ECS is seeking a Senior Cloud Engineer / Data Integration Lead to work at our Oahu, HI location.
ECS is seeking a seasoned Senior Cloud Engineer / Data Integration Lead to support the development, implementation, and deployment of Amicus, our premier Mission Partner Environment (MPE) supporting USINDOPACOM. Operating within the Microsoft Isolated Secret Region (MS-ISR) Azure RX cloud enclave, Amicus is an Impact Level 6 (IL6) Data-Centric Zero Trust environment under an active Authorization to Operate (ATO) at the Secret Releasable (SEC REL) classification level. This role requires a blend of deep cloud engineering expertise, tactical command and control (C2) systems integration, and hands-on deployment experience. The selected engineer will act as the principal data integrator, bringing together critical Common Operating Picture (COP) systems and data pipelines to support the upcoming Olympus Fires operational demonstration in October 2026. The ideal candidate will possess a background similar to elite Field Support Engineers (FSEs) from advanced defense data-analytics programs (e.g., Maven Smart System/Palantir). They must be highly proficient in building data-centric pipelines, working with complex data ontologies, and deploying robust cloud-native tools directly to warfighters in the Pacific theater.
Note on Location & Support Structure: You are backed by a dedicated, back-end engineering / core development team and Director + Program Management team based at our Northern Virginia headquarters (Fairfax/Springfield and Fort Meade). You will start in Virginia to align with the core developers, clear onboarding, and gain necessary enclave access. Following this integration phase, you will deploy to INDOPACOM (Oahu, Hawaii) for a minimum of 9 months to serve as the theater's lead integrator, technical authority, and operator liaison. Following the initial 9-month theater deployment, you will have the option to either remain on-site supporting USINDOPACOM in Oahu, Hawaii, or transition back to corporate headquarters in Fairfax, VA, or Fort Meade, MD. This flexibility is enabled because the Amicus MPE effort is a key pillar of DISA’s enduring Combatant Command Integration Environment (CIE) operations, which are actively being scaled and implemented across all global Combatant Commands (CCMDs) and Areas of Responsibility (AORs).
Position Responsibilities:
- Design, build, and maintain data integration pipelines to ingest, parse, normalize, and visualize operational data from major C2 and Common Operating Picture (COP) systems.
- Target and integrate data from systems such as Global Command and Control System (GCCS), Maven Smart System (MSS), and other critical INDOPACOM situational awareness tools. Specifically, engineer data ingest, track correlation, and synchronization pathways for the following platforms:
- BODHI (or BOHDI): Ingesting all-source data network development, human factors analysis, and targeting database streams.
- SNC TRAX: Integrating digital grid battle network data, tactical radio translations, and high-speed Cursor-on-Target (CoT) gateway telemetry.
- Joint Fires Network (JFN): Integrating sensor feeds into USINDOPACOM’s Persistent Targeting-Quality Common Operating Picture (PT-COP).
- Integrated Air and Missile Defense (IAMD) Battle Command System (IBCS): Conducting sensor-to-shooter data correlation across multi-domain defense frameworks.
- Advanced Battle Management System (ABMS) & Tactical Operations Center-Light (TOC-L): Integrating telemetry and real-time aerial sensor data feeds.
- Common Mission Control Center (CMCC): Integrating space and cyber intelligence data flows into the joint tactical network.
- Joint Automated Deep Operations Coordination System (JADOCS): Supporting joint targeting, validation, and deep fires coordination data flows.
- Anduril Lattice & Menace Systems: Facilitating software-defined edge compute, sensor tracking, and machine-to-machine tasking integrations.
- Palantir Gotham & Foundry: Structuring comprehensive data ontologies to synchronize operational, intelligence, and contested logistics metrics.
- AIR6500 (Joint Air Battle Management System): Supporting bilateral C2 interoperability with coalition partner air defense architectures (e.g., Australian Defence Force).
- Radiant Mercury (RM): Utilizing cross-domain solutions (CDS) to sanitize and safely ingest high-side data feeds into the Secret Releasable MPE enclave.
- All Partners Access Network (APAN): Supporting data exchange and unclassified coordination tools for humanitarian and disaster relief (HADR) missions.
