Platform Architect (Kubernetes / CI/CD) | TS/SCI

MomentumAI LLC
Denver, United States
10 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$150,000.0 - $275,000.0
Working hours
Regular working hours

Tech stack

Kubernetes Security Artificial Intelligence Amazon Web Services Automation of Tests Microsoft Azure Bash Shell Cloud Computing Cloud Foundry Databases Continuous Integration Data Migration DevOps
+44 more
Domain Name System (DNS) Github Python (Programming Language) Key Management Linux System Administration Nginx Octopus Deploy OpenShift Performance Tuning Prometheus Zero Trust Network Access Azure Machine Learning Software Engineering Data Streaming Tripwire VMware VSphere YAML Data Logging Pulumi Scripting Load Balancing Autoscaling Istio Grafana Amazon Virtual Private Cloud (VPC) Gitlab Cloudformation Containerization Gitlab-ci Tanzu Kubernetes Rancher Hashicorp Linkerd (Service Mesh) Data Management CIS Benchmarks Api Gateway Terraform Oracle Cloud Infrastructure Code Restructuring Docker Jenkins Vulnerability Analysis Vmware

Job description

At MomentumAI, you’ll architect, harden, and deliver secure Kubernetes platforms and CI/CD pipelines that power mission-critical systems across the Federal Civilian, DoD, and IC communities. You’ll partner with platform, app, and security teams to design resilient architectures, drive application migrations, and implement repeatable, compliance-ready delivery patterns aligned to MomentumAI’s Platform-as-a-Product approach.

We are seeking a Platform Architect with deep, hands-on platform engineering, Kubernetes, CI/CD, and container security experience. You will partner with mission stakeholders, developers, security, and operations in secure environments to design resilient architectures, build app and data platforms, and migrate workloads to the platforms while meeting stringent compliance requirements.

WHAT YOU’LL DO

  • Architecture & delivery: Own architecture and delivery of containerized applications on Kubernetes across commercial, government, and air-gapped environments.
  • CI/CD design & implementation: Design and implement CI/CD (GitOps-first using Argo CD/Flux, or classic pipelines via GitHub Actions/GitLab/Jenkins) with policy gates, automated testing, artifact signing, and environment promotion.
  • Container & cluster hardening: Apply CIS Benchmarks/DoD STIGs, admission control (OPA/Gatekeeper/Kyverno), image scanning (Trivy/Anchore/Clair), SBOM/SLSA supply-chain controls, and secrets management (Vault/KMS).
  • Application migration & modernization: Lead discovery, assessment, and execution (rehost/replatform/refactor), data migration strategies, blue/green and canary releases, and service mesh patterns (Istio/Linkerd).
  • Infrastructure as Code: Implement Terraform/Pulumi/Helm/Kustomize; codify platform baselines and repeatable environment builds.
  • Observability & reliability: Establish Prometheus/Grafana/ELK/OpenTelemetry, performance tuning, autoscaling, and SLOs.
  • Security & compliance partnership: Support NIST 800-53, FedRAMP, RMF/ATO documentation, continuous monitoring, and evidence collection.
  • Team coaching & communication: Create architecture diagrams, decision records, runbooks, and deliver executive/mission briefings.
  • Pre-sales & delivery support: Contribute to LOE estimates, SOWs/ROMs, roadmaps, and technical demos/workshops.

Requirements

Strong candidates will meet most (not necessarily all) of the technical requirements below.

