Senior Cloud Systems Administrator / DevSecOps Security Engineer

Posted 3 Hours Ago
Be an Early Applicant
Alexandria, VA, USA
In-Office
135K-195K Annually
Senior level
Aerospace • Information Technology • Professional Services • Defense
The Role
Operate and secure IL5 cloud environments across development, test, training, and production. Administer Kubernetes, infrastructure, databases, CI/CD pipelines, observability, backups, and disaster recovery. Implement DevSecOps security scanning, IAM, secrets management, vulnerability remediation, STIG compliance, audit logging, and continuous monitoring. Support RMF/ATO documentation, POA&M management, cybersecurity operations, and platform modernization from VDI-hosted systems to a cloud-native architecture.
Summary Generated by Built In
Overview

AMERICAN SYSTEMS is an employee-owned federal government contractor supporting national priority programs through our strategic solutions in the areas of Information Technology, Engineering & Analysis, Test & Evaluation, and Training.

Responsibilities

Operate, sustain, automate, continuously improve, and secure DTE&A Data Management Platform (DDMP) environments across development, test, training, and production, with emphasis on availability, configuration compliance, observability, release support, and user-impacting operational excellence. This hybrid role combines senior system administration, site reliability engineering, cloud operations, DevSecOps, cybersecurity engineering, and RMF/ATO support for an IL5 CUI system.

 

Key Responsibilities

  • Administer and sustain DDMP cloud environments across Development, Test, Training, and Production.
  • Operate the managed Kubernetes environment supporting DDMP containerized application services, including deployment support, capacity monitoring, auto-scaling, patching, upgrades, and incident troubleshooting.
  • Maintain cloud infrastructure, networking, storage, managed databases, integrations, service endpoints, certificates, and DNS in accordance with approved architecture and security baselines.
  • Support the transition from the current VDI-hosted Linux/Windows server model to an elastic, multi-AZ, cloud-native platform.
  • Maintain backup, recovery, high-availability, disaster-recovery, and restore-validation procedures for application, database, configuration, and infrastructure assets.
  • Monitor availability, latency, performance, capacity, backup success, error rates, deployment health, and cloud-resource utilization.
  • Develop operational dashboards and service-level metrics to support mission leadership and platform engineering decisions.
  • Administer, maintain, and improve CI/CD pipelines for application, infrastructure, database, and configuration releases.
  • Implement repeatable, auditable deployment and rollback procedures for Test, Training, and Production environments.
  • Embed automated security checks into CI/CD pipelines, including source-code, dependency, secrets, container-image, IaC, and vulnerability scanning.
  • Maintain secure artifact repositories, