×
Register Here to Apply for Jobs or Post Jobs. X

SecDevOps Engineer

Job in Washington, District of Columbia, 20022, USA
Listing for: Knox Systems
Full Time position
Listed on 2026-08-02
Job specializations:
  • IT/Tech
    Cybersecurity, Cloud Computing: Infrastructure & Operations, Systems Engineer, SRE/Site Reliability
Salary/Wage Range or Industry Benchmark: 100000 - 130000 USD Yearly USD 100000.00 130000.00 YEAR
Job Description & How to Apply Below

About Knox

Knox runs the largest Federal managed cloud, building and operating secure cloud and AI environments that support the U.S. government’s most critical missions — from national security and public safety to essential public services. Our customers rely on Knox to deploy production systems that meet the highest standards for security, reliability, and compliance.

Work at Knox is high-impact and purpose-driven. The problems we solve are high-stakes, the expectations are high, and the results are visible. Speed, rigor, and trust matter here - because the environments we secure cannot fail. Your contributions are visible, your expertise is relied upon, and the impact of your work is immediate and measurable. We operate at federal scale, securing some of the most sensitive government environments in the country - because the systems we build must perform without fail.

The Role

The Sec Dev Ops  Engineer designs, automates, and maintains Knox’s secure cloud infrastructure and CI/CD pipelines across AWS, Azure, and GCP within our FedRAMP-authorized, multi-tenant boundaries. Day-to-day, the work centers on Zero Trust access, continuous monitoring, cloud security posture, and observability — keeping secure, compliant, and repeatable operations running across federal cloud environments.

The ideal candidate combines hands-on cloud architecture experience, automation expertise, and a deep security-operations mindset. This role bridges the gap between core cloud engineering and rigorous federal compliance, embedding security controls directly into the deployment fabric using Infrastructure as Code (IaC) and Policy-as-Code frameworks.

Role Focus & Technical Matrix
  • Zero Trust & Identity - Zscaler (ZPA / PRA), Hashi Corp Vault, Okta, Azure AD / Entra , AWS IAM Identity Center
  • Infrastructure as Code - Terraform (Primary), Ansible, Cloud Formation, Git Ops (ArgoCD / Helm)
  • Security & Compliance- FedRAMP (IL4 boundaries), NIST 800-53, Wiz, Qualys, Crowd Strike,
  • OPA, Hashi Corp Sentinel
  • Observability & Ops- Grafana, Prometheus, Cloud Watch, Pager Duty, Service Now (CAB / eCAB)
Key Responsibilities Zero Trust & Access Management
  • Support and operate Zero Trust Network Access (Zscaler ZPA / PRA) architectures including app connectors, privileged remote access, and private application access boundaries.
  • Manage privileged credentials, API tokens, and secrets lifecycle using Hashi Corp Vault, establishing automated credential flows and programmatic rotation.
  • Integrate and maintain federated identity providers (Okta, Azure AD / Entra , AWS IAM Identity Center) and actively support ongoing multi-cloud identity migrations.
  • Enforce strict least-privilege access models and machine-to-machine credential rotation policies across all automation systems.
Cloud Infrastructure & Secure Automation
  • Build and manage multi-tenant infrastructure across AWS, Azure, and GCP using Infrastructure as Code (Terraform primary; Ansible and Cloud Formation as needed).
  • Automate end-to-end provisioning, configuration management, and environment deployment workflows via secure CI/CD and Git Ops paradigms.
  • Manage cloud networking, IAM topologies, and security group configurations tailored strictly to FedRAMP controls and Impact Level 4 (IL4) boundaries.
CI/CD, Policy-as-Code & Container Security
  • Develop and maintain secure CI/CD pipelines utilizing Git Hub Actions, Git Lab CI, Azure Dev Ops, or Jenkins.
  • Integrate Policy-as-Code frameworks (OPA, Hashi Corp Sentinel, or Azure Policy) into pipeline gates to enforce organizational compliance before infrastructure provisioning.
  • Embed automated static application security testing (SAST), software composition analysis (SCA), and container vulnerability scans into active deployment workflows.
  • Build, deploy, and troubleshoot containerized workloads within managed Kubernetes environments (EKS, AKS, GKE) using Helm, ArgoCD, or Kustomize.
Continuous Monitoring, Vulnerability & Compliance
  • Support FedRAMP Continuous Monitoring (Con Mon) cycles, managing incident tickets, Plan of Action and Milestones (POA&M) tracking, and technical remediation follow-through.
  • Maintain IaC, pipeline architectures, and operating configurations…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary