Senior DevOps/Compliance Engineer (FedRAMP 20x Continuous Compliance
Listed on 2026-07-31
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Cloud Computing: Infrastructure & Operations, SRE/Site Reliability
Senior Dev Ops Engineer
Uber Ether is a leader in the hyper-secure infrastructure space for Identity and Access Management (IAM), Zero Trust, and compliance acceleration. Our platform and expert services team enable government and commercial customers to have ultimate control over access to critical information. We are employee-first, with outstanding benefits and a track record of upskilling and fostering growth. We're looking for employees who get excited about pioneering novel solutions to new, complex challenges.
This role sits within Uber Ether's Compliance Business Unit, supporting a FedRAMP 20x advisory project built on Google Cloud Platform (GCP). As Senior Dev Ops Engineer, you will build and operate the CI/CD pipelines, automation, and monitoring that put FedRAMP 20x Key Security Indicator (KSI) requirements into practice, and author the Standard Operating Procedures (SOPs) that keep Ping's platform in continuous compliance long after go-live.
Ops Strategy & Continuous Compliance Leadership
- Serve as the principal Dev Ops authority for implementing FedRAMP 20x KSI requirements into the CI/CD and operations model
- Define and maintain the automation roadmap for operationalizing all the KSIs across the FedRAMP KSI families within the Advantage Dev Ops toolchain
- Lead design sessions with engineering to determine how each KSI is enforced, tested, and evidenced in the deployment pipeline
- Drive technical decision-making on pipeline gating, automated policy checks, and continuous monitoring instrumentation
- Partner with the Senior Architect and Compliance BU leadership to translate KSI mapping decisions into working Dev Ops procedures
- Establish Dev Ops standards and design patterns for KSI enforcement that can be reused across future GCP engagements
- Own the end-to-end implementation of CI/CD pipelines and automation that enforce FedRAMP 20x KSI requirements across Advantage deployments on Google Cloud Platform
- Build and maintain Infrastructure as Code (Terraform, Deployment Manager) that encodes KSI controls directly into GCP deployments
- Implement automation that continuously collects and packages compliance evidence for each of the KSIs
- Stand up container security scanning, network segmentation enforcement, and secrets management within the CI/CD pipeline
- Build and maintain Git Lab CI/CD pipelines, Terraform modules, and secure deployment tooling for the environment
- Champion Dev Sec Ops practices, ensuring KSI-aligned security gates are built into every pipeline stage from day one
- Author and maintain Standard Operating Procedures (SOPs) covering deployment, monitoring, incident response, and KSI verification for the platform
- Lead working sessions with engineering to document repeatable, auditable procedures for maintaining KSI compliance post-authorization
- Produce SOP documentation suitable for assessor review, mapping each procedure back to its corresponding KSI
- Support 3
PAO assessments and FedRAMP 20x reviews by walking through operational procedures and evidence pipelines - Translate compliance requirements into operational runbooks that align with Advantage delivery standards
- Drive continuous improvement of SOPs based on assessor feedback, CR26 verification results, and evolving FedRAMP 20x guidance
- Work closely with the Compliance Architect and SoC functions to ensure monitoring dashboards and alerting satisfy KSI evidence requirements
- Build automated KSI verification jobs that continuously confirm each of the KSI families remains in a compliant state
- Maintain remediation runbooks and system hardening procedures specific to the GCP-hosted environment
- Support 3
PAO assessments and audits by producing and explaining automated evidence packages tied to each KSI - Implement Policy as Code and machine readable/OSCAL-based evidence generation across the CI/CD pipeline
- Ensure proper integration between GCP-native security tooling, pipeline automation, and Uber Ether's compliance evidence model
- Foster technical collaboration between Uber Ether's Compliance BU,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).