Position Details
Mid DevSecOps Engineer -Cloud Migration
- Location
- Remote
- Work Setting
- Hybrid
- Employment Type
- Full Time
Position Overview
We are seeking a mid-level DevSecOps Engineer to help migrate mission systems and applications from on-premise data centers into U.S. Government cloud environments, specifically Microsoft Azure Government and AWS GovCloud (US). In this role you will embed security into every stage of the migration and delivery lifecycle, automating the build, deployment, and hardening of workloads while ensuring compliance with federal security standards. You will work alongside cloud architects, application teams, and security engineers to re-platform legacy systems securely, reliably, and with minimal disruption to operations.
Responsibilities
• Plan and execute the migration of on-premise applications, databases, and infrastructure to Azure Government and AWS GovCloud (US) using rehost, replatform, and refactor strategies.
• Build and maintain infrastructure using Terraform, ARM/Bicep, and/or AWS CloudFormation to provision repeatable, auditable, and version-controlled cloud environments.
• Design, implement, and maintain secure CI/CD pipelines (e.g., Azure DevOps, GitLab CI, GitHub Actions, Jenkins) with integrated security scanning and automated testing.
• Integrate SAST, DAST, SCA, secrets scanning, and container image scanning into pipelines; remediate findings and enforce security gates.
• Apply DISA STIGs, CIS Benchmarks, and NIST 800-53 controls; support FedRAMP, FISMA, and Authority to Operate (ATO) processes and continuous monitoring (ConMon).
• Containerize legacy and modern workloads and deploy to Kubernetes (AKS/EKS) or equivalent, with secure configuration and image supply-chain controls.
• Implement least-privilege access using IAM, Azure AD/Entra ID, RBAC, and secrets management (HashiCorp Vault, AWS Secrets Manager, Azure Key Vault).
• Stand up monitoring, logging, and alerting (CloudWatch, Azure Monitor, ELK, Splunk, Prometheus/Grafana) to support operations and security incident response.
• Configure secure landing zones, VPCs/VNets, transit connectivity, firewalls, and hybrid links (ExpressRoute, Direct Connect, VPN) during phased migration.
• Produce runbooks, migration plans, and architecture diagrams; collaborate with ISSOs, application owners, and program stakeholders.
• Build and maintain infrastructure using Terraform, ARM/Bicep, and/or AWS CloudFormation to provision repeatable, auditable, and version-controlled cloud environments.
• Design, implement, and maintain secure CI/CD pipelines (e.g., Azure DevOps, GitLab CI, GitHub Actions, Jenkins) with integrated security scanning and automated testing.
• Integrate SAST, DAST, SCA, secrets scanning, and container image scanning into pipelines; remediate findings and enforce security gates.
• Apply DISA STIGs, CIS Benchmarks, and NIST 800-53 controls; support FedRAMP, FISMA, and Authority to Operate (ATO) processes and continuous monitoring (ConMon).
• Containerize legacy and modern workloads and deploy to Kubernetes (AKS/EKS) or equivalent, with secure configuration and image supply-chain controls.
• Implement least-privilege access using IAM, Azure AD/Entra ID, RBAC, and secrets management (HashiCorp Vault, AWS Secrets Manager, Azure Key Vault).
• Stand up monitoring, logging, and alerting (CloudWatch, Azure Monitor, ELK, Splunk, Prometheus/Grafana) to support operations and security incident response.
• Configure secure landing zones, VPCs/VNets, transit connectivity, firewalls, and hybrid links (ExpressRoute, Direct Connect, VPN) during phased migration.
• Produce runbooks, migration plans, and architecture diagrams; collaborate with ISSOs, application owners, and program stakeholders.
Qualifications
• 3–5 years of combined DevOps, cloud engineering, or systems engineering experience, with hands-on DevSecOps responsibilities.
• Demonstrated experience migrating workloads from on-premise environments to public cloud.
• Hands-on experience with at least one government cloud region — Azure Government, Google, Oracle, or AWS GovCloud (US) — and working knowledge of the others.
• Proficiency with Infrastructure as Code (Terraform, Bicep/ARM, or CloudFormation).
• Experience building and securing CI/CD pipelines and integrating automated security scanning.
• Strong scripting/automation skills (Python, Bash, PowerShell).
• Working knowledge of containerization (Docker) and orchestration (Kubernetes).
• Familiarity with federal security frameworks: NIST 800-53, FedRAMP, FISMA, DISA STIGs, and the ATO lifecycle.
• Active U.S. Government security clearance and U.S. Citizenship (required).
• Demonstrated experience migrating workloads from on-premise environments to public cloud.
• Hands-on experience with at least one government cloud region — Azure Government, Google, Oracle, or AWS GovCloud (US) — and working knowledge of the others.
• Proficiency with Infrastructure as Code (Terraform, Bicep/ARM, or CloudFormation).
• Experience building and securing CI/CD pipelines and integrating automated security scanning.
• Strong scripting/automation skills (Python, Bash, PowerShell).
• Working knowledge of containerization (Docker) and orchestration (Kubernetes).
• Familiarity with federal security frameworks: NIST 800-53, FedRAMP, FISMA, DISA STIGs, and the ATO lifecycle.
• Active U.S. Government security clearance and U.S. Citizenship (required).