Infrastructure Architecture & Platform Engineering

Tangram, Inc.
Dayton, OH, United States
3 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Amazon Web Services Software Applications Automation of Tests Bash Shell Cloud Foundry Code Review Cyber Security Computer Engineering Linux DevOps Disaster Recovery
+30 more
Identity and Access Management Python (Programming Language) NIPRNet OpenID Reliability Engineering Prometheus Security Assertion Markup Language (SAML) Secure Coding Software Deployment Software Engineering SonarQube Tripwire Backup and Restore Scripting Cloud Platform System Okta Delivery Pipeline Grafana IT Architecture Caching Gitlab-ci Kubernetes Information Technology Terraform Data Pipelines Devsecops Docker Static Application Security Testing Golang Dynamic Application Security Testing

Job description

As a Senior Engineer, you will serve as a technical anchor-mentoring engineers, driving platform architecture decisions, and collaborating closely with cross-functional software teams to accelerate Continuous Authority to Operate (cATO) processes and integrate robust, shift-left security practices., Pipeline Architecture, Leadership & Software Delivery

  • Lead the architecture, design, and continuous optimization of enterprise CI/CD pipelines using GitLab CI or alternative deployment platforms.
  • Architect and mature GitOps workflows using FluxCD or ArgoCD to manage multi-cluster state across complex environments.
  • Establish automated testing, automated vulnerability gates, caching strategies, and performance benchmarks to dramatically shorten build and release cycles.
  • Provide tier-3 escalation support and root-cause analysis for build, deployment, or automation pipeline failures.
  • Drive technical standards, best practices, and code reviews across DevOps/DevSecOps practices within the engineering organization.

Infrastructure Architecture & Platform Engineering

  • Architect, deploy, and maintain secure, highly available Cloud-Native infrastructure using AWS GovCloud and Kubernetes.
  • Design scalable Infrastructure-as-Code (IaC) frameworks (e.g., Terraform, OpenTofu) for automated provisioning of cloud, on-premises, and air-gapped environments.
  • Establish containerization standards, custom Helm chart templates, and orchestration patterns across multi-tenant Kubernetes clusters.
  • Lead deployment architectures and secure baseline configurations across multiple security enclaves (NIPRNet, SIPRNet, JWICS, C2S/SC2S).

Continuous Security, cATO & Compliance Strategy

  • Architect end-to-end “Shift-Left” security controls into the delivery workflow, including automated SAST/DAST, container scanning, software bill of materials (SBOM) generation, and dependency tracking.
  • Lead compliance-as-code initiatives to enforce DoD Cybersecurity directives, STIGs, and NIST SP 800-53 controls to accelerate cATO approval frameworks.
  • Champion the integration and adoption of DoD Enterprise DevSecOps reference architectures (e.g., Platform One, Big Bang) and hardened container pipelines using Iron Bank.

Observability, Site Reliability & Platform Operations

  • Architect enterprise observability and telemetry stacks (Prometheus, Grafana, Loki, Jaeger) to enable proactive system health monitoring, alert automation, and operational insights.
  • Lead disaster recovery, high-availability, and business continuity strategy, including automated backup and restore procedures for core Kubernetes clusters and stateful services.
  • Evaluate, pilot, and introduce emerging cloud-native and DevSecOps technologies to elevate overall team capabilities and platform efficiency.

Requirements

Tangram Flex is seeking a Senior DevSecOps / Platform Engineer with 5+ years of experience to lead and advance our cloud-native platform infrastructure, secure software delivery pipelines, and DevSecOps strategy. In this role, you will architect, optimize, and scale cloud-native application build environments and CI/CD pipelines supporting critical internal products and customer deployments across unclassified and classified domains., * Education: Bachelor’s degree in Computer Science, Computer Engineering, IT, Cybersecurity, or equivalent practical experience.

  • Experience: 5+ years of hands-on experience in software deployment, cloud platform engineering, DevOps, or DevSecOps role in an enterprise or DoW environment.
  • Clearance: U.S. Citizenship required; must possess an active Secret security clearance, or possess the ability to obtain and maintain a U.S. Government Top Secret/SCI Security Clearance.
  • Core Technical Capabilities: Expert-level proficiency with AWS / AWS GovCloud, Kubernetes architecture, Docker/container runtimes, and Linux enterprise administration/scripting (Bash, Python, Go).

  • Advanced experience designing enterprise-grade GitLab CI/CD pipelines and infrastructure orchestration with Terraform.
  • DoD 8570/8140 Compliance: Active IAT Level II or IAM Level II/III certification (e.g., Security+ CE, CySA+, CISSP, CISM)
  • Willingness and ability to travel up to 20% to client sites, customer locations, and industry conferences as required., * Deep expertise in container security scanning and governance tools (e.g., Anchore, Trivy, SonarQube, NeuVector, Sysdig).
  • Strong experience with central authentication and identity providers (Okta, Keycloak, OIDC/SAML).
  • Proven experience mentoring mid-level and junior engineers on cloud-native practices, secure coding guidelines, and operational excellence.
  • Strong technical writing ability to author architectural blueprints, compliance documentation, and standard operating procedures (SOPs).
  • Excellent communication skills with the ability to bridge technical requirements between software development teams, product managers, and government stakeholders.
  • Flexibility to support high-priority operational deployment windows or mission-critical outage resolutions.
  • Direct hands-on experience with Air Force Platform One, Big Bang architecture, Iron Bank hardened container baselines, and AWS C2S/SC2S cloud environments.
  • Proven track record assisting or leading cATO accreditation efforts for defense or intelligence customer software applications.

Benefits & conditions

We are committed to staying rooted in our core value of Team First. For that reason, we’ve designed a highly competitive benefits program and supportive work environment to engage employees and their families.

  • Hybrid work options
  • Flexible working hours, 10 paid holidays, and generous Paid Time Off (PTO)
  • Employer-paid Medical, Dental, Vision, and Short/Long-Term Disability Insurance
  • Access to group rating plans for Life Insurance
  • Employer contribution to Health Savings Account (HSA)
  • Competitive 401(k) employer match
  • A vibrant engineering culture that fosters transparency, collaboration, and continuous professional growth via internal tech community events (Lightning Talks, Integration Events)

About the company

What We Do: Our team and products provide solutions to enable innovators to design, develop, verify, and advance critical systems, while accelerating innovation that advances our nation’s security. By accelerating delivery of critical systems, Tangram is transforming the way our nation solves complex software challenges.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

1:08 min

Building solutions with open source GoLang infrastructure tools

Jad Wahab · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

6:16 min

Event-driven Golang backend architecture and cloud deployment

Irina Branovic Irina Branovic · World Congress 2026 Europe

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all