Senior DevOps/Compliance Engineer
DevOps Compliance Engineer (Sr.)
REMOTE
Pay From: $140,000 per yearMUST:
Experienced Senior DevOps/Compliance Engineer
8+ years of experience in DevOps, site reliability engineering, or platform automation roles
3+ years of experience building CI/CD pipelines and automation on Google Cloud Platform (GCP)
Proven track record of implementing security or compliance controls directly into deployment pipelines
Experience supporting FedRAMP, DoD, or other federal compliance frameworks in an operational capacity
Expert-level knowledge of Google Cloud Platform (GCP) services, IAM, networking, and security tooling, with relevant certifications (Professional Cloud DevOps Engineer preferred)
Strong understanding of FedRAMP 20x Key Security Indicators (KSIs) and how they translate into pipeline and operational controls
Deep expertise in Infrastructure as Code tools (Terraform, Deployment Manager) and GitOps workflows
Strong experience with containerization and orchestration (Docker, Kubernetes/GKE) in secure, compliance-focused environments
Hands-on experience with CI/CD platforms such as GitLab CI/CD, including pipeline security gating and policy enforcement
Solid understanding of FedRAMP 20x requirements, KSI families, and continuous compliance obligations
Working knowledge of NIST 800-53 security controls and how they are operationalized in a CI/CD environment
Experience supporting Assessment & Authorization (A&A) activities from an operations or DevOps perspective
Experience with FISMA, FIPS 140-2, and related federal security requirements
Strong communication skills with ability to document clear, assessor-ready SOPs and explain automation to technical and non-technical audiences
Experience with compliance automation and evidence-generation tooling, including OSCAL and Policy as Code frameworks
Bachelor's degree in Computer Science, Engineering, or related technical field; equivalent experience consideredDUTIES:
Serve as the principal DevOps authority for implementing FedRAMP 20x KSI requirements into the CI/CD and operations model
Define and maintain the automation roadmap for operationalizing all the KSIs across the FedRAMP KSI families within the Advantage DevOps toolchain
Lead design sessions with engineering to determine how each KSI is enforced, tested, and evidenced in the deployment pipeline
Drive technical decision-making on pipeline gating, automated policy checks, and continuous monitoring instrumentation
Partner with the Senior Architect and Compliance BU leadership to translate KSI mapping decisions into working DevOps procedures
Establish DevOps standards and design patterns for KSI enforcement that can be reused across future GCP engagements
Own the end-to-end implementation of CI/CD pipelines and automation that enforce FedRAMP 20x KSI requirements across Advantage deployments on Google Cloud Platform
Build and maintain Infrastructure as Code (Terraform, Deployment Manager) that encodes KSI controls directly into GCP deployments
Implement automation that continuously collects and packages compliance evidence for each of the KSIs
Stand up container security scanning, network segmentation enforcement, and secrets management within the CI/CD pipeline
Build and maintain GitLab CI/CD pipelines, Terraform modules, and secure deployment tooling for the environment
Champion DevSecOps practices, ensuring KSI-aligned security gates are built into every pipeline stage from day one
Work closely with the Compliance Architect and SoC functions to ensure monitoring dashboards and alerting satisfy KSI evidence requirements
Build automated KSI verification jobs that continuously confirm each of the KSI families remains in a compliant state
Maintain remediation runbooks and system hardening procedures specific to the GCP-hosted environment
Support 3PAO assessments and audits by producing and explaining automated evidence packages tied to each KSI
Implement Policy as Code and machine readable/OSCAL-based evidence generation across the CI/CD pipeline
Ensure proper integration between GCP-native security tooling, pipeline automation, and compliance evidence modelQuadrant is an affirmative action/equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, status as a protected veteran, or status as an individual with a disability. "Healthcare benefits are offered to all eligible employees according to compliance mandated by the Affordable Care Act".