> Markdown version of [/jobs/ext/2416142-devops-lead-fedramp](https://www.wearedevelopers.com/jobs/ext/2416142-devops-lead-fedramp). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # DevOps Lead (FedRAMP) - **Company:** Orca Security - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $230,000.0 - $260,000.0 - **Contract:** Permanent contract - **Skills:** Xacta, Microsoft Windows, Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, Computer Engineering, Continuous Integration, Software Debugging, DevOps, Federal Information Processing Standards (FIPS), Python (Programming Language), Key Management, S Interface, Software Vulnerability Management, Data Logging, Kubernetes, Information Technology, Terraform, Plan of Action and Milestones - **Published:** August 31, 2026 - **Apply:** https://orca.security/about/careers/6149333004?gh_jid=6149333004 ## About the Role * You are hands on today and you want to stay that way. You are writing infrastructure code and operating production systems now, and you would be doing roughly two thirds of that in this role alongside the ownership and customer work. * Real experience inside a FedRAMP authorized system. You can talk about an authorization boundary, a significant change, or what a 3PAO will ask for, from having done it. * 5 or more years in DevOps, SRE, or cloud infrastructure, with genuine production ownership. * Deep AWS experience, including hands on AWS GovCloud and a clear understanding of how it differs from commercial. * Kubernetes in production. Operating it, debugging it, and upgrading it. * Terraform and infrastructure as code at scale, 3 or more years. * Automation in Python or an equivalent language, with an instinct to script what others do by hand. * Fluency in NIST SP 800-53 Rev 5. You can move between a control and its real technical implementation in either direction. * Vulnerability management experience in a regulated environment. * The presence to hold a technical conversation with a federal customer's security team and be the reason they trust the answer. Excellent written and spoken English. * Based in the United States, with access to the authorized environment subject to our federal personnel screening requirements. * Comfortable working with an Israel based R&D organization, with meaningful overlap with Israel hours. Bonus Points: * Experience with the FedRAMP 20x pathway, OSCAL tooling, or KSI based validation. * Exposure to DoD IL4 or IL5, StateRAMP, CMMC, or IRAP. * Experience growing a small infrastructure team. * Compliance automation tooling such as Xacta, Paramify, RegScale, or Vanta. * Background at a security product company or with a cloud native security platform. * Bachelor's degree in Computer Science or Computer Engineering, or equivalent hands on experience. ## Description Own and operate Orca's FedRAMP environments across AWS, Azure, and GCP. Build infrastructure with Terraform, Kubernetes, Helm, and CI/CD; automate compliance validation, drift detection, evidence collection, and inventory management. Lead continuous monitoring, authorization artifacts, OSCAL transition, 3PAO assessments, and federal customer security engagements. Serve as the senior technical authority, maintain production health and incident response, and eventually build a U.S.-based infrastructure team while remaining hands-on., The DevOps Lead (FedRAMP) will own Orca's FedRAMP environment. All of it. The infrastructure, the authorization, and the relationships with the agencies and assessors who depend on it. This is a builder's role with real authority. You will be the most senior Orca engineer in our federal environment and the person everyone comes to for anything that touches it, from a Terraform change to an agency security review. You will set the technical direction, and you will implement it yourself. Over time you will grow a small US based team around you while keeping your own hands on the system. The timing is good. FedRAMP is moving to 20x, with machine readable OSCAL packages, Key Security Indicators, and continuous validation replacing point in time assessment. Most companies are treating that as a compliance problem. We want to treat it as an automation problem, and you will be the one who designs how Orca does it. If you like being the definitive expert on a system that matters, and you want the ownership without giving up the engineering, this is a rare shape of role. What You'll Do: Build and operate the federal environment * Own and evolve Orca's FedRAMP environment in AWS GovCloud, AWS East/West, Azure Government, Azure Commercial, and GCP, including EKS, Terraform, Helm, CI/CD, FIPS validated endpoints, hardened images, secrets management, and centralized logging. * Write the infrastructure code yourself and set the standards for how it is written. * Design the automation that makes compliance a byproduct of how the system runs, covering continuous configuration validation, drift detection, evidence collection, and inventory accuracy. * Decide how new platform capabilities land in the federal environment, and bring them in cleanly. * Own production health, monitoring, and incident response for the environment. Own the FedRAMP program * Run continuous monitoring end to end, including scanning, POA&M, inventory, and reporting. * Own the authorization artifacts, from the SSP and boundary diagrams through control implementation, and lead their move to OSCAL. * Assess and categorize changes to the boundary, and own the notification process that goes with them. * Lead annual assessment and 3PAO engagements, from scoping through evidence to closing findings. * Be Orca's interface to the FedRAMP PMO, our agency sponsor, and our assessors. * Track where the program is heading and tell us what it means for us early. Represent Orca to federal customers * Be the technical voice of our federal environment in front of agency security teams, prime contractors, and prospects, across security reviews, architecture deep dives, and audit responses. * Work directly with our federal sales, sales engineering, and customer success teams. You will be in the rooms where a credible technical answer wins the account. * Translate between an agency ISSO and an R&D team in Tel Aviv, in both directions, so requirements arrive as something buildable. ## Related Videos - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Demystifying DevOps—Pros, cons, dos & don'ts](https://www.wearedevelopers.com/videos/338-demystifying-devops-pros-cons-dos-don-ts) - [#90DaysOfDevOps - The DevOps Learning Journey](https://www.wearedevelopers.com/videos/548-90daysofdevops-the-devops-learning-journey) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [DevOps Engineer Salary [2023]](https://www.wearedevelopers.com/magazine/203-devops-engineer-salary-2023) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)