- Develop interfaces, APIs, and middleware to host or pull data from external tactical systems directly into the Amicus MPE.
- Coordinate closely with theater stakeholders to implement data mesh and data-centric security policies, ensuring proper data marking and access control at the Secret Releasable level.
- Maintain and expand the Amicus collaboration suite within the MS-ISR Mission Plane, leveraging state-of-the-art secure software tools:
- Identity & Access Management (ICAM): Deploy and federate PingFederate (IdP) and PingDirectory Server to secure user identity data at scale.
- Data-Centric Security (DCS): Implement and configure the Virtru Data Security Platform (v2.0.5.1+) to enable Attribute-Based Access Control (ABAC), encrypt Microsoft Exchange outbound mail flow via Virtru Gateways, and protect SharePoint file shares.
- Data Labeling & Tagging: Configure Titus (Fortra's Data Classification Suite) to enforce Tetragraph and visual classification labeling on unstructured and semi-structured data.
- Secure Chat: Deploy and federate Matrix (end-to-end encrypted) and Openfire (XMPP) chat systems, enabling secure, federated messaging across Five Eyes (FVEY) networks.
- Secure Voice & Video: Configure and secure Pexip for cross-domain, FIPS 140-3 validated, and Zero Trust-compliant voice and video collaboration.
- Infrastructure Enablers: Implement and harden Palo Alto firewalls and maintain directory synchronization.
- Manage:
- Secure cloud-native infrastructure in Microsoft Azure RX (IL6), Microsoft Isolated Secret Region (MS-ISR), AWS GovCloud, and other classified environments, utilizing Terraform for Infrastructure as Code (IaC) automation.
- Network Time Protocol (NTP) routing within MS-ISR utilizing Azure VM IC Time Synchronization Provider services.Design and implement a robust, two-tier Public Key Infrastructure (PKI) system using an Offline Root Certificate Authority (CA) and hardware-based cryptographic keys managed via Hardware Security Modules (HSMs).
- Monitor security compliance, vulnerability remediations, STIG compliance, and patch management in both classified and releasable enclaves.
- Deploy to USINDOPACOM (Oahu, Hawaii) for a minimum of 9 months to provide dedicated on-island engineering, system integration, and direct operator feedback loops.
- Act as the single point of contact and subject matter expert (SME) on-site for the Amicus C2 integration effort, bridging the gap between developers in Virginia and operators in theater.
- Support the federation of Amicus core services with the INDOPACOM Mission Network (IMN), the Collaborative Partner Environment (CPE), the Canadian Operational Mission Network (COMN-P/COMN-E), and the UK Ramsey environment in preparation for the October 2026 Olympus Fires demonstration.
- Facilitate knowledge transfer, hands-on training, and technical handoffs between ECS engineering, theater commands, and mission partners.
- Other duties, as assigned.
Salary Range: $170,000-210,000
General Description of Benefit
Preferred Qualifications- U.S. Citizen.
- Active, current TS/SCI security clearance.
- Bachelor of Science in Computer Science, Engineering, Information Systems (or equivalent practical experience) with:
- 7+ years of technical IT platform implementation experience.
- 5+ years of hands-on experience delivering customer-facing cloud projects (AWS and/or Azure).
- 3+ years of experience in technical leadership, field systems integration, or deployment support.
- Active DoD 8140 IAT Level II Security+ (or higher).
- Deployment Readiness: Must be fully willing and able to deploy to Oahu, Hawaii for a minimum of 9 continuous months.
- C2 & Tactical System Familiarity: Proven experience working with or integrating military C2/COP systems, specifically GCCS, Maven Smart System (MSS), or any PACOM COP / C2 System.
- Data-Centric Capabilities: Demonstrated experience working with high-performance data platforms (e.g., Palantir Foundry/Gotham, Maven ecosystem) with a focus on building data ontologies, data pipelines, and implementing data-centric security architectures.
- Collaboration & Security Software Stack: Direct experience deploying, configuring, or maintaining at least three of the following: Virtru, PingFederate, Titus/Tetragraph, Pexip, Matrix, or Openfire.
