DevSecOps Cloud Engineer

Sorry, this job was removed at 02:17 a.m. (CST) on Thursday, Apr 30, 2026
Be an Early Applicant
Fairfax, VA, USA
In-Office
Artificial Intelligence • Cloud • Information Technology • Security • Software
The Role
Job Summary & Responsibilities

ECS is seeking a DevSecOps Cloud Engineer to work remotely.


Summary: Hands-on infrastructure engineer who owns the day-to-day provisioning, configuration, and operation of all AWS and Azure cloud resources supporting ECS DevLabs. This role is the person writing the Terraform, managing the EKS clusters, configuring IAM policies, maintaining networking, and operating the Big Bang platform. Works closely with the Platform Engineering Lead on architecture decisions and the Security & Compliance Engineer on hardening and control implementation.

This is a deeply technical, hands-on role. The DevSecOps Cloud Engineer writes infrastructure-as-code, debugs cluster issues, configures security services, and keeps the platform running — not managing people or setting strategy. The "DevSecOps" in the title reflects that security is embedded in every infrastructure decision, not bolted on afterward.

Primary Responsibilities:

Infrastructure as Code:

  • Write and maintain Terraform for all AWS infrastructure (EKS, RDS, VPC, IAM, S3, CloudFront, Route 53, KMS, WAF).
  • Manage Terraform state files, backend configurations, and module versioning.
  • Implement infrastructure changes through merge requests with peer review.
  • Maintain reusable Terraform modules (VPC, RDS, IRSA, ELB, node pools).
  • Author and maintain Azure Terraform where applicable (Entra DS, VMs, networking).
  • Handle cloud account onboarding (new AWS accounts, Azure subscriptions).

EKS & Kubernetes Operations:

  • Manage EKS cluster lifecycle (version upgrades, node group scaling, AMI updates).
  • Maintain and upgrade Platform One Big Bang components (Istio, Keycloak, Flux, NeuVector, Grafana, Prometheus, Alert Manager, and many others).
  • Configure and manage Flux GitOps manifests and Helm chart deployments.
  • Manage SOPS-encrypted secrets and AWS Secrets Manager entries.
  • Troubleshoot cluster issues (pod scheduling, resource contention, Istio routing, certificate expiration).
  • Manage Kustomization overlays for environment-specific configurations.
  • Coordinate Big Bang version upgrades with SRE for zero-downtime rollouts.

Networking & Security Services:

  • Configure and maintain VPCs, subnets, security groups, NAT gateways, and route tables.
  • Manage load balancers (ALB, NLB) and target group configurations.
  • Maintain ACM certificates and Route 53 DNS records.
  • Configure and tune AWS WAF rules, Shield Advanced protections, and Firewall Manager policies.
  • Manage AWS security service configurations (Security Hub, GuardDuty, Inspector, CloudTrail, Config).
  • Implement network segmentation and firewall rules per compliance requirements.
  • Configure VPN tunnels and cross-cloud connectivity (AWS ↔ Azure).

IAM & Access Control:

  • Implement and maintain IAM policies, cross-account roles, and permission boundaries.
  • Configure Pod Identity Associations (PIA) and IRSA for Kubernetes workloads.
  • Manage AWS SSO permission sets and account assignments.
  • Manage Azure service principles, Entra ID app registrations, and Graph API permissions.
  • Implement least-privilege access patterns and review IAM policy drift.
  • Rotate service account credentials and API keys on schedule.

Database & Storage:

  • Manage RDS PostgreSQL instances (provisioning, parameter groups, maintenance windows, snapshots).
  • Configure ElastiCache clusters and connection parameters.
  • Manage S3 bucket policies, lifecycle rules, and replication configurations.
  • Configure EBS encryption defaults and Data Lifecycle Manager snapshot policies.
  • Manage CUR/Athena/Glue configuration for cost reporting.

Operational:

  • Monitor and optimize cloud spend across all accounts, flag anomalies to Platform Lead.
  • Address infrastructure-related P1/P2/P3 incidents.
  • Document infrastructure decisions and maintain runbooks for common operations.
  • Support the Security & Compliance Engineer with Terraform implementations.
  • Support the SRE with infrastructure changes needed for monitoring, logging, and backup.

