Lead DevOps Engineer - IAM Platform
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+16 more
Job description
We’re seeking a Lead DevOps Engineer to serve as the technical anchor for a large-scale enterprise identity platform deployment inside a highly secure, air-gapped government cloud environment. This is a hands-on leadership role: you will own the underlying Kubernetes/cloud infrastructure, CI/CD and artifact-delivery pipelines, and the operational foundation that a broader identity and access management (IAM/IGA) platform is built on top of. Due to the classified nature of the target environment, program- and client-specific details will be shared directly with candidates after initial screening. What we can share now: this is a multi-year, phased deployment supporting a large user base and a large application portfolio, the environment will be built on Kubernetes in a government cloud comparable to commercial hyperscaler offerings but operating under stricter security and connectivity constraints (including limited or no internet egress). This role is DevOps/platform-engineering first. Deep identity product expertise is not required - we need someone who can own infrastructure, automation, and delivery pipelines, and who is comfortable picking up identity/access concepts and vendor tooling on the job alongside our identity architects.
What You’ll Do
- Own and operate Kubernetes-based infrastructure in a secure/classified cloud environment, including cluster lifecycle, capacity planning, and production support
- Build and maintain CI/CD (GitOps-style) pipelines to deploy and update containerized platform components across dev, test, and production tiers
- Design and manage the process for moving software artifacts (container images, Helm charts, license files, patches) into an air-gapped or restricted-connectivity environment, including validation and change-control steps
- Apply security hardening (STIG-equivalent), patching cadence, and compliance controls to infrastructure and supporting services
- Partner closely with identity architects/engineers to support deployment of directory, authentication, federation, and identity governance services
- Stand up and maintain observability, logging, and SIEM integration for platform components
- Own backup/restore procedures and support disaster-recovery and failover testing
- Lead day-to-day technical delivery for a small team of engineers; report progress, risks, and blockers to program/practice leadership
- Produce clear infrastructure-as-code, runbooks, and operational documentation to support an eventual transition/handover to client operations staff
Requirements
- 5+ years of DevOps, Platform Engineering, or Site Reliability Engineering experience
- 2+ years operating Kubernetes in production environments
- Strong hands-on experience with a major cloud provider (AWS strongly preferred); experience with government/GovCloud or restricted-connectivity cloud environments is a significant plus
- Experience with infrastructure-as-code tooling (Terraform, Ansible, or similar) and container packaging/deployment tools (IronBanks)
- Experience building and maintaining CI/CD or GitOps pipelines (e.g., ArgoCD, Jenkins, GitLab CI, or similar)
- Working familiarity with federal security hardening and compliance frameworks (e.g., STIG/DISA baselines, NIST 800-53/800-171, RMF/ATO processes) - you don’t need to be a compliance expert, but you should be comfortable operating within one
- General working knowledge of identity and access management concepts - SAML, OIDC, LDAP/directory services, PKI, MFA/smart-card (PIV/CAC) authentication - enough to collaborate effectively with identity specialists; deep product-level expertise is not required
- Strong written and verbal communication skills; comfortable engaging directly with client technical stakeholders
Nice to Have
- Direct hands-on experience with any enterprise identity/IAM or identity governance (IGA) platform (e.g., Ping Identity, ForgeRock, Okta, SailPoint, Saviynt, Microsoft Entra) - willingness to ramp up on a specific vendor stack is valued more than prior depth
- Prior experience working in air-gapped, disconnected, or classified cloud/enclave environments
- Experience supporting ATO/RMF documentation, audit evidence collection, or continuous monitoring programs
- Background supporting large-scale application onboarding or migration efforts
- Veteran or prior DoD/IC program experience is a plus, not a requirement
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Highest Paying Tech Companies for Developers
Fully Remote Software Engineer Jobs
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
DevOps Engineer Salary [2023]