Senior Cloud Systems Administrator / DevSecOps Security Engineer with Security Clearance
Quick Overview
Job Description
AMERICAN SYSTEMS is an employee-owned federal government contractor supporting national priority programs through our strategic solutions in the areas of Information Technology, Engineering && Analysis, Test && Evaluation, and Training. Responsibilities Operate, sustain, automate, continuously improve, and secure DTE&&A Data Management Platform (DDMP) environments across development, test, training, and production, with emphasis on availability, configuration compliance, observability, release support, and user-impacting operational excellence. This hybrid role combines senior system administration, site reliability engineering, cloud operations, DevSecOps, cybersecurity engineering, and RMF/ATO support for an IL5 CUI system.
Key Responsibilities
- Administer and sustain DDMP cloud environments across Development, Test, Training, and Production.
- Operate the managed Kubernetes environment supporting DDMP containerized application services, including deployment support, capacity monitoring, auto-scaling, patching, upgrades, and incident troubleshooting.
- Maintain cloud infrastructure, networking, storage, managed databases, integrations, service endpoints, certificates, and DNS in accordance with approved architecture and security baselines.
- Support the transition from the current VDI-hosted Linux/Windows server model to an elastic, multi-AZ, cloud-native platform.
- Maintain backup, recovery, high-availability, disaster-recovery, and restore-validation procedures for application, database, configuration, and infrastructure assets.
- Monitor availability, latency, performance, capacity, backup success, error rates, deployment health, and cloud-resource utilization.
- Develop operational dashboards and service-level metrics to support mission leadership and platform engineering decisions.
- Administer, maintain, and improve CI/CD pipelines for application, infrastructure, database, and configuration releases.
- Implement repeatable, auditable deployment and rollback procedures for Test, Training, and Production environments.
- Embed automated security checks into CI/CD pipelines, including source-code, dependency, secrets, container-image, IaC, and vulnerability scanning.
- Maintain secure artifact repositories, container registries, versioned configuration baselines, deployment manifests, and release evidence.
- Serve as the technical cybersecurity operations lead for DDMP, partnering with the cloud architect and program security stakeholders.
- Implement and maintain cloud IAM, Kubernetes RBAC, least-privilege access, service identities, secrets management, encryption, key management, and privileged-access contr ols.
- Operate continuous security monitoring, centralized audit logging, threat detection, security alerting, and vulnerability-management processes.
- Coordinate ACAS/Nessus scans, assess findings, validate remediation, document false positives or mitigations, and manage vulnerabilities through closure.
- Apply, validate, document, and sustain required DISA STIG and SRG configurations for operating systems, containers, Kubernetes, databases, applications, and supporting infrastructure.
- Support RMF and ATO activities by collecting, organizing, and maintaining technical evidence for implemented contr ols and continuous monitoring.
- Maintain POA&&M items, security risk registers, remediation plans, and compliance status reports. Qualifications
- BS Degree
- 11+ years of progressively responsible experience in systems administration, cloud operations, DevSecOps, cybersecurity engineering, site reliability engineering, or a comparable infrastructure/security discipline.
- 3+ years of experience operating cloud-hosted, containerized, or hybrid enterprise applications in production.
- Strong Linux systems-administration experience, preferably Ubuntu and Red Hat Enterprise Linux or derivatives; working knowledge of Windows Server is required for transition from the current DDMP state.
- Top Secret Clearance with SCI eligibility
- Proven hands-on experience administering Docker and Kubernetes, including, cluster and workload operations; Namespace, RBAC, resource quota, ingress, storage, and network-policy management; Helm or equivalent package/deployment tooling; pod, node, container, certificate, networking, and deployment troubleshooting; and upgrade, patching, backup, recovery, scaling, and availability procedures.
- Direct experience supporting a DoD IL5 environment, a DISA-hosted service, NIPRNET-connected workloads, or a system operating under a DoW ATO.
- Experience supporting CAC/PKI-based authentication, ICAM federation, certificate lifecycle management, and zero-trust access patterns.
- Experience performing or supporting ISSO, ISSM, SCA-V, security-contr ol assessor, ATO, or continuous-monitoring functions.
- Experience developing or maintaining RMF artifacts, including, System Security Plan; Contr ol Implementation statements; Contr ol Inheritance matrices; Security Assessment evidence; POA Continuous-monitoring Strategy; Incident-response Plan; and Contingency Plan and Disaster-recovery Test evidence.
- Experience with eMASS or another DoW governance, risk, and compliance system.
- Experience with GitLab security capabilities or equivalent tools for static application security testing, dynamic application security testing, software composition analysis, secrets detection, container image scanning, infrastructure-as-code scanning, and SBOM generation and software supply-chain contr ols.
- Experience implementing Kubernetes security contr ols, including workload identity, pod-security standards, admission contr ol, image provenance, runtime protection, network segmentation, and audit logging.
- Experience with Splunk, Elastic, Prometheus, Grafana, OpenTelemetry, cloud-native monitoring, or comparable observability platforms.
- Experience administering PostgreSQL, including backup and restoration validation, maintenance, performance triage, replication monitoring, access contr ols, and encryption.
- Experience securing API gateways, REST/GraphQL APIs, API tokens, service-to-service authentication, and external-system integrations.
- Experience supporting Microsoft 365/SharePoint Online integrations, especially where SharePoint serves as an authoritative artifact repository.
- Familiarity with the security considerations for managed AI/LLM services, including CUI/data-boundary protection, access contr ols, audit logging, prompt/data retention, output validation, and human-in-the-loop decision processes.
- Experience with ITIL-aligned incident, problem, change, configuration, and service-level management.
Pay Transparency Statement AMERICAN SYSTEMS is committed to pay transparency for our applicants and employee-owners. The salary range for this position is USD $135,000.00/Yr.
- USD $195,000/Yr. Actual compensation will be determined based on several factors permitted by law. AMERICAN SYSTEMS provides for the welfare of its employees and their dependents through a comprehensive benefits program by offering healthcare benefits, paid leave, retirement plans, insurance programs, and education and training assistance.
EEO Statement EEO Race/Sex/Disability Status/Veteran Status
Similar jobs
- TC
Cloud Network Engineer II
NewTrinite Consulting Group LLC
Farmington Hills, MI🇺🇸Hybrid20 hours agoDockerAWSEncryption+16Technology - CS
AWS Senior Cloud Engineer
NewCompest Solutions Inc
United States🇺🇸Hybrid20 hours agoAWSTechnology - HM
Clous Engineer (Cloud Engineer 2) - 30446 with Security Clearance
NewHII Mission Technologies
Hurlburt Field, FL🇺🇸$74.5k - $105k/yrOn-site20 hours agoDockerAWSMachine Learning+14Technology - PH
Senior Cloud / Server Engineer
NewPhoton
Atlanta, GA🇺🇸Hybrid20 hours agoMicroservicesMongoDBSQL+10Technology - PE
Mid-Level Network Engineer with Security Clearance
NewPeopleTec
Huntsville, AL🇺🇸Hybrid20 hours agoAnsibleTechnology - VT
Oracle Cloud Infrastructure
NewVRN Technologies
Phoenix, AZ🇺🇸Hybrid20 hours agoOracleEncryptionPhoenixTechnology