SlipstreamJobsFresh Startup & VC-Backed Jobs

Sec Dev Ops Engineer - Level 3

Knox Systems - Arlington, VA, United States - In-office - posted 2026-09-30

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 155,000 - 185,000 / annual

Knox operates the largest Federal & DoD managed cloud, building and operating secure cloud and AI environments that support the U.S. government's most critical missions. This SecDevOps Engineer role is responsible for designing, automating, and maintaining Knox's secure cloud infrastructure and CI/CD pipelines across AWS, Azure, and GCP within FedRAMP-authorized, multi-tenant boundaries. Day-to-day work centers on Zero Trust access, continuous monitoring, cloud security posture, and observability — keeping secure, compliant, and repeatable operations running across federal cloud environments. Key responsibilities include: **Zero Trust & Access Management:** Support and operate Zero Trust Network Access architectures (Zscaler ZPA/PRA) including app connectors and privileged remote access. Manage privileged credentials and secrets lifecycle using HashiCorp Vault with automated credential flows and rotation. Integrate and maintain federated identity providers (Okta, Azure AD/Entra ID, AWS IAM Identity Center) and support multi-cloud identity migrations. Enforce strict least-privilege access models and machine-to-machine credential rotation policies. **Cloud Infrastructure & Secure Automation:** Design, build, and manage multi-tenant infrastructure across AWS, Azure, and GCP using Infrastructure as Code (Terraform primary; CloudFormation as needed). Automate end-to-end provisioning, configuration management, and environment deployment workflows via secure CI/CD and GitOps paradigms. Manage cloud networking, IAM topologies, and security group configurations tailored to FedRAMP controls and Impact Level 4 (IL4) boundaries. **CI/CD, Policy-as-Code & Container Security:** Develop and maintain secure CI/CD pipelines utilizing GitLab CI, Azure DevOps, or Jenkins. Integrate Policy-as-Code frameworks (OPA or Azure Policy) into pipeline gates to enforce organizational compliance before infrastructure provisioning. Embed automated SAST, SCA, and container vulnerability scans into active deployment workflows. Build, deploy, and troubleshoot containerized workloads within managed Kubernetes environments (EKS, AKS, GKE) using Helm, ArgoCD, or Kustomize. **Continuous Monitoring, Vulnerability & Compliance:** Support FedRAMP Continuous Monitoring (ConMon) cycles by implementing technical security controls, managing incident tickets, and executing technical remediation. Maintain IaC, pipeline architectures, and operating configurations compliant with FedRAMP and NIST 800-53 standards. Automate programmatic audit evidence generation for specific control requirements (CM-2, CM-6, AU-2, SC-12). Participate in formal enterprise change management processes via ServiceNow, preparing documentation for Technical Change Reviews and CAB/eCAB workflows. **Observability & Incident Reliability:** Deploy and maintain centralized dashboards, alert definitions, log aggregation, and metrics/APM architectures using Grafana, Prometheus, or cloud-native tooling. Define, track, and report on Service Level Indicators (SLIs) and Service Level Objectives (SLOs) for critical secure services. Participate in the team's operational on-call rotation (PagerDuty), driving rapid incident resolution, root-cause analyses, and P1 war room execution. **REQUIREMENTS** Required Experience & Skills: - 5–7 years of dedicated professional experience in SecDevOps, Cloud Security Engineering, DevOps, or Platform Engineering - Hands-on production experience with at least one major hyperscaler (AWS preferred), with functional exposure to Azure and/or GCP environments - High proficiency in Terraform (declarative IaC) and robust scripting capabilities (Python, Bash, or PowerShell) - Practical experience managing enterprise identity/access tooling (Okta, Entra ID) and secrets management platforms (HashiCorp Vault, AWS KMS, or Azure Key Vault) - Familiarity operating endpoint protection (EDR), cloud security posture management (CSPM), or vulnerability scanning platforms (e.g., CrowdStrike, Wiz, Qualys) - Experience building, configuring, and troubleshooting containerized environments (Docker, Kubernetes) - Practical or working understanding of FedRAMP, NIST 800-53, or SOC 2 compliance frameworks Preferred Certifications: - HashiCorp Certified: Terraform Associate - AWS Certified SysOps Administrator or Solutions Architect (Associate) - CompTIA Security+, CISSP, or equivalent security credential - Microsoft Certified: Azure Administrator Associate Special Requirement: Due to the nature of work with federal government clients and compliance with applicable regulations, this position requires U.S. citizenship. Dual citizenship is not permitted. Candidates must be able to provide documentation verifying sole U.S. citizenship status as part of the background check process.

Similar roles