Summary
A technology organization supporting sensitive workloads is seeking a DevOps engineer to manage cloud infrastructure, deployment pipelines, security controls, and compliance programs while enabling engineering teams to move faster.
Highlights
Remote-friendly role focused on infrastructure ownership, security improvements, compliance automation, and protecting sensitive data environments.
Description
As we take on more government and defense work, the security and integrity of our infrastructure becomes its own discipline โ and we want someone who owns it rather than spreading it thin across the product engineers.
The "sec" in this role is the point: you'll be responsible for how sensitive data moves, where it lives, and who can see it, so the rest of the team can focus on building.
This is a remote-friendly role open to candidates across the U.S., with occasional in-person sync when the work calls for it.
What you'll do
Own our infrastructure and deployment pipeline โ including deploying into containerized, customer-provided environments and on Azure.Own the security posture for controlled and sensitive data: data transmission, storage, access control, key management, and who can and can't see what.Drive our compliance program from identification into implementation โ NIST controls (we're already tracking these in ControlMap), CMMC / SPRS, and recurring assessments like SOC 2 Type II.Partner with leadership and IT on compliance requirements and timelines, and turn a backlog of controls into an ongoing, sustainable program that doesn't grind product velocity to a halt.Take security concerns off the plates of full-stack and ML engineers so they can ship.
Must-haves
Eligible to obtain and hold a U.S.
security clearance โ an active clearance is not required today, but you must be able to qualify for one.Strong DevOps / infrastructure background โ CI/CD, cloud (Azure especially), containerized deployments, and infrastructure-as-code.A security-focused mindset for infrastructure hardening and compliance โ you think about access, isolation, and blast radius by default.Ability to implement a defined set of controls in our stack โ turning a documented framework into working configuration, policy, and automation.
Nice to have
Prior government or defense experience โ ideally in defense contracting โ and comfort operating inside those environments.Hands on exposure to NIST 800-171, CMMC, or navigating an ATO Process