Cloud/Network Infrastructure Engineer, Senior

ECS Corporate Services, LLC
Fairfax, VA, United States
4 days ago
Apply on www.jofdav.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$123,000.0 - $184,000.0
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Amazon S3 Bash Shell Software as a Service Cloud Computing Continuous Integration Dynamic Host Configuration Protocol Domain Name System (DNS) Amazon DynamoDB Github Identity and Access Management Subnetting
+25 more
JSON Python (Programming Language) Network Security Network Architecture Routing Node.Js Performance Tuning RabbitMQ TCP/IP YAML Data Logging Scripting Computer Networking Systems Transport Layer Security Load Balancing Amazon Virtual Private Cloud (VPC) Templating Git Flow Kubernetes Infrastructure Automation Frameworks Terraform Appdynamics Devsecops Confluent Microservices

Job description

Everforth ECS is seeking a Senior Infrastructure Engineer (AWS / Terraform / EKS) to join the Infrastructure & Cloud Team supporting the C DM Data Service federal programs under DHS CISA. This role focuses on designing, building, and operating secure, repeatable AWS environments within a FedRAMP and ATO-governed context . The engineer will work in an environment where all deployments are infrastructure-as-code, peer-reviewed, and fully auditable. The successful candidate will combine hands-on AWS engineering depth with a strong sense of operational discipline, automation, and compliance awareness . This is not just EKS/Terraform build work; it is operational own ership across commercial and GovCloud AWS accounts for connectivity, routing, DNS, F5/load balancing, EKS, Terraform, security remediation, migrations, and stakeholder coordination.

We are seeking dynamic , energetic, and engaging team members who love challenges ! The ideal candidate will be able to align to the following duties:

  • Troubleshoot and support enterprise load- balancing and ingress patterns, including F5 or equivalent technologies, DNS, TLS/certificate paths, routing, and endpoint reachability.

  • Coordinate directly with application teams, Security, stakeholders, network owners, and program lea dership to resolve connectivity, access, migraiton , and production readiness issues.

  • Design, build, and maintain Infrastructure-as-Code using Terraform (modules, S3/DynamoDB remote state, OPA/ tfsec policy integration).

  • Provision, upgrade, and manage EKS clusters, including namespaces, Helm-based add-ons (cert-manager, ESO, Confluent Operator), and IAM roles for service accounts.

  • Design, configure, and troubleshoot AWS VPC networking, including routing, TGWs, DNS, DHCP, endpoints, NACLs, and security groups.

  • Implement and secure microservices on EKS with proper connectivity to AWS services (S3, ECR, Secrets Manager, IAM).

  • Automate infrastructure deployments using GitHub Actions (or self-hosted runners), cross-account IAM role assumptions, and CI/CD policy gates.

  • Collaborate with security and applications teams to enforce least-privilege IAM, automate compliance evidence collection, and support RMF/ATO documentation.

  • Diagnose and resolve complex issues spanning containers, Kubernetes networking, and AWS layers (VPC - Zscaler - C - TIPS - SaaS endpoints).

  • Support observability, logging, and monitoring through integration with Elastic, ScienceLogic, or AppDynamics to meet SLA and audit requirements.

  • Mentor and guide junior engineers through knowledge sharing, paired engineering, and process standardization.

  • Evaluate and improve infrastructure design for policy compliance, resiliency, and performance tuning.

  • Develop and maintain SOPs and playbooks that align with program governance.

  • Support legacy-to-CAWS migration activities, including RabbitMQ/app-server connectivity, environment cutover support , dependency discovery, and validation of network paths across lower and production environments .

  • Quickly build working knowledge of inherited environments , document tribal knowledge, create diagrams/runbooks, and transfer operational context to primary and ba ckup owners.

  • Operate within a formal change-control, evidence, and audit expectations, including CR support, implementation evidence, rollback planning, and post -change validation.

Requirements

  • Must be a US citizen with the ability to obtain Public Trust Suitability .

  • Bachelor’s degree or 8 years of relevant experience .

  • 6+ years designing, implementing, securing, and maintaining AWS Cloud infrastructure (CAWS, GovCloud, or equivalent).

  • 5 + years troubleshooting hybrid/cloud network connectivity, including VPC routing, TGW, DNS, DHCP, TLS/certificates , security groups, NACLs, endpoints, and load balancers.

  • 5+ years of experience with Terraform (advanced modules, state management, policy enforcement).

  • 5+ years’ Experience with Kubernetes networking, ingress, CoreDNS , service exposure, node/sec urity group behavior , and connectivity between EKS workloads and AWS/external services.

  • 5+ years of infrastructure experience related to network security

  • Strong networking foundation: TCP/IP, DNS, DHCP, TLS, routing, subnetting, NACLs, and endpoint connectivity.

  • Proficient scripting/automation using Python or Bash, YAML/JSON templating, and Git-based workflows.

  • Experience in security compliance environments (FedRAMP, FISMA, NIST 800-53) and supporting ATO documentation.

  • Demonstrated ability to collaborate cross-functionally with Security, DevSecOps , and CI/CD teams to maintain compliant, auditable infrastructure.

  • Strong communication skills with the ability to interface effectively with stakeholders from engineers to senior management.

Benefits & conditions

Salary: $123,000 - $184,000

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.jofdav.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:24 min

Evaluating formal AWS certifications versus raw practical engineering experience

Jan Giacomelli · LIVE

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

3:47 min

Exploring JSON, CBOR, and JOSE for data serialization

Aaron Russell · LIVE

1:35 min

Centralizing configuration logic with native YAML block references

Matthieu Vincent Matthieu Vincent · Europe 2026 Virtual

3:50 min

Queues in TCP stacks and continuous network connections

Clemens Vasters Clemens Vasters · World Congress 2022

2:03 min

Distinguishing type definition constructs from data validation routines

Clemens Vasters Clemens Vasters · World Congress 2025

Videos

See all

Related articles

See all