Description
The Role
Windward is the leading Maritime AI™ company, delivering all-source operational intelligence on the maritime domain to defense, law enforcement, customs and commercial customers worldwide.
We fuse AIS, dark vessel signals, EO, SAR and RF into a single operational picture, and turn it into explainable, mission-grade intelligence.
Our US federal footprint is growing and we are building the infrastructure to support it properly.
You will lead our US federal infrastructure.
The GovCloud account is empty today — you are building it from scratch.
The mandate is to stand up a compliant AWS GovCloud enclave that is logically and operationally separated from our commercial platform, migrate our federal workloads into it, take it through FedRAMP authorization and CMMC Level 2 assessment, and then audit that environment against the controls you implemented.
This is a greenfield build, not a maintenance role: you make the foundational architecture decisions, you own the environment end to end in production — availability, security posture, cost and compliance — and you hire and lead the small team that runs it with you.
Agentic AI is in the product, not just the pitch: we automate screening and investigation workflows, and customers extend them with their own templates and data sources.
We build the same way — agentic development is how our engineering and security teams work day to day, and we expect the same from you on infrastructure and compliance work.
What you'll do
Build the entire GovCloud environment from scratch — greenfield, no existing footprint to inherit: account and Organizations structure, networking, identity, encryption, logging, boundary protection, and every supporting service.Own that environment permanently once it exists: you are the accountable engineer for its availability, security posture, patch state, cost and audit readiness.Lead the end-to-end migration of our federal workloads into it: plan, sequence, cutover and validate, with clear rollback criteria at every stage.Conduct full internal audits of the environment you built — control-by-control assessment, gap analysis, findings and remediation plans — and stand behind that assessment in front of external assessors.Define and defend the FedRAMP authorization boundary — data flow diagrams, inventory, and the technical evidence behind each control.Own infrastructure as code across the federal environment (Terraform), including drift detection, policy-as-code guardrails, and reproducible environment builds.Build and operate Kubernetes (EKS) workloads in GovCloud: hardened cluster configuration, workload identity, admission control, patching and upgrade cadence.Build FedRAMP-compliant CI/CD: separated pipelines, signed artifacts, SBOM generation, provenance, and controlled promotion paths between commercial and federal environments.Implement continuous monitoring and the monthly ConMon reporting cycle: vulnerability scanning, POA&M management, deviation requests, and significant change requests.Stand up centralized logging, audit trail integrity and alerting to federal retention requirements; integrate incident response and on-call for the federal environment.Work directly with the CISO, our 3PAO and prime contractors on assessment readiness, evidence collection, SSP maintenance and SPRS scoring.Establish the operational runbooks, DR/BCP procedures and RPO/RTO validation for federal workloads.Apply agentic tooling to infrastructure and compliance work — automated evidence collection, control validation, drift and configuration review — with the human gates and audit trail a federal boundary requires.Hire, onboard and lead the US federal infrastructure team as the footprint grows; set the technical bar and the on-call culture.
Required qualifications
7+ years in DevOps, SRE, platform or cloud infrastructure engineering, with at least 3 years hands-on in AWS GovCloud (US).Proven experience leading a FedRAMP authorization and/or a commercial-to-GovCloud migration end to end — owning the plan and the outcome, not contributing to someone else's.Demonstrated ability to conduct a full audit of an environment you built: assess it control-by-control, produce defensible findings and evidence, and close the gaps.Must be eligible for an active US Government security clearance (Secret minimum), currently in scope and transferable.US citizenship.Deep AWS expertise: IAM and permission boundaries, KMS and key management, VPC design and private connectivity, GuardDuty / Security Hub / Config, CloudTrail and log integrity.Expert-level Terraform, including module design and multi-account state management.Production Kubernetes experience (EKS preferred), including security hardening and upgrade management.AI-first working methodology: real, daily use of coding agents and agentic workflows to build and review, with sound judgment about where automated output needs a human gate.Track record of integrating fast — shipping working infrastructure in weeks, and getting productive in an unfamiliar codebase and organization quickly.People management experience: hiring, onboarding, performance and technical mentorship of engineers.Comfortable operating as the senior technical voice in a room of auditors, assessors and prime contractor security teams.
Preferred qualifications
TS/SCI clearance.CMMC Level 2 assessment experience, including SSP authorship and SPRS submission.Experience supporting DoD or IC customers, or working as a subcontractor under DFARS 252.204-7012 flowdowns.Familiarity with DISA STIGs, DoD SRG impact levels (IL4/IL5), or AWS Secret Region.Experience with SingleStore (MemSQL) — deployment, operation or migration.Experience running data platforms in a restricted environment (MongoDB Atlas for Government, or equivalent).Experience with commercial-to-federal codebase separation and release management for the same product across two boundaries.
Our environment
AWS (multi-account, primary commercial region us-west-2) · EKS · MongoDB Atlas · Terraform with automated governance · GitHub and GitHub Actions · Coralogix for observability · incident.io for incident management · Semgrep and GHAS in the security pipeline.
Certified to ISO 27001 and ISO 22301, SOC 2 Type II attested.
Why this role
You will not be inheriting someone else's architecture or filling a seat on a large platform team.
You are defining how a fast-moving, AI-first company operates inside a federal boundary, close to the decisions that matter and to the government customers who depend on the outcome.
The work is technically demanding and highly visible.
Windward is an equal opportunity employer.
Positions requiring a security clearance and US citizenship are restricted as permitted under applicable US law, including ITAR and federal contract requirements.