SecDevOps Engineer (Jr
Listed on 2026-08-08
-
IT/Tech
Cybersecurity, Cloud Computing: Infrastructure & Operations, SRE/Site Reliability
About Knox
Knox runs the largest Federal and DoW managed cloud, building and operating secure cloud and AI environments that support the U.S. government’s most critical missions — from national security and public safety to essential public services. Our customers rely on Knox to deploy production systems that meet the highest standards for security, reliability, and compliance.
Work at Knox is high-impact and purpose-driven. The problems we solve are high stakes, the expectations are high, and the results are visible. Speed, rigor, and trust matter here - because the environments we secure cannot fail. Your contributions are visible, your expertise is relied upon, and the impact of your work is immediate and measurable. We operate at federal scale, securing some of the most sensitive government environments in the country - because the systems we build must perform without fail.
The Junior Sec Dev Ops Engineer supports the maintenance, monitoring, and security auditing of Knox’s cloud infrastructure and CI/CD pipelines across AWS, Azure, and GCP. Operating on-site in Washington, DC, within our FedRAMP-authorized boundaries, this role focuses on day-to-day identity administration, configuration monitoring, and vulnerability triage—helping ensure secure, repeatable operations across federal cloud environments under the direct mentorship of senior engineers.
The ideal candidate has strong technical fundamentals (Linux, basic networking, Git, and scripting), a passionate curiosity for cloud security and automation, and a strong security-first mindset. This is a growth-oriented role designed to build elite technical expertise in Zero Trust architectures, automated compliance engineering, and multi-cloud environments.
Role Focus & Technical MatrixZero Trust & Identity:
Monitoring Zscaler connectors, Hashi Corp & Vault basic secret updates.
Infrastructure as Code:
Running pre-written Terraform plans, Git PR workflows, fundamental Cloud Formation playbooks.
Security & Compliance:
FedRAMP baselines, sorting Wiz/Qualys vulnerability alerts, basic Crowd Strike endpoint checks
Observability & Ops:
Grafana dashboard upkeep, Cloud Watch metrics, Service Now ticketing, shadow on-call protocols
- Assist in monitoring Zero Trust Network Access tools (Zscaler ZPA / PRA), verifying application connectors and remote access pathways remain operational.
- Support secrets management workflows within Hashi Corp Vault, including basic credential generation, entry updates, and confirming automated rotations execute without error.
- Review basic IAM permissions and cloud role policies to ensure alignment with least privilege models under senior engineering review.
- Run, test, and troubleshoot pre-defined Terraform modules across development and staging environments in AWS, Azure, or GCP.
- Identify and log configuration drift or environment resource issues, assisting senior engineers with standard infrastructure patching and remediation tasks.
- Review cloud security groups, public endpoint configurations, and basic network routes to cross-check them against compliance baselines.
- Monitor and triage failing CI/CD pipeline runs within Git Hub Actions, Git Lab CI, or Azure Dev Ops, escalating systemic errors to the team.
- Review automated security scan readouts (SAST, SCA, and container scans) embedded in the pipeline.
- Assist in updating, building, and running security base-image layers for containers (Docker) destined for managed Kubernetes clusters (EKS, AKS, GKE).
- Assist compliance with the programmatic gathering of audit evidence for ongoing FedRAMP Continuous Monitoring (Con Mon) cycles, specifically targeting CM-2, CM-6, AU-2, and SC-12 controls.
- Assist with Plan of Action and Milestones (POA&M) ticket creation, tracking remediation deadlines across the platform.
- Draft and submit technical change requests within Service Now, ensuring correct structural documentation for review by the Change Advisory Board (CAB).
- Maintain and adjust basic Grafana and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).