Senior DevSecOps Engineer, GovCloud & Compliance
Listed on 2026-08-16
-
IT/Tech
Cybersecurity
About the company
the company provides the world’s only integrated go-to-customer platform that combines transformation services, industry insights, and powerful technology to enable B2B companies to protect, retain, and grow large accounts. Our platforms take an outside-in approach to improving commercial health, utilizing executive buyer insights to inform the orchestration of commercial activities that improve relationships, maximize growth, and scale beyond our engagement. We are extending this platform to serve government and defense customers operating in secure, compliance-bound environments.
RoleSummary:
the company is seeking a lead-level Senior Dev Sec Ops Engineer to own the secure deployment of our platform into a dedicated AWS Gov Cloud environment and to drive our path to CMMC Level 2 certification. This is a high-ownership role: you will architect, stand up, and harden the isolated enclave that handles Controlled Unclassified Information (CUI), build the security automation that keeps it compliant, and serve as the technical lead implementing the controls that an assessment depends on, working alongside an external CMMC advisor.
We pair deep hands‑on infrastructure work with a modern, LLM‑augmented workflow. On our commercial‑side infrastructure, you should use agentic coding tools like Claude Code daily as a force multiplier for infrastructure‑as‑code, policy‑as‑code, and pipeline automation (not as a novelty). The expectation is that a senior engineer armed with these tools can design, build, and harden systems at a pace and quality level that wasn’t previously possible, while retaining full ownership of architecture, correctness, and security posture.
Our platform runs as microservices on EKS with an Istio service mesh, backed by Aurora PostgreSQL. You will be responsible for translating that architecture into a Gov Cloud‑resident, control‑compliant deployment, and for keeping it secure, observable, and audit‑ready.
What You’ll DoSecure Gov Cloud Deployment & Infrastructure- Own the design and standup of our AWS Gov Cloud enclave for CUI — network isolation, account/boundary segmentation, identity, and a clearly defined authorization boundary documented for assessment.
- Build and maintain infrastructure as code (Terraform) for reproducible, reviewable, and auditable provisioning of all enclave resources.
- Harden the EKS/Istio runtime — network policy, mTLS, admission control, pod security, secrets management, and least‑privilege IAM across the cluster and AWS services.
- Architect machine‑to‑machine ingest paths that keep CUI within the boundary and minimize human exposure to sensitive data by design.
- Manage encryption, key management, and data‑at‑rest/in‑transit controls consistent with FedRAMP and DoD impact‑level expectations for the environment.
- Design and own the secure CI/CD pipeline with enforced security gates: SAST, DAST, dependency/SCA scanning, container image scanning, and signed, traceable artifacts.
- Implement supply‑chain security — SBOM generation, provenance, and controls over what reaches the protected environment.
- Build compliance and configuration as code so that control enforcement and evidence collection are automated, continuous, and demonstrable rather than manual.
- Serve as the technical lead for CMMC Level 2 / NIST SP 800‑171 implementation
, translating the 110 controls into concrete, enforced technical safeguards across the enclave. - Partner with our external CMMC advisor to scope, prepare for, and pass assessment — you own the technical implementation and evidence, the advisor guides strategy and readiness.
- Support and maintain compliance documentation — System Security Plan (SSP), Plans of Action & Milestones (POA&M), the control responsibility matrix, and SPRS scoring inputs.
- Build the evidence pipeline
: automated logging, monitoring, and artifact collection that proves controls are operating, not just defined.
- Stand up observability inside the enclave using AWS‑native tooling (e.g., Cloud Watch in Gov Cloud) for metrics, logs, audit trails, and alerting.
- Own incident…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).