- DevOps & IaC Tooling:
- Advanced proficiency building Infrastructure as Code (IaC) utilizing Terraform.
- Hands-on experience with containerization and orchestration using Kubernetes and Docker.
- Strong DevOps pipeline experience using GitLab CI/CD, configuration management tools, and automated testing frameworks.
- Cloud & Networking Depth:
- Strong working knowledge of cloud-native services (AWS Lambda, IAM, RDS, S3, EC2, CloudWatch, Sagemaker).
- Advanced IP networking skills including VPCs, VPNs, VRF, DNS, load-balancing, and secure cross-domain solutions.
- Operating Systems & Scripting:
- Expertise in administering, hardening (STIGing), and patching Linux/Red Hat enterprise environments.
- Advanced scripting experience with Python, PowerShell, and Bash.
- DoD Compliance: Must possess an active DoD 8570.01-M IAM Level I certification or higher (e.g., Security+ CE, CAP, CND, or Cloud+).
- Strong problem-solving and decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate solution.
- Highly developed interpersonal and oral/written communication skills, with the ability to effectively and professionally interact with a diverse set of stakeholders (from peers to end-users to executive management).
Skills Required
- U.S. citizenship
- Active, current TS/SCI security clearance
- Bachelor of Science in Computer Science, Engineering, Information Systems, or equivalent practical experience
- 7+ years of technical IT platform implementation experience
- 5+ years of hands-on customer-facing cloud project delivery using AWS and/or Azure
- 3+ years of technical leadership, field systems integration, or deployment support experience
- Active DoD 8140 IAT Level II Security+ or higher
- Willingness and ability to deploy to Oahu, Hawaii for at least nine continuous months
- Experience integrating military C2/COP systems, including GCCS, Maven Smart System, or PACOM C2 systems
- Experience with Palantir Foundry/Gotham or Maven data platforms, data ontologies, data pipelines, and data-centric security
- Direct experience deploying, configuring, or maintaining at least three of Virtru, PingFederate, Titus/Tetragraph, Pexip, Matrix, or Openfire
- Advanced Terraform Infrastructure as Code experience
- Hands-on Kubernetes and Docker experience
- Strong GitLab CI/CD, configuration management, and automated testing experience
- Strong knowledge of AWS cloud-native services, including Lambda, IAM, RDS, S3, EC2, CloudWatch, and SageMaker
- Advanced IP networking skills including VPCs, VPNs, VRF, DNS, load balancing, and cross-domain solutions
- Expertise administering, hardening, STIGing, and patching Linux/Red Hat enterprise environments
- Advanced scripting experience with Python, PowerShell, and Bash
- Active DoD 8570.01-M IAM Level I certification or higher, such as Security+ CE, CAP, CND, or Cloud+
- Strong problem-solving, decision-making, interpersonal, oral, and written communication skills
ECS Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about ECS and has not been reviewed or approved by ECS.
-
Healthcare Strength — ECS advertises multiple national-network medical plan options with HSA eligibility alongside dental and vision coverage. Coverage generally begins quickly and is paired with company-paid short- and long-term disability, adding stability to the health package.
-
Retirement Support — A 401(k) with Safe Harbor and immediate vesting on employer contributions is emphasized, with an employer match available. Access to an employee stock purchase plan via the parent company provides an additional savings avenue.
-
Parental & Family Support — Paid parental leave up to 30 days, adoption assistance, and other family-oriented leaves are highlighted. Feedback suggests these offerings add meaningful value beyond base pay for many roles.
ECS Insights
What We Do
ECS, a segment of ASGN (NYSE: ASGN), delivers advanced solutions and services in cloud, cybersecurity, artificial intelligence (AI), machine learning (ML), application and IT modernization, and science and engineering. The company solves critical, complex challenges for customers across the U.S. public sector, defense, intelligence and commercial industries. ECS maintains partnerships with leading cloud, cybersecurity, and AI/ML providers and holds specialized certifications in their technologies. Headquartered in Fairfax, Virginia, ECS has more than 3,400 employees throughout the U.S. and has been recognized as a Top Workplace by The Washington Post for the last five years.








