Position Details
Senior DevSecOps Engineer- Cloud Migration
- Location
- Remote
- Work Setting
- Hybrid
- Employment Type
- Full Time
Position Overview
We are seeking a Senior DevSecOps Engineer to lead the migration of mission systems and applications from on-premise data centers into U.S. Government cloud environments, specifically Microsoft Azure Government and AWS GovCloud (US). In this role you will own the technical strategy for embedding security into every stage of the migration and delivery lifecycle, set standards for infrastructure automation and pipeline security, and drive compliance with federal security requirements across the program. You will serve as a technical lead and mentor, partnering directly with program stakeholders, ISSOs, and Authorizing Officials to re-platform legacy systems securely and with minimal disruption to operations.
Responsibilities
• Lead the planning and execution of migrations from on-premise environments to Azure Government and AWS GovCloud (US), selecting and directing rehost, replatform, and refactor strategies across the program.
• Define and govern Infrastructure as Code standards and reusable modules (Terraform, ARM/Bicep, and/or AWS CloudFormation) to ensure repeatable, auditable, and version-controlled environments at scale.
• Architect secure, enterprise-grade CI/CD pipelines (Azure DevOps, GitLab CI, GitHub Actions, Jenkins) and establish organization-wide security scanning and testing standards.
• Own the strategy for SAST, DAST, SCA, secrets scanning, and container image scanning; define security gate policy and drive remediation across teams.
• Lead the application of DISA STIGs, CIS Benchmarks, and NIST 800-53 controls, and own FedRAMP, FISMA, ATO, and continuous monitoring (ConMon) processes as primary technical point of contact with ISSOs and Authorizing Officials.
• Set direction for containerization and Kubernetes (AKS/EKS) orchestration strategy, including secure configuration standards and image supply-chain controls across multiple teams or programs.
• Architect least-privilege access models using IAM, Azure AD/Entra ID, RBAC, and enterprise secrets management (HashiCorp Vault, AWS Secrets Manager, Azure Key Vault).
• Own the observability strategy, standing up and governing monitoring, logging, and alerting platforms (CloudWatch, Azure Monitor, ELK, Splunk, Prometheus/Grafana) across the program.
• Design secure landing zone architecture, VPCs/VNets, transit connectivity, firewalls, and hybrid links (ExpressRoute, Direct Connect, VPN) for phased, multi-workload migrations.
• Mentor junior and mid-level engineers, review technical designs, act as primary liaison to ISSOs and senior program stakeholders, and approve runbooks, migration plans, and architecture diagrams.
• Define and govern Infrastructure as Code standards and reusable modules (Terraform, ARM/Bicep, and/or AWS CloudFormation) to ensure repeatable, auditable, and version-controlled environments at scale.
• Architect secure, enterprise-grade CI/CD pipelines (Azure DevOps, GitLab CI, GitHub Actions, Jenkins) and establish organization-wide security scanning and testing standards.
• Own the strategy for SAST, DAST, SCA, secrets scanning, and container image scanning; define security gate policy and drive remediation across teams.
• Lead the application of DISA STIGs, CIS Benchmarks, and NIST 800-53 controls, and own FedRAMP, FISMA, ATO, and continuous monitoring (ConMon) processes as primary technical point of contact with ISSOs and Authorizing Officials.
• Set direction for containerization and Kubernetes (AKS/EKS) orchestration strategy, including secure configuration standards and image supply-chain controls across multiple teams or programs.
• Architect least-privilege access models using IAM, Azure AD/Entra ID, RBAC, and enterprise secrets management (HashiCorp Vault, AWS Secrets Manager, Azure Key Vault).
• Own the observability strategy, standing up and governing monitoring, logging, and alerting platforms (CloudWatch, Azure Monitor, ELK, Splunk, Prometheus/Grafana) across the program.
• Design secure landing zone architecture, VPCs/VNets, transit connectivity, firewalls, and hybrid links (ExpressRoute, Direct Connect, VPN) for phased, multi-workload migrations.
• Mentor junior and mid-level engineers, review technical designs, act as primary liaison to ISSOs and senior program stakeholders, and approve runbooks, migration plans, and architecture diagrams.
Qualifications
• 8+ years of combined DevOps, cloud engineering, or systems engineering experience, including significant hands-on DevSecOps leadership responsibilities.
• Demonstrated track record leading large-scale migrations of workloads from on-premise environments to public cloud.
• Deep, hands-on expertise with multiple government cloud regions — Azure Government, AWS GovCloud (US), Google, or Oracle.
• Expert-level proficiency with Infrastructure as Code (Terraform, Bicep/ARM, or CloudFormation), including designing reusable module standards.
• Proven experience architecting and securing CI/CD pipelines at scale, including automated security scanning strategy.
• Advanced scripting/automation skills (Python, Bash, PowerShell).
• Deep experience with containerization (Docker) and orchestration (Kubernetes), including multi-cluster or multi-program strategy.
• Strong hands-on experience with federal security frameworks: NIST 800-53, FedRAMP, FISMA, DISA STIGs, and direct experience carrying systems through the ATO lifecycle.
• Experience mentoring engineers and leading technical workstreams or teams.
• Active U.S. Government security clearance and U.S. Citizenship (required).
• Demonstrated track record leading large-scale migrations of workloads from on-premise environments to public cloud.
• Deep, hands-on expertise with multiple government cloud regions — Azure Government, AWS GovCloud (US), Google, or Oracle.
• Expert-level proficiency with Infrastructure as Code (Terraform, Bicep/ARM, or CloudFormation), including designing reusable module standards.
• Proven experience architecting and securing CI/CD pipelines at scale, including automated security scanning strategy.
• Advanced scripting/automation skills (Python, Bash, PowerShell).
• Deep experience with containerization (Docker) and orchestration (Kubernetes), including multi-cluster or multi-program strategy.
• Strong hands-on experience with federal security frameworks: NIST 800-53, FedRAMP, FISMA, DISA STIGs, and direct experience carrying systems through the ATO lifecycle.
• Experience mentoring engineers and leading technical workstreams or teams.
• Active U.S. Government security clearance and U.S. Citizenship (required).