp Vault, including basic\ncredential generation, entry updates, and confirming automated rotations execute without\nerror.\nReview basic IAM permissions and cloud role policies to ensure alignment with least-\nprivilege models under senior engineering review.\nInfrastructure & Automation Support\nRun, test, and troubleshoot pre-defined Terraform modules across development and\nstaging environments in AWS, Azure, or GCP.\nIdentify and log configuration drift or environment resource issues, assisting senior\nengineers with standard infrastructure patching and remediation tasks.\nReview cloud security groups, public endpoint configurations, and basic network routes to cross-check them against compliance baselines.\nCI/CD & Pipeline Maintenance\nMonitor and triage failing CI/CD pipeline runs within GitHub Actions, GitLab CI, or Azure\nDevOps, escalating systemic errors to the team.\nReview automated security scan readouts (SAST, SCA, and container scans) embedded\nin the pipeline.\nAssist in updating, building, and running security base-image layers for containers\n(Docker) destined for managed Kubernetes clusters (EKS, AKS, GKE).\nCompliance Monitoring & Change Administration\nAssist compliance with the programmatic gathering of audit evidence for ongoing\nFedRAMP Continuous Monitoring (ConMon) cycles, specifically targeting CM-2, CM-6,\nAU-2, and SC-12 controls.\nAssist with Plan of Action and Milestones (POA&M) ticket creation, tracking remediation\ndeadlines across the platform.\nDraft and submit technical change requests within ServiceNow, ensuring correct structural\ndocumentation for review by the Change Advisory Board (CAB).\nObservability & Incident Support\nMaintain and adjust basic Grafana and CloudWatch dashboards, ensuring alert\nnotifications are mapped accurately to operational notification streams.\nMonitor standard system health indicators, performing low-severity alert triaging to\nprevent production fatigue.\nMaintain open telemetry operations for ongoing application monitoring\nParticipate in a shadow on-call rotation capacity (PagerDuty) alongside senior engineers\nto develop live diagnostic and real-time incident resolution skills.\n\nQualifications\nRequired Experience & Core Aptitude\nExperience: 1–2 years of experience in an entry-level technical role (e.g., IT Support,\nJunior Systems Administrator, Helpdesk/NOC, Cyber Operations, or relevant cloud\nengineering internship/bootcamp).\nLocation: Must be able to work fully on-site at our Washington, DC office.\nLinux Fundamentals: Comfortable navigating the Linux command line (Bash), managing\nfile permissions, viewing system logs, and executing basic terminal commands.\nNetworking Core: Solid grasp of foundational networking concepts (DNS, TCP/IP,\nHTTP/HTTPS, SSH, Subnets, and basic firewall/security group rules).\nCloud & Version Control Exposure: Foundational exposure to public cloud concepts\n(AWS preferred) and basic Git workflows (cloning, branching, commits, Pull Requests).\nBasic Scripting: Ability to read and write fundamental scripts in Python or Bash to\nautomate repetitive tasks, parse logs, or interact with simple APIs.\nSecurity Mindset: Strong conceptual understanding of core security principles (Least\nPrivilege, Multi-Factor Authentication, IAM basics, Encryption).\nSoft Skills & Growth Mindset: High technical curiosity, excellent written documentation\nhabits, and a strong eagerness to learn directly from senior engineers on-site\nNice to Have (Bonus Experience / Technologies You Will Learn)\nExposure to Infrastructure as Code concepts (Terraform or CloudFormation).\nFamiliarity with container basics (Docker) or CI/CD pipelines (GitHub Actions, GitLab CI)\nBasic experience using ticketing or monitoring tools (Jira, ServiceNow, CloudWatch,\nGrafana)\nConceptual awareness of federal security or compliance frameworks (FedRAMP, NIST\n800-53, or SOC 2\nDesirable Certifications\nCompTIA Security+ or Linux+\nAWS Certified Cloud Practitioner or Solutions Architect (Associate)\nHashiCorp Certified: Terraform Associate (or actively pursuing)\nMicrosoft Certified: Azure Fundamentals\nHiring Requirement: Due to the nature of our work with federal government clients and compliance with applicable regulations, this position requires U.S. citizenship. Dual citizenship is not permitted for this role. Candidates must be able to provide documentation verifying sole U.S. citizenship status as part of the background check process.\nAny offer of employment is contingent upon the successful completion of all required pre-employment screenings, including a background check, in accordance with applicable laws and government contract requirements.\nCompensation Range: $90k to $110k plus bonus and equity.\nBenefits & Perks\nKnox offers a competitive employee benefits package including Medical, Dental, Vision, Life & Disability, unlimited PEO, and an employee funded 401k plan. Please note, benefits are subject to change.\nWe are an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. Employment decisions are made without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, veteran status, or any other legally protected status.","datePosted":"2026-08-06T15:43:29.511Z","dateModified":"2026-08-06T15:43:29.511Z","hiringOrganization":{"@type":"Organization","name":"Knox Systems","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Washington","addressRegion":"DC","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"c0a8c82c60a06d53082931ca"},"url":"https://jobsearcher.com/jobs/c0a8c82c60a06d53082931ca"}}