Summary
✨ AI‑Generated
A principal-level Platform and DevSecOps Architect is sought for an onsite, full-time role focused on designing, building, operating, and continuously improving secure cloud-based application platforms. You will provide hands-on technical leadership across Kubernetes and managed container platforms, CI/CD, GitOps, Infrastructure as Code, containerization, networking, identity, security, and observability. The role requires strong experience architecting and troubleshooting production environments, developing sophisticated reusable deployment pipelines, and delivering automated, secure, scalable, and maintainable platform solutions. A minimum of 10 years of relevant experience, including at least 8 years of cloud engineering experience with AWS, is required.
Highlights
Hands-on principal-level architecture role with significant technical leadership and ownership across secure cloud platforms, Kubernetes, CI/CD, infrastructure automation, security, networking, and observability. The position offers the opportunity to design and continuously improve scalable, reusable, and maintainable platform solutions.
Description
Job Title: Principal Platform / DevSecOps Architect
Place of Performance: Onsite
Employment Type: Full-Time
Experience Required: Minimum 10 years of relevant experience, including at least 8 years of AWS engineering experience
Job Summary
We are seeking a Principal Platform / DevSecOps Architect to serve as a hands-on technical architect responsible for designing, building, operating, and continuously improving secure AWS-based application platforms.
The successful candidate will provide technical leadership across Kubernetes/EKS, GitLab CI/CD, GitOps, Infrastructure as Code, containerization, DevSecOps, networking, identity, security, and platform observability while developing automated, reusable, secure, and maintainable platform solutions.
Key Responsibilities
Architect, operate, and troubleshoot production Kubernetes environments, primarily Amazon EKS.Design, develop, and maintain sophisticated GitLab CI/CD pipelines and reusable pipeline templates.Implement GitOps practices for Kubernetes applications and infrastructure.Build and maintain secure AWS infrastructure using Infrastructure as Code (IaC).Develop reusable Helm charts, Kubernetes manifests, deployment patterns, and platform automation.Support containerized applications using Docker.Integrate security scanning, secrets management, IAM, and other DevSecOps controls into delivery pipelines.Troubleshoot complex issues spanning applications, containers, Kubernetes, AWS, networking, certificates, and identity.Support authentication and authorization capabilities, including: IAM
RBAC
OAuth2/OIDC
LDAP
TLS/mTLS
Certificate-based authentication
Improve logging, monitoring, auditing, and overall platform observability.Automate recurring operational tasks and convert manual processes into reusable platform solutions.Develop standardized deployment, pipeline, and infrastructure templates.Document technical solutions, operational procedures, and architecture decisions.Mentor engineers across development, infrastructure, platform, and security teams.Lead technical troubleshooting and resolution across multiple technology layers.
Required Qualifications
U.S.
Citizenship.Active Top Secret/SCI security clearance, with the ability to obtain and maintain a polygraph.Minimum 10 years of experience in software engineering, cloud engineering, DevOps, DevSecOps, platform engineering, or related technical disciplines.Minimum 8 years of AWS engineering experience.Strong hands-on production experience with Kubernetes, preferably Amazon EKS.Deep experience building and troubleshooting GitLab CI/CD pipelines.Strong AWS engineering experience, including: Networking
IAM
Compute
Storage
Load balancing
Monitoring
Strong Docker and containerization experience.Experience with GitOps and Infrastructure as Code.Experience creating reusable deployment, pipeline, and infrastructure templates.Strong Linux, networking, and command-line troubleshooting skills.Software development or scripting experience with Python, Go, Java, Ruby, Bash, or comparable languages.Strong understanding of: IAM and RBAC
Authentication and authorization
TLS and certificates
DNS
HTTP
Routing
Load balancing
Ability to independently troubleshoot complex systems across multiple technology layers.Strong technical communication, documentation, and collaboration skills.
Preferred Qualifications & Certifications
Relevant AWS certifications.Kubernetes/CNCF certifications.Security or DevSecOps certifications.Experience with: Helm
Argo CD
Flux
Terraform
CloudFormation
Experience with Keycloak, LDAP, OAuth2/OIDC, PKI, CAC/PIV, or client-certificate authentication.Experience with Prometheus/Grafana, CloudWatch, ELK/OpenSearch, or comparable observability platforms.Experience integrating security scanning and compliance controls into CI/CD environments.Experience working in regulated or security-sensitive environments.
Additional Requirements
Must maintain the required Top Secret/SCI security clearance and meet applicable polygraph requirements.Position requires onsite work.