  • Active TS/SCI or TS/SCI eligibility (must be able to obtain and maintain). U.S. citizenship required.
  • 7+ years in Solutions Architecture, Platform Engineering, DevOps, or related roles.
  • 3+ years hands-on Kubernetes in production (cluster design, operations, troubleshooting).
  • CI/CD pipeline experience (e.g., GitHub Actions, GitLab CI, Jenkins) including environment promotion and approvals in regulated contexts.
  • Containerization fundamentals (Docker/OCI), image lifecycle management, and container hardening practices.
  • Infrastructure as Code (e.g., Terraform, CloudFormation, Crossplane) for cloud or on-prem deployments.
  • Solid Linux administration, networking (VPC/VNet, DNS, TLS, ingress/egress, load balancing), and security fundamentals.
  • Observability & logging (e.g., Prometheus, Grafana, ELK/EFK, OpenTelemetry); root-cause analysis and performance tuning.
  • Scripting proficiency (Bash) and YAML fluency.
  • Software engineering proficiency in at least one of Go or Python.
  • Demonstrated ability to lead cross-functional initiatives, influence without authority, and present to technical and executive audiences.

PREFERRED QUALIFICATIONS

These are nice-to-haves that strengthen your candidacy. You don’t need all of them.

  • CI or FS Poly.
  • Experience delivering in DoD/IC environments, including air-gapped clusters and high-side/low-side data flows.
  • Managed Kubernetes distributions (EKS, AKS, GKE, VKS, Rancher, OpenShift).
  • VMware ecosystem: VCF architecture/operations (vSphere, NSX-T, vSAN, SDDC Manager), VKS, Tanzu, or Cloud Foundry.
  • GitOps (Argo CD, Flux) and Kubernetes packaging (Helm, Kustomize).
  • Container registries (Harbor, ECR, ACR, GCR) and vulnerability scanning (Trivy, Anchore, Clair).
  • Kubernetes policy & runtime security: OPA/Gatekeeper/Kyverno, Pod Security Standards, Cilium/Calico, Falco, Sigstore/Cosign, SBOM tooling.
  • Secrets management (HashiCorp Vault, cloud KMS/HSM).
  • Government cloud platforms: AWS GovCloud, Azure Government, or Google Assured Workloads.
  • AI/ML platforms: AWS Bedrock/SageMaker, Azure OpenAI/ML, or Google Vertex AI/Gemini.
  • Stateful workloads on Kubernetes: database refactoring/replication, Operators, StatefulSets, StorageClasses.
  • Service mesh (Istio, Linkerd), API gateways (Kong, NGINX), Zero Trust tooling (Teleport).
  • Relevant certifications: CKA/CKAD/CKS; VMware VCP tracks; cloud certs (AWS/Azure/GCP); DoD 8570/8140 (Security+, CISSP).

Benefits & conditions

Compensation: $150,000 - $275,000 OTE Benefits: Comprehensive health, dental, and vision; 401(k) with 6% company match; FSA/HSA; life and AD&D; short- and long-term disability; unlimited PTO; other well-being and professional growth benefits. See https://wearemomentum.ai/benefits/ for more details.

Actual compensation will be based on experience, geographic location, and clearance level.

About the company

MomentumAI is a platform engineering consultancy helping enterprises and government agencies build next-generation app and data platforms. Our team pioneered the Platform-as-a-Product approach at Pivotal and VMware, and has spent over a decade delivering production-scale platforms. We design and implement container orchestration (Kubernetes, Tanzu/Cloud Foundry, OpenShift, Rancher), microservices patterns, and automated CI/CD. Leveraging tools like Terraform, Crossplane, Kratix, Helm, and Kustomize - and service meshes such as Istio and Envoy - we help customers operate securely across AWS (incl. GovCloud), Azure (incl. Government), GCP, and on-prem environments. We also leverage Zero Trust access patterns (e.g., Teleport) and DevSecOps/SRE practices to ensure reliable, compliant, and observable operations.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:53 min

Configuring dynamic proxy updates with Istio Pilot

Jan Mensch Jan Mensch · World Congress 2026 Europe

1:58 min

Configuring a baseline isolated agent on Tanzu platform

Oren Penso Oren Penso · World Congress 2026 Europe

1:35 min

Centralizing configuration logic with native YAML block references

Matthieu Vincent Matthieu Vincent · Europe 2026 Virtual

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

7:15 min

Installing Istio programmatically with bash scripts

Thomas Südbröcker · LIVE

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

Videos

See all

Related articles

See all