> Markdown version of [/jobs/ext/735511-security-infrastructure-engineer-sovereign-zero-trust](https://www.wearedevelopers.com/jobs/ext/735511-security-infrastructure-engineer-sovereign-zero-trust). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security & Infrastructure Engineer - Sovereign Zero-Trust - **Company:** Bison Bison Cooperative Association - **Location:** San Francisco, CA, United States - **Experience:** Expert - **Salary:** $140,000.0 - $180,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Audit Trail, Computer Networks, Continuous Integration, Domain Name System (DNS), Key Management, Network Architecture, Public Key Infrastructure, Role-Based Access Control, Zero Trust Network Access, SAP (Applications), Kubernetes, Hashicorp, Static Application Security Testing, Dynamic Application Security Testing - **Published:** June 29, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=a2025e4693332c78 ## About the Role * 5+ years security engineering with 2+ years at senior level * Expert in zero-trust air-gapped architecture, sovereign security deployment (HIPAA/FedRAMP/ITAR), cryptographically signed agentic access controls (SAP/RBAC/ABAC), and immutable audit trail design (JSONL/OpenTelemetry) across DoD and international jurisdictions * Zero-trust architecture: SPIFFE/SPIRE, mTLS, and PKI design at depth * Cryptography implementation: Ed25519, ECDSA P-256, AES-256-GCM, TLS 1.3 * Kubernetes security: RBAC, pod security standards, network policies, and secrets management * Secrets management: HashiCorp Vault or OpenBao - rotation, audit logging, and access policies * Air-gapped or classified system security experience required ## Description * Architect end-to-end sovereign security posture across all deployment environments - including zero-trust air-gapped network isolation with no external egress, HIPAA/FedRAMP/ITAR compliance readiness, and certified deployment across 20+ international jurisdictions and DoD environments * Enforce cryptographically signed agentic access controls via the Signed Action Protocol (SAP), with RBAC/ABAC governing both human and agent principals across every sovereign stack deployment * Maintain immutable JSONL audit trails with OpenTelemetry instrumentation across all agent actions, ensuring every deployment can be fully demonstrated, audited, and certified within a 30-minute live review * Design and implement zero-trust network architecture: SPIFFE/SPIRE workload identity and mTLS on all inter-service paths * Build per-country sovereign PKI: Ed25519 root CAs, TLS cert lifecycle management, and sovereign certificate issuance * Implement the Signed Action Protocol: ECDSA P-256 signing on all agent actions and signature verification * Deploy and maintain secrets management via OpenBao (sovereign Vault fork): rotation policies and audit logging * Own the air-gap certification process: tcpdump verification, DNS egress blocking, and namespace isolation * Enforce data residency via Kubernetes network policies, namespace boundaries, and per-country egress rules * Integrate security scanning (SAST/DAST) into the CI/CD pipeline with automated credential exposure detection ## Related Videos - [Trust Issues: Because Zero-Trust Isn’t Optional Anymore](https://www.wearedevelopers.com/videos/100089-trust-issues-because-zero-trust-isn-t-optional-anymore) - [Bridging AI and Nomad: a Go-based MCP Server for Cluster Control](https://www.wearedevelopers.com/videos/2063-bridging-ai-and-nomad-a-go-based-mcp-server-for-cluster-control) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [Securing Secrets in the GitOps era](https://www.wearedevelopers.com/videos/546-securing-secrets-in-the-gitops-era) - [No Keys for the Robot: GitOps as the Control Plane for Autonomous Agents](https://www.wearedevelopers.com/videos/100095-no-keys-for-the-robot-gitops-as-the-control-plane-for-autonomous-agents) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)