SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 155,584 - 199,012 / annual
Nozomi Networks is hiring a Senior Site Reliability Engineer to own and operate their FedRAMP-authorized environment supporting US public sector customers. You will be the primary engineer responsible for day-to-day reliability, security posture, and compliance operations of this critical infrastructure, working autonomously with oversight from a Switzerland-based SRE team and Security & Compliance organization.
Key responsibilities include:
- Serve as primary owner of the FedRAMP environment, ensuring availability, performance, and continuous compliance with FedRAMP baseline controls
- Build and maintain cloud infrastructure and services within the FedRAMP authorization boundary on AWS GovCloud
- Own the patching and vulnerability remediation lifecycle, meeting FedRAMP SLAs (30/90/180 days by severity) and maintaining evidence
- Execute and improve the Continuous Monitoring (ConMon) program: monthly vulnerability scanning, POA&M creation and tracking, deviation requests, and monthly deliverables to the 3PAO and agency sponsors
- Manage deployments and change control within the boundary, ensuring compliance with Configuration Management processes and Significant Change Request procedures
- Maintain system hardening against CIS/STIG benchmarks and FIPS-validated cryptography requirements
- Promote and implement automated solutions for application deployment, patching, evidence collection, and operational activities
- Troubleshoot issues across the entire stack (network, OS, applications)
- Support annual assessments and audits (3PAO), producing artifacts and demonstrating control implementation
- Drive post-incident analysis and reporting to agency stakeholders and US-CERT/CISA where required
- Participate in periodic on-call duties
- Operate within settings with strong confidentiality and data privacy protocols
The role carries high autonomy and responsibility as the primary owner of the FedRAMP environment and its outcomes. You will work asynchronously with a team in Central European Time.
REQUIREMENTS:
- US citizenship or lawful permanent residency; all work performed from within the United States; ability to pass applicable background investigations (FedRAMP and agency requirements)
- Proven professional experience as an SRE, DevOps, or Cloud engineer, including experience operating in a FedRAMP, FISMA, DoD IL, or similarly regulated environment
- Ability to work autonomously and communicate effectively in an async-first setup with a team in a different time zone
- Working knowledge of NIST SP 800-53 controls and the FedRAMP continuous monitoring process (scanning, POA&Ms, deviation requests, annual assessments)
- Strong hands-on experience with Kubernetes
- Hands-on experience with AWS, ideally AWS GovCloud (US)
- Experience with vulnerability management tooling (e.g., Tenable/Nessus, Qualys) and interpreting scan results into actionable remediation plans
- Good knowledge and understanding of at least one programming language (Ruby, Python, Go)
- Experience defining infrastructure as code using tools such as Terraform or CloudFormation
- Experience in the definition of CI/CD pipelines using technologies like Jenkins, GitHub Actions, or similar
- Demonstrable experience using AI-enabled tools as part of day-to-day work to improve efficiency, quality, or decision-making, while applying sound professional judgement and maintaining accountability for outputs within the constraints of a regulated environment
NICE TO HAVE:
- Experience preparing for or maintaining a FedRAMP Authorization to Operate (ATO), including SSP contributions and control narratives
- Familiarity with STIG/CIS hardening automation (e.g., Ansible, OpenSCAP)
- Familiarity with SIEM/log aggregation and audit log retention requirements in federal environments
- Experience working with 3PAOs, agency ISSOs/ISSMs, or the FedRAMP PMO
- Relevant certifications (e.g., AWS certifications, CISSP, Security+, CKA)