{"schemaVersion":"jobsearcher.job.v1","id":"c487ce10699932b2c07d79cd","url":"https://jobsearcher.com/jobs/c487ce10699932b2c07d79cd","canonicalUrl":"https://jobsearcher.com/jobs/c487ce10699932b2c07d79cd","title":"Senior DevOps/Compliance Engineer","description":"DevOps Compliance Engineer (Sr.)\r\nREMOTE\r\nPay From: $140,000 per yearMUST:\r\nExperienced Senior DevOps/Compliance Engineer\r\n8+ years of experience in DevOps, site reliability engineering, or platform automation roles\r\n3+ years of experience building CI/CD pipelines and automation on Google Cloud Platform (GCP)\r\nProven track record of implementing security or compliance controls directly into deployment pipelines\r\nExperience supporting FedRAMP, DoD, or other federal compliance frameworks in an operational capacity\r\nExpert-level knowledge of Google Cloud Platform (GCP) services, IAM, networking, and security tooling, with relevant certifications (Professional Cloud DevOps Engineer preferred)\r\nStrong understanding of FedRAMP 20x Key Security Indicators (KSIs) and how they translate into pipeline and operational controls\r\nDeep expertise in Infrastructure as Code tools (Terraform, Deployment Manager) and GitOps workflows\r\nStrong experience with containerization and orchestration (Docker, Kubernetes/GKE) in secure, compliance-focused environments\r\nHands-on experience with CI/CD platforms such as GitLab CI/CD, including pipeline security gating and policy enforcement\r\nSolid understanding of FedRAMP 20x requirements, KSI families, and continuous compliance obligations\r\nWorking knowledge of NIST 800-53 security controls and how they are operationalized in a CI/CD environment\r\nExperience supporting Assessment & Authorization (A&A) activities from an operations or DevOps perspective\r\nExperience with FISMA, FIPS 140-2, and related federal security requirements\r\nStrong communication skills with ability to document clear, assessor-ready SOPs and explain automation to technical and non-technical audiences\r\nExperience with compliance automation and evidence-generation tooling, including OSCAL and Policy as Code frameworks\r\nBachelor's degree in Computer Science, Engineering, or related technical field; equivalent experience consideredDUTIES:\r\nServe as the principal DevOps authority for implementing FedRAMP 20x KSI requirements into the CI/CD and operations model\r\nDefine and maintain the automation roadmap for operationalizing all the KSIs across the FedRAMP KSI families within the Advantage DevOps toolchain\r\nLead design sessions with engineering to determine how each KSI is enforced, tested, and evidenced in the deployment pipeline\r\nDrive technical decision-making on pipeline gating, automated policy checks, and continuous monitoring instrumentation\r\nPartner with the Senior Architect and Compliance BU leadership to translate KSI mapping decisions into working DevOps procedures\r\nEstablish DevOps standards and design patterns for KSI enforcement that can be reused across future GCP engagements\r\nOwn the end-to-end implementation of CI/CD pipelines and automation that enforce FedRAMP 20x KSI requirements across Advantage deployments on Google Cloud Platform\r\nBuild and maintain Infrastructure as Code (Terraform, Deployment Manager) that encodes KSI controls directly into GCP deployments\r\nImplement automation that continuously collects and packages compliance evidence for each of the KSIs\r\nStand up container security scanning, network segmentation enforcement, and secrets management within the CI/CD pipeline\r\nBuild and maintain GitLab CI/CD pipelines, Terraform modules, and secure deployment tooling for the environment\r\nChampion DevSecOps practices, ensuring KSI-aligned security gates are built into every pipeline stage from day one\r\nWork closely with the Compliance Architect and SoC functions to ensure monitoring dashboards and alerting satisfy KSI evidence requirements\r\nBuild automated KSI verification jobs that continuously confirm each of the KSI families remains in a compliant state\r\nMaintain remediation runbooks and system hardening procedures specific to the GCP-hosted environment\r\nSupport 3PAO assessments and audits by producing and explaining automated evidence packages tied to each KSI\r\nImplement Policy as Code and machine readable/OSCAL-based evidence generation across the CI/CD pipeline\r\nEnsure proper integration between GCP-native security tooling, pipeline automation, and compliance evidence modelQuadrant is an affirmative action/equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, status as a protected veteran, or status as an individual with a disability. \"Healthcare benefits are offered to all eligible employees according to compliance mandated by the Affordable Care Act\".","company":"Quadrant","rawCompany":"quadrant","city":"Sterling","state":"VA","isRemote":false,"isActive":false,"createdAt":"2026-08-08T01:24:15.190Z","occupations":[{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"},{"code":"11-9199.02","title":"Compliance Managers","slug":"compliance-managers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Senior DevOps/Compliance Engineer","description":"DevOps Compliance Engineer (Sr.)