Senior Forward Deployed Engineer

Mount Indie
Alexandria, VA, United States
23 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Working hours
Regular working hours

Tech stack

Amazon Web Services Software System Penetration Testing Microsoft Azure Bash Shell Configuration Management Computer Networks Linux Python (Programming Language) OpenShift Red Hat Enterprise Linux Prometheus Zero Trust Network Access
+15 more
Server Administration Software Technical Review Data Logging Google Cloud Istio Grafana Multi-Cloud Gitlab Cloudformation Containerization Kubernetes Terraform Splunk Devsecops Docker

Job description

Operating at customer sites ranging from connected networks to classified SCIFs with DDIL constraints, you will be responsible for owning technical relationships for high-visibility defense and intelligence community missions, leading deployments into denied environments, and mentoring forward deployed engineers across the bench.

You will set architectural direction for Game Warden integration into customer networks, resolve mission-critical issues in zero-connectivity scenarios, and translate field realities into product roadmap priorities, ensuring that our most sensitive engagements deliver on technical commitments and customers achieve operational objectives.

We need someone capable of managing complex deployments in classified environments with full accountability for technical outcomes, diagnosing and resolving critical failures in real-time without escalation paths or external dependencies, and mentoring junior engineers and establishing technical standards that scale across customer engagements.

As a key partner to engineering, Security/Compliance, and Product leadership, you will feed customer operational challenges and platform gaps directly into development priorities, to ensure the proprietary platform serves warfighter needs, serving as the senior technical authority for the company’s most demanding customer relationships.

Note: Candidates must reside in one of our approved hiring hubs:

  • DC/Maryland/Virginia

  • Raleigh/Durham/Chapel Hill, NC

  • Denver/Colorado Springs, CO

  • Dallas/Fort Worth, TX

What You’ll Do

  • Own end-to-end technical delivery for 2F’s highest-complexity government and defense engagements - architecting, deploying, and sustaining Game Warden and integrated customer workloads across classified networks, DDIL environments, and multiple Impact Levels (IL2-IL6) and JWICS.
  • Serve as the senior technical escalation point and primary client-facing authority, representing 2F to senior customer stakeholders (program managers, ISSOs/ISSMs, mission owners) and making real-time architectural and risk-tradeoff decisions on-site.
  • Lead and mentor other Forward Deployed and DevSecOps Engineers - setting technical standards, reviewing designs, and building the playbooks that let the team scale to new missions faster.
  • Deploy and harden secure Kubernetes-based infrastructure (Talos Linux, Docker, Istio, GitLab, Helm, Terraform) to sustain a Zero Trust (ZT) environment across customer cloud and on prem environments.
  • Translate field experience into product and platform improvements, working directly with Engineering and Product leadership to prioritize the roadmap based on real deployment friction.
  • Drive accreditation and continuous ATO (cATO) outcomes in partnership with the security/compliance team - producing and validating evidence against NIST 800-53, RMF, STIGs, and FedRAMP controls, and owning remediation of findings from 3PAO assessments and penetration tests.
  • Maintain rigorous configuration management, security documentation, and audit-ready evidence across all engagements, and supporting the 2F team in customer security reviews and audits.
  • Travel to client locations as needed for complex system deployments, updates and troubleshooting during high impact operational exercises, integration and training events.

Requirements

  • 7-10 years of experience in systems deployment, DevSecOps, or platform engineering in regulated/classified government environments, including demonstrated ownership of complex, mission-critical deployments (not just support/execution).
  • Multi-cloud, government-authorized infrastructure: Hands-on experience deploying and hardening workloads across AWS GovCloud/Commercial, Microsoft Azure Government, and Google Cloud, including Infrastructure-as-Code (Terraform, CloudFormation, or equivalent) tailored to DoD Impact Level 2-6 and JWICS environments.
  • Container & orchestration security: Expertise securing Kubernetes/OpenShift or equivalent container platforms - image hardening, admission controls, network policies, and runtime security - within accredited enclaves.
  • Observability & incident response: Skilled in implementing logging, monitoring, and alerting stacks (ELK, Splunk, Prometheus/Grafana) to support 24/7 incident response, penetration test remediation, and Day 2 operations.
  • Understanding of RMF and ATO process in order to drive accreditation outcomes.
  • Expert level proficiency in Linux (Talos, RedHat) server administration, along with deploying and maintaining Kubernetes on cloud platforms and disparate compute hardware.
  • Demonstrated leadership: experience mentoring engineers, leading technical design reviews, or acting as a technical lead on customer-facing engagements.
  • Strong scripting/automation ability in Go, Rust, Python, or Bash, with a track record of building internal tooling to remove manual toil from security and operations workflows.
  • Active DoD Top Secret/SCI clearance (or eligibility, with active clearance strongly preferred); U.S. citizenship required.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:53 min

Configuring dynamic proxy updates with Istio Pilot

Jan Mensch Jan Mensch · World Congress 2026 Europe

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

7:15 min

Installing Istio programmatically with bash scripts

Thomas Südbröcker · LIVE

6:30 min

Empowering non-traditional developers through skill-based automated deployment

Hazal Mestci +1 · Coffee With Developers

Videos

See all

Related articles

See all