Lead DevOps Engineer - IAM Platform

Anonymous Employer
Fort Meade, MD, United States
7 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Working hours
Regular working hours

Tech stack

Amazon Web Services Application Portfolio Management Cloud Computing Continuous Integration DevOps Multi-Factor Authentication Identity and Access Management Lightweight Directory Access Protocols (LDAP) Octopus Deploy OpenID Ping (Networking Utility) Public Key Infrastructure
+16 more
Reliability Engineering Azure Active Directory Ansible Security Assertion Markup Language (SAML) Security Information and Event Management Data Logging Cloud Platform System Okta Delivery Pipeline Kubernetes Helm Charts Gitlab-ci Kubernetes Deployment Automation SailPoint Terraform Jenkins

Job description

We’re seeking a Lead DevOps Engineer to serve as the technical anchor for a large-scale enterprise identity platform deployment inside a highly secure, air-gapped government cloud environment. This is a hands-on leadership role: you will own the underlying Kubernetes/cloud infrastructure, CI/CD and artifact-delivery pipelines, and the operational foundation that a broader identity and access management (IAM/IGA) platform is built on top of. Due to the classified nature of the target environment, program- and client-specific details will be shared directly with candidates after initial screening. What we can share now: this is a multi-year, phased deployment supporting a large user base and a large application portfolio, the environment will be built on Kubernetes in a government cloud comparable to commercial hyperscaler offerings but operating under stricter security and connectivity constraints (including limited or no internet egress). This role is DevOps/platform-engineering first. Deep identity product expertise is not required - we need someone who can own infrastructure, automation, and delivery pipelines, and who is comfortable picking up identity/access concepts and vendor tooling on the job alongside our identity architects.

What You’ll Do

  • Own and operate Kubernetes-based infrastructure in a secure/classified cloud environment, including cluster lifecycle, capacity planning, and production support
  • Build and maintain CI/CD (GitOps-style) pipelines to deploy and update containerized platform components across dev, test, and production tiers
  • Design and manage the process for moving software artifacts (container images, Helm charts, license files, patches) into an air-gapped or restricted-connectivity environment, including validation and change-control steps
  • Apply security hardening (STIG-equivalent), patching cadence, and compliance controls to infrastructure and supporting services
  • Partner closely with identity architects/engineers to support deployment of directory, authentication, federation, and identity governance services
  • Stand up and maintain observability, logging, and SIEM integration for platform components
  • Own backup/restore procedures and support disaster-recovery and failover testing
  • Lead day-to-day technical delivery for a small team of engineers; report progress, risks, and blockers to program/practice leadership
  • Produce clear infrastructure-as-code, runbooks, and operational documentation to support an eventual transition/handover to client operations staff

Requirements

  • 5+ years of DevOps, Platform Engineering, or Site Reliability Engineering experience
  • 2+ years operating Kubernetes in production environments
  • Strong hands-on experience with a major cloud provider (AWS strongly preferred); experience with government/GovCloud or restricted-connectivity cloud environments is a significant plus
  • Experience with infrastructure-as-code tooling (Terraform, Ansible, or similar) and container packaging/deployment tools (IronBanks)
  • Experience building and maintaining CI/CD or GitOps pipelines (e.g., ArgoCD, Jenkins, GitLab CI, or similar)
  • Working familiarity with federal security hardening and compliance frameworks (e.g., STIG/DISA baselines, NIST 800-53/800-171, RMF/ATO processes) - you don’t need to be a compliance expert, but you should be comfortable operating within one
  • General working knowledge of identity and access management concepts - SAML, OIDC, LDAP/directory services, PKI, MFA/smart-card (PIV/CAC) authentication - enough to collaborate effectively with identity specialists; deep product-level expertise is not required
  • Strong written and verbal communication skills; comfortable engaging directly with client technical stakeholders

Nice to Have

  • Direct hands-on experience with any enterprise identity/IAM or identity governance (IGA) platform (e.g., Ping Identity, ForgeRock, Okta, SailPoint, Saviynt, Microsoft Entra) - willingness to ramp up on a specific vendor stack is valued more than prior depth
  • Prior experience working in air-gapped, disconnected, or classified cloud/enclave environments
  • Experience supporting ATO/RMF documentation, audit evidence collection, or continuous monitoring programs
  • Background supporting large-scale application onboarding or migration efforts
  • Veteran or prior DoD/IC program experience is a plus, not a requirement

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · WWC Europe 2026

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

2:52 min

Implementing IAM with Keycloak and OpenID Connect

Thomas Südbröcker · LIVE

Videos

See all

Related articles

See all