> Markdown version of [/jobs/ext/1926296-lead-devops-engineer-iam-platform](https://www.wearedevelopers.com/jobs/ext/1926296-lead-devops-engineer-iam-platform). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead DevOps Engineer - IAM Platform - **Company:** Anonymous Employer - **Location:** Fort Meade, MD, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Application Portfolio Management, Cloud Computing, Continuous Integration, DevOps, Multi-Factor Authentication, Identity and Access Management, Lightweight Directory Access Protocols (LDAP), Octopus Deploy, OpenID, Ping (Networking Utility), Public Key Infrastructure, Reliability Engineering, Azure Active Directory, Ansible, Security Assertion Markup Language (SAML), Security Information and Event Management, Data Logging, Cloud Platform System, Okta, Delivery Pipeline, Kubernetes Helm Charts, Gitlab-ci, Kubernetes, Deployment Automation, SailPoint, Terraform, Jenkins - **Published:** August 5, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9075864/lead-devops-engineer-iam-platform ## About the Role * 5+ years of DevOps, Platform Engineering, or Site Reliability Engineering experience * 2+ years operating Kubernetes in production environments * Strong hands-on experience with a major cloud provider (AWS strongly preferred); experience with government/GovCloud or restricted-connectivity cloud environments is a significant plus * Experience with infrastructure-as-code tooling (Terraform, Ansible, or similar) and container packaging/deployment tools (IronBanks) * Experience building and maintaining CI/CD or GitOps pipelines (e.g., ArgoCD, Jenkins, GitLab CI, or similar) * Working familiarity with federal security hardening and compliance frameworks (e.g., STIG/DISA baselines, NIST 800-53/800-171, RMF/ATO processes) - you don't need to be a compliance expert, but you should be comfortable operating within one * General working knowledge of identity and access management concepts - SAML, OIDC, LDAP/directory services, PKI, MFA/smart-card (PIV/CAC) authentication - enough to collaborate effectively with identity specialists; deep product-level expertise is not required * Strong written and verbal communication skills; comfortable engaging directly with client technical stakeholders Nice to Have * Direct hands-on experience with any enterprise identity/IAM or identity governance (IGA) platform (e.g., Ping Identity, ForgeRock, Okta, SailPoint, Saviynt, Microsoft Entra) - willingness to ramp up on a specific vendor stack is valued more than prior depth * Prior experience working in air-gapped, disconnected, or classified cloud/enclave environments * Experience supporting ATO/RMF documentation, audit evidence collection, or continuous monitoring programs * Background supporting large-scale application onboarding or migration efforts * Veteran or prior DoD/IC program experience is a plus, not a requirement ## Description We're seeking a Lead DevOps Engineer to serve as the technical anchor for a large-scale enterprise identity platform deployment inside a highly secure, air-gapped government cloud environment. This is a hands-on leadership role: you will own the underlying Kubernetes/cloud infrastructure, CI/CD and artifact-delivery pipelines, and the operational foundation that a broader identity and access management (IAM/IGA) platform is built on top of. Due to the classified nature of the target environment, program- and client-specific details will be shared directly with candidates after initial screening. What we can share now: this is a multi-year, phased deployment supporting a large user base and a large application portfolio, the environment will be built on Kubernetes in a government cloud comparable to commercial hyperscaler offerings but operating under stricter security and connectivity constraints (including limited or no internet egress). This role is DevOps/platform-engineering first. Deep identity product expertise is not required - we need someone who can own infrastructure, automation, and delivery pipelines, and who is comfortable picking up identity/access concepts and vendor tooling on the job alongside our identity architects. What You'll Do * Own and operate Kubernetes-based infrastructure in a secure/classified cloud environment, including cluster lifecycle, capacity planning, and production support * Build and maintain CI/CD (GitOps-style) pipelines to deploy and update containerized platform components across dev, test, and production tiers * Design and manage the process for moving software artifacts (container images, Helm charts, license files, patches) into an air-gapped or restricted-connectivity environment, including validation and change-control steps * Apply security hardening (STIG-equivalent), patching cadence, and compliance controls to infrastructure and supporting services * Partner closely with identity architects/engineers to support deployment of directory, authentication, federation, and identity governance services * Stand up and maintain observability, logging, and SIEM integration for platform components * Own backup/restore procedures and support disaster-recovery and failover testing * Lead day-to-day technical delivery for a small team of engineers; report progress, risks, and blockers to program/practice leadership * Produce clear infrastructure-as-code, runbooks, and operational documentation to support an eventual transition/handover to client operations staff ## Related Videos - [My journey into DevOps world - How it all started!](https://www.wearedevelopers.com/videos/545-my-journey-into-devops-world-how-it-all-started) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [#90DaysOfDevOps - The DevOps Learning Journey](https://www.wearedevelopers.com/videos/548-90daysofdevops-the-devops-learning-journey) - [GitOps for the people](https://www.wearedevelopers.com/videos/815-gitops-for-the-people) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) ## Related Articles - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [DevOps Engineer Salary [2023]](https://www.wearedevelopers.com/magazine/203-devops-engineer-salary-2023) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)