> Markdown version of [/jobs/ext/1183671-secdevops-engineer-mid-level-3](https://www.wearedevelopers.com/jobs/ext/1183671-secdevops-engineer-mid-level-3). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SecDevOps Engineer (Mid-Level 3) - **Company:** Knox Systems - **Location:** Washington, DC, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Microsoft Azure, Bash Shell, Cloud Computing, Cloud Computing Security, Cloud Engineering, Configuration Management, CompTIA Security+, System Configuration, Continuous Integration, DevOps, Event Logging, Federated Identity Management, Github, Identity and Access Management, Python (Programming Language), Key Management, Windows PowerShell, Remote Access Technology, Azure Active Directory, Ansible, Prometheus, Zero Trust Network Access, Policy as Code, Google Cloud, Okta, Delivery Pipeline, Grafana, Infrastructure as Code (IaC), Cloudformation, Containerization, Gitlab-ci, Git Flow, Kubernetes, Infrastructure Automation Frameworks, Hashicorp, Cloudwatch, Terraform, Qualys, Docker, Pagerduty, Jenkins, Servicenow, Plan of Action and Milestones, Static Application Security Testing, Vulnerability Analysis - **Published:** July 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=2b57f128793c5b9c ## About the Role * Experience: 3-5 years of dedicated professional experience in SecDevOps, Cloud Security Engineering, DevOps, or Platform Engineering. * Cloud Infrastructure: Hands-on production experience with at least one major hyperscaler (AWS preferred), with functional exposure to Azure and/or GCP environments. * Automation & Scripting: High proficiency in Terraform and robust scripting capabilities (Python, Bash, or PowerShell); familiarity with Ansible is preferred. * Identity & Secrets: Practical experience managing enterprise identity/access tooling (Okta, Entra ID) and secrets management platforms (HashiCorp Vault, AWS KMS, or Azure Key Vault). * Security Tooling: Familiarity operating endpoint protection (EDR), cloud security posture management (CSPM), or vulnerability scanning platforms (e.g., CrowdStrike, Wiz, Qualys). * Containers: Experience building, configuring, and troubleshooting containerized environments (Docker, Kubernetes). * Compliance Alignment: A strong conceptual or practical understanding of FedRAMP, NIST 800-53, or SOC 2 compliance frameworks. Preferred Certifications * HashiCorp Certified: Terraform Associate * AWS Certified SysOps Administrator or Solutions Architect (Associate) * CompTIA Security+ or equivalent security credential * Microsoft Certified: Azure Administrator Associate Hiring Requirement: Due to the nature of our work with federal government clients and compliance with applicable regulations, this position requires U.S. citizenship. Dual citizenship is not permitted for this role. Candidates must be able to provide documentation verifying sole U.S. citizenship status as part of the background check process. Any offer of employment is contingent upon the successful completion of all required pre-employment screenings, including a background check, in accordance with applicable laws and government contract requirements. ## Description The SecDevOps Engineer designs, automates, and maintains Knox's secure cloud infrastructure and CI/CD pipelines across AWS, Azure, and GCP within our FedRAMP-authorized, multi-tenant boundaries. Day-to-day, the work centers on Zero Trust access, continuous monitoring, cloud security posture, and observability - keeping secure, compliant, and repeatable operations running across federal cloud environments. The ideal candidate combines hands-on cloud architecture experience, automation expertise, and a deep security-operations mindset. This role bridges the gap between core cloud engineering and rigorous federal compliance, embedding security controls directly into the deployment fabric using Infrastructure as Code (IaC) and Policy-as-Code frameworks. Role Focus & Technical Matrix Zero Trust & Identity - Zscaler (ZPA / PRA), HashiCorp Vault, Okta, Azure AD / Entra ID, AWS IAM Identity Center Infrastructure as Code - Terraform (Primary), Ansible, CloudFormation, GitOps (ArgoCD / Helm) Security & Compliance- FedRAMP (IL4 boundaries), NIST 800-53, Wiz, Qualys, CrowdStrike, OPA, HashiCorp Sentinel Observability & Ops- Grafana, Prometheus, CloudWatch, PagerDuty, ServiceNow (CAB / eCAB), * Support and operate Zero Trust Network Access (Zscaler ZPA / PRA) architectures including app connectors, privileged remote access, and private application access boundaries. * Manage privileged credentials, API tokens, and secrets lifecycle using HashiCorp Vault, establishing automated credential flows and programmatic rotation. * Integrate and maintain federated identity providers (Okta, Azure AD / Entra ID, AWS IAM Identity Center) and actively support ongoing multi-cloud identity migrations. * Enforce strict least-privilege access models and machine-to-machine credential rotation policies across all automation systems., * Build and manage multi-tenant infrastructure across AWS, Azure, and GCP using Infrastructure as Code (Terraform primary; Ansible and CloudFormation as needed). * Automate end-to-end provisioning, configuration management, and environment deployment workflows via secure CI/CD and GitOps paradigms. * Manage cloud networking, IAM topologies, and security group configurations tailored strictly to FedRAMP controls and Impact Level 4 (IL4) boundaries., * Develop and maintain secure CI/CD pipelines utilizing GitHub Actions, GitLab CI, Azure DevOps, or Jenkins. * Integrate Policy-as-Code frameworks (OPA, HashiCorp Sentinel, or Azure Policy) into pipeline gates to enforce organizational compliance before infrastructure provisioning. * Embed automated static application security testing (SAST), software composition analysis (SCA), and container vulnerability scans into active deployment workflows. * Build, deploy, and troubleshoot containerized workloads within managed Kubernetes environments (EKS, AKS, GKE) using Helm, ArgoCD, or Kustomize. Continuous Monitoring, Vulnerability & Compliance * Support FedRAMP Continuous Monitoring (ConMon) cycles, managing incident tickets, Plan of Action and Milestones (POA&M) tracking, and technical remediation follow-through. * Maintain IaC, pipeline architectures, and operating configurations compliant with FedRAMP and NIST 800-53 standards. * Automate programmatic audit evidence generation for specific control requirements, including CM-2 (Baseline Configurations), CM-6 (Configuration Settings), AU-2 (Event Logging), and SC-12 (Cryptographic Key Establishment and Management). * Participate in formal enterprise change management processes via ServiceNow, preparing documentation for Technical Change Reviews and Change Advisory Board (CAB/eCAB) workflows., * Deploy and maintain centralized dashboards, alert definitions, log aggregation, and metrics/APM architectures using Grafana, Prometheus, or cloud-native tooling. * Define, track, and report on Service Level Indicators (SLIs) and Service Level Objectives (SLOs) for critical secure services. * Participate in the team's operational on-call rotation (PagerDuty), driving rapid incident resolution, root-cause analyses, and P1 war room execution. ## Related Videos - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [Hosting a modern justice system](https://www.wearedevelopers.com/videos/332-hosting-a-modern-justice-system) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) ## Related Articles - [DevOps Engineer Salary [2023]](https://www.wearedevelopers.com/magazine/203-devops-engineer-salary-2023) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market)