Application Vulnerability Assessment Program (AVAP) Engineer/System Administrator

ELUMIN LLC
Springfield, VA, United States
5 days ago
Apply on www.careerjet.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$134,000.0 - $185,000.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Artificial Intelligence Amazon Web Services Application Layers Microsoft Azure Backup Devices Cloud Computing Software Documentation Databases Continuous Integration Data Centers DevOps
+29 more
Monitoring of Systems Key Management Linux System Administration SQL Azure Network Architecture OpenID Open Web Application Security Cloud Services Fortify (Software) Zero Trust Network Access Security Assertion Markup Language (SAML) Server Administration Single Sign-On SQL Databases User Provisioning Software Virtualization Technology Okta Software Security Containerization Kubernetes Infrastructure Automation Frameworks Information Technology OpenText Deployment Automation Bicep Azure AKS Terraform Docker Vulnerability Analysis

Job description

Build your next generation organization with advanced automation and AI tools - purpose-built for enterprise scale. We engineer intelligence into the core of infrastructure for Federal and commercial customers. Openvista® Suite

  • Hyperscaler® - AI for the operators who keep everything running. Design automations, deploy them with confidence, and manage your environment from a single platform *

Forward Deployed Engineering Support

  • Infrastructure Automation Engineers - Embed directly with your team to design and build automations purpose-built for your environment, eliminating manual toil and delivering operational efficiency at scale.

  • Cloud and Data Center Engineers - We can take full ownership of designing, running, and managing your infrastructure across public cloud, private data center, or hybrid environments as a true operational partner.

Job Description The Application Vulnerability Assessment Program (AVAP) Engineer/System Administrator is responsible for operating and securing the program’s application security platforms, including OpenText Fortify, OWASP Dependency-Track, and any future application security tools, deployed in containerized and virtualized environments within Azure Kubernetes Service (AKS). This role manages Kubernetes-based infrastructure (AKS), container image pipelines, and automation through Infrastructure-as-Code and CI/CD (Azure DevOps) to ensure resilient, scalable, and compliant deployments. The engineer will perform system administration for both Windows and Linux environments, enforce security and compliance requirements aligned to federal standards, and maintain runbooks, SOPs, and metrics to support operational excellence. In addition, the role supports AVAP customers by troubleshooting platform issues to minimize downtime and ensure mission-critical vulnerability assessment services remain highly available., Design, deploy, and maintain secure, scalable, and resilient cloud infrastructure in Azure such as Azure Key Vault, Azure SQL Server, Azure SQL DB, Azure Kubernetes Service (AKS), etc. * Operate and administer Kubernetes clusters (AKS) including node pools, networking, persistent volumes, ingress controllers, secrets management, access control, namespaces, etc.

  • Manage system administration for both Windows and Linux environments
  • Manage container image lifecycle and updates by pull hardened images (i.e., Iron Bank), scan for vulnerabilities, enforce least-privilege configurations, and publish to ACR.
  • Perform regular server administration tasks including patching, user provisioning, system monitoring, and backup/restoration.
  • Automate deployments of infrastructure and applications using Azure DevOps or equivalent CI/CD pipelines with ARM/Bicep/Terraform and Helm.
  • Implement and enforce security/compliance controls aligned to NIST SP 800-53 and Zero Trust (i.e., key vault integration, secret management, TLS cert rotation).
  • Develop and maintain operational runbooks, playbooks, SOPs, and system/network architecture diagrams to ensure repeatability and continuous system documentation.
  • Troubleshoot platform and pipeline issues across application, network, and infrastructure layers to minimize downtime for AVAP customers.
  • Contribute to monitoring and metrics collection (availability, scan throughput, failure rates, license utilization) to support program-level reporting.

Requirements

Demonstrated expertise with Azure (preferred) and familiarity with AWS and GCP cloud services. * Hands-on experience with Kubernetes administration (AKS), Helm, and containerization (Docker).

  • Experience with system administration for both Windows and Linux environments
  • Experience with system administration pertaining to SQL servers/databases, backup/restore, patching, etc.
  • Experience with Infrastructure-as-Code (ARM/Bicep, Terraform, Helm) and CI/CD pipelines (Azure DevOps).
  • Demonstrated experience with Terraform, Bicep, and/or ARM for infrastructure automation and immutability.
  • Strong troubleshooting skills across networking, compute, and application layers.
  • Familiarity with application security tools is a plus (OpenText Fortify Software Security Center, License and Infrastructure Management, OWASP Dependency Track, etc.)
  • Understanding of single sign-on implementations using SAML/OIDC (management of users/groups in Okta) as well as SCIM for automatic user provisioning.
  • Excellent technical writing and documentation skills.
  • Ability to work within government compliance frameworks (FedRAMP, NIST, FISMA, Zero Trust).

Years of Experience and Education Requirements Bachelor’s degree in Computer Science, Information Technology, or related field, or equivalent hands-on experience. * 3+ years of hands-on experience in system administration and DevOps engineering supporting containerized platforms/Kubernetes. Type: Full-Time

Benefits & conditions

Location: Northwest D.C. 4 days on-site, 1 day Hybrid (Monday or Friday) Shift: Normal Business Hours. 5 days on-site. Type of Travel: Local Target Salary Range: The anticipated salary range for this position is $134,000.00 to $185,000.00. This range is not a guarantee of compensation. Final salary will be determined based on factors including experience, geographic location, and any applicable contractual requirements, and may fall above or below the stated range. Benefits: We offer an excellent comprehensive benefits plan that includes Medical, Dental & Vision options and more.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:56 min

Provisioning a secure container infrastructure with Bicep

Matthias Falkenberg +1 · World Congress 2022

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · World Congress 2023

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

Videos

See all

Related articles

See all