Senior Platform Engineer; FedD
Listed on 2026-10-03
-
IT/Tech
Cybersecurity
Role Description
Defense Unicorns is seeking a senior Dev Sec Ops Engineer to embed with a government team and its technology partners building an emerging AI-powered engineering ecosystem.
This role sits at the intersection of platform engineering, cybersecurity, compliance, and software delivery. The engineer will help establish secure, automated, and repeatable pipelines that allow software, AI models, and agentic capabilities to move rapidly from development into operational environments while identifying cybersecurity and compliance risks early—before formal security testing.
The ideal candidate is a hands-on Dev Sec Ops engineer with deep experience in Kubernetes, cloud infrastructure, CI/CD, NIST 800-53, and the RMF/ATO process. They should be comfortable working directly with government personnel and multiple commercial technology partners, troubleshooting across technical boundaries, and translating security requirements into practical engineering controls rather than treating compliance as a downstream gate.
This is an embedded engineering role—not a traditional security or compliance staff-augmentation position. The engineer will help the team move quickly, build security into the development lifecycle, and create repeatable patterns that can scale from the initial prototype environment into higher-classification operational environments.
Responsibilities- Design, implement, and continuously improve secure CI/CD and Git Ops pipelines for cloud-native software, AI models, and agentic applications.
- Work hands-on with Kubernetes and Red Hat Open Shift/Open Shift AI environments to automate secure build, test, promotion, deployment, and lifecycle workflows.
- Translate NIST SP 800-53 controls and RMF requirements into practical engineering controls, policies, pipeline checks, and automated evidence collection.
- Identify cybersecurity, compliance, configuration, and supply-chain risks early in the development lifecycle—before formal security testing or authorization activities.
- Support the end-to-end ATO/RMF lifecycle, including control implementation, technical evidence generation, security artifacts, remediation tracking, and preparation for assessment.
- Build and maintain automated security checks across source code, dependencies, container images, infrastructure, configurations, and deployment pipelines.
- Implement software supply-chain security practices including SBOM generation, provenance, artifact signing, vulnerability scanning, policy enforcement, and controlled artifact promotion.
- Develop Infrastructure as Code using Terraform, Pulumi, Ansible, or similar technologies to make environments consistent, auditable, and repeatable.
- Configure and improve Git Lab CI/CD pipelines, runners, registries, and automated workflows across multiple environments.
- Integrate identity, secrets management, policy enforcement, logging, monitoring, and security tooling into the broader engineering platform.
- Collaborate with platform, data, AI/agent, and architecture engineers to ensure security and compliance requirements are designed into the system rather than bolted on later.
- Work directly with commercial technology partners to resolve cross-platform security, deployment, identity, networking, and integration issues.
- Help establish repeatable approaches for promoting software and AI capabilities across security domains and into classified operational environments.
- Develop security automation and compliance-as-code patterns that reduce manual effort and accelerate authorization decisions.
- Create and maintain architecture decision records, security documentation, technical…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).