Tools Owned:

  • ECS Software Factory (all Terraform modules and state files).
  • EKS cluster configurations and Big Bang component versions.
  • AWS IAM policies (CloudForgeReadRole, CloudForgeAthenaRole, PIA roles, SSO permission sets).
  • VPC architecture, security groups, load balancers, NAT gateways.
  • RDS instances, ElastiCache clusters, S3 buckets.
  • Route 53 DNS records and ACM certificates.
  • WAF rules, Shield configuration, Firewall Manager policies.
  • SOPS encryption keys and Secrets Manager entries.
  • Cloud account provisioning and credential rotation.
  • Azure service principles and Entra ID app registrations.
  • CUR/Athena/Glue cost reporting infrastructure.
  • Other various AWS services and Kubernetes based application deployments.

Salary Range: $150,000 - $190,000 

General Description of Benefits 

Preferred Qualifications
  • 10+ years in cloud infrastructure engineering with AWS (required).
  • Strong Terraform expertise (module authoring, state management, multi-account patterns).
  • Kubernetes administration experience (EKS preferred; node management, RBAC, networking, troubleshooting).
  • Helm chart development and GitOps workflows (Flux or ArgoCD).
  • AWS networking (VPC design, load balancing, DNS, security groups, NAT, VPN).
  • IAM architecture (policies, roles, cross-account trust, OIDC federation, IRSA/PIA).
  • AWS security services (Security Hub, GuardDuty, WAF, CloudTrail, KMS, Config).
  • SOPS and secrets management patterns.
  • PostgreSQL administration fundamentals (RDS configuration, backups, parameter tuning).
  • Scripting (Bash, Python, or Go for automation).
  • Experience with hardened Kubernetes distributions (Big Bang, Iron Bank) preferred.
  • Azure experience (Entra ID, networking, VMs) preferred but not required.
  • Understanding of NIST 800-53 / CMMC controls as they apply to infrastructure.

ECS Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about ECS and has not been reviewed or approved by ECS.

  • Healthcare Strength ECS advertises multiple national-network medical plan options with HSA eligibility alongside dental and vision coverage. Coverage generally begins quickly and is paired with company-paid short- and long-term disability, adding stability to the health package.
  • Retirement Support A 401(k) with Safe Harbor and immediate vesting on employer contributions is emphasized, with an employer match available. Access to an employee stock purchase plan via the parent company provides an additional savings avenue.
  • Parental & Family Support Paid parental leave up to 30 days, adoption assistance, and other family-oriented leaves are highlighted. Feedback suggests these offerings add meaningful value beyond base pay for many roles.

ECS Insights

Similar Jobs

Rackner Logo Rackner

Cloud Platform Engineer

Artificial Intelligence • Cloud • Machine Learning
In-Office
Fort Belvoir, VA, USA
11 Employees

MongoDB Logo MongoDB

Staff Software Engineer

Big Data • Cloud • Software • Database
Easy Apply
Remote or Hybrid
United States
5550 Employees
151K-297K Annually

MetLife Logo MetLife

Principal IAM Engineer

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Remote or Hybrid
United States
43000 Employees
112K-189K Annually

MetLife Logo MetLife

Consultant

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Remote or Hybrid
United States
43000 Employees
59K-99K Annually
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Fairfax, VA
2,129 Employees
Year Founded: 1993

What We Do

ECS, a segment of ASGN (NYSE: ASGN), delivers advanced solutions and services in cloud, cybersecurity, artificial intelligence (AI), machine learning (ML), application and IT modernization, and science and engineering. The company solves critical, complex challenges for customers across the U.S. public sector, defense, intelligence and commercial industries. ECS maintains partnerships with leading cloud, cybersecurity, and AI/ML providers and holds specialized certifications in their technologies. Headquartered in Fairfax, Virginia, ECS has more than 3,400 employees throughout the U.S. and has been recognized as a Top Workplace by The Washington Post for the last five years.

Similar Companies Hiring

Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Software
US
100 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account