Haystack
← Back to Jobs
Remote
Technology
LT

Jr. Site Reliability Engineer FedRAMP Vulnerability Management

Lorven Technologies, Inc.United States🇺🇸United StatesPosted 4 Sept 2026

Quick Overview

Seniority
Mid Senior
Work mode
Remote
Location
United States
Posted
19 hours ago
RubyAWSAnsibleGitLab CIJiraKubernetesPython

Job Description

Role: Jr. Site Reliability Engineer – FedRAMP Vulnerability Management

Location: Remote – USA – PST Time zone

Contract role

FedRAMP experience is must

 

Job description:

 

Meet the Team

  1. The SRE Compliance & Security Initiatives team is responsible for maintaining the stability, scalability, and efficiency of the infrastructure and applications that power our FedRAMP cloud platform. As a team of five engineers distributed across the US, we combine deep infrastructure expertise with a strong focus on automation, reliability, and operational excellence. We are the primary SRE team working together with more than 20 other teams across SRE and the broader Engineering, Security and Product organizations to support a platform that serves a rapidly growing customer base that currently manages tens of thousands of devices. The team operates with a high degree of autonomy, giving engineers the opportunity to drive both critical initiatives and grassroots improvements that solve real operational challenges. One of our most exciting areas of focus is expanding our ability to build highly automated processes to increase the operational efficiency and security of our cloud environments that support evolving regulatory requirements. Everyone on the team has a voice, and engineers are encouraged to identify problems, propose solutions, and take ownership of improvements that make the platform more reliable and easier to operate.

 

Your Impact

  1. Own findings for FedRAMP Vulnerability Management from intake through validated remediation and closure.  Triage and prioritize host, OS-package, container, base-image, and application-dependency findings using exploitability, asset criticality, and remediation deadlines.  Identify the real source of vulnerable software and determine whether the right action is a dependency update, image rebuild, promotion, host change, deviation, false-positive correction, or ticket cleanup.  Implement or coordinate fixes through Ansible, GitLab CI, package managers, container builds, Artifactory, and Federal promotion-train workflows and validated promoted artifacts.  Validate fixes using effective package versions, build artifacts, image manifests, deployed-host evidence, and scanner rescans before resolving vulnerability tickets.  Maintain Jira evidence, ownership, due-date escalation, exception rationale, backlog metrics, runbooks, automation, and knowledge transfer.  Success will mean reducing the overdue backlog, improving ownership and evidence quality, delivering repeatable automation and runbooks, and transferring a sustainable process to the CSI team for future use.
  2. Develop and maintain automation solutions that improve the reliability, scalability, security and operational efficiency of infrastructure and processes for the hosts in our FedRAMP cloud environments, as well as new innovations that allow us to adjust to changing compliance requirements. Design and enhance deployment pipelines, testing frameworks, and operational tooling to support the continued growth of a platform serving a rapidly growing number of managed devices worldwide. Troubleshoot complex infrastructure and distributed systems issues to ensure high availability while helping teams adapt their infrastructure, applications and processes to FedRAMP controls and requirements. Contribute to critical projects such as refactoring our deployment process, and new cluster build outs by building automation that enables manual toil reduction, as well as rapid and repeatable processes for new purpose-built cloud environments. Partner with other engineering teams, product management, and business partners across multiple teams and time zones to understand platform dependencies, seek opportunities for improvement, and deliver solutions that enhance reliability and performance while reducing operational overhead. 

 

Minimum Qualifications

  1. 2+ years of experience in Site Reliability Engineering, DevOps, Infrastructure Engineering, or a related role supporting cloud-based production environments.
  2. Practical vulnerability-management experience; familiarity with Qualys, JFrog Xray, SCA/SBOM, or equivalent tooling; and working knowledge of dependency-management for Ruby/Bundler, Python/pip, and Go modules. Experience with direct versus transitive dependencies, version constraints, lockfiles, go.mod/go.sum, and verifying the effective version shipped in a built artifact.
  3. Experience developing and maintaining infrastructure automation using Ansible.
  4. Experience administering and troubleshooting Linux-based systems and distributed infrastructure environments.
  5. Experience designing, implementing, and maintaining CI/CD pipelines, including GitLab CI.
  6. Experience supporting large-scale infrastructure environments consisting of hundreds or thousands of systems.
  7. Available to be online from 9am-4pm PST.

 

Preferred Qualifications

  1. Familiarity with AWS or other public cloud platforms and hybrid infrastructure environments.
  2. Knowledge of monitoring, observability, and reliability engineering practices and tooling.
  3. Familiarity with Kubernetes concepts and containerized application platforms.
  4. Experience leveraging AI-assisted development tools to improve software development, automation, operational analysis, and engineering productivity.
  5. Experience managing fleet wide software deployments
  6. Experience providing support and priority incident triage.

Similar jobs