\r\nREMOTE\r\nPay From: $140,000 per yearMUST:\r\nExperienced Senior DevOps/Compliance Engineer\r\n8+ years of experience in DevOps, site reliability engineering, or platform automation roles\r\n3+ years of experience building CI/CD pipelines and automation on Google Cloud Platform (GCP)\r\nProven track record of implementing security or compliance controls directly into deployment pipelines\r\nExperience supporting FedRAMP, DoD, or other federal compliance frameworks in an operational capacity\r\nExpert-level knowledge of Google Cloud Platform (GCP) services, IAM, networking, and security tooling, with relevant certifications (Professional Cloud DevOps Engineer preferred)\r\nStrong understanding of FedRAMP 20x Key Security Indicators (KSIs) and how they translate into pipeline and operational controls\r\nDeep expertise in Infrastructure as Code tools (Terraform, Deployment Manager) and GitOps workflows\r\nStrong experience with containerization and orchestration (Docker, Kubernetes/GKE) in secure, compliance-focused environments\r\nHands-on experience with CI/CD platforms such as GitLab CI/CD, including pipeline security gating and policy enforcement\r\nSolid understanding of FedRAMP 20x requirements, KSI families, and continuous compliance obligations\r\nWorking knowledge of NIST 800-53 security controls and how they are operationalized in a CI/CD environment\r\nExperience supporting Assessment & Authorization (A&A) activities from an operations or DevOps perspective\r\nExperience with FISMA, FIPS 140-2, and related federal security requirements\r\nStrong communication skills with ability to document clear, assessor-ready SOPs and explain automation to technical and non-technical audiences\r\nExperience with compliance automation and evidence-generation tooling, including OSCAL and Policy as Code frameworks\r\nBachelor's degree in Computer Science, Engineering, or related technical field; equivalent experience consideredDUTIES:\r\nServe as the principal DevOps authority for implementing FedRAMP 20x KSI requirements into the CI/CD and operations model\r\nDefine and maintain the automation roadmap for operationalizing all the KSIs across the FedRAMP KSI families within the Advantage DevOps toolchain\r\nLead design sessions with engineering to determine how each KSI is enforced, tested, and evidenced in the deployment pipeline\r\nDrive technical decision-making on pipeline gating, automated policy checks, and continuous monitoring instrumentation\r\nPartner with the Senior Architect and Compliance BU leadership to translate KSI mapping decisions into working DevOps procedures\r\nEstablish DevOps standards and design patterns for KSI enforcement that can be reused across future GCP engagements\r\nOwn the end-to-end implementation of CI/CD pipelines and automation that enforce FedRAMP 20x KSI requirements across Advantage deployments on Google Cloud Platform\r\nBuild and maintain Infrastructure as Code (Terraform, Deployment Manager) that encodes KSI controls directly into GCP deployments\r\nImplement automation that continuously collects and packages compliance evidence for each of the KSIs\r\nStand up container security scanning, network segmentation enforcement, and secrets management within the CI/CD pipeline\r\nBuild and maintain GitLab CI/CD pipelines, Terraform modules, and secure deployment tooling for the environment\r\nChampion DevSecOps practices, ensuring KSI-aligned security gates are built into every pipeline stage from day one\r\nWork closely with the Compliance Architect and SoC functions to ensure monitoring dashboards and alerting satisfy KSI evidence requirements\r\nBuild automated KSI verification jobs that continuously confirm each of the KSI families remains in a compliant state\r\nMaintain remediation runbooks and system hardening procedures specific to the GCP-hosted environment\r\nSupport 3PAO assessments and audits by producing and explaining automated evidence packages tied to each KSI\r\nImplement Policy as Code and machine readable/OSCAL-based evidence generation across the CI/CD pipeline\r\nEnsure proper integration between GCP-native security tooling, pipeline automation, and compliance evidence modelQuadrant is an affirmative action/equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, status as a protected veteran, or status as an individual with a disability. \"Healthcare benefits are offered to all eligible employees according to compliance mandated by the Affordable Care Act\".","datePosted":"2026-08-08T01:24:15.190Z","dateModified":"2026-08-08T01:24:15.190Z","hiringOrganization":{"@type":"Organization","name":"Quadrant","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Sterling","addressRegion":"VA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"c487ce10699932b2c07d79cd"},"url":"https://jobsearcher.com/jobs/c487ce10699932b2c07d79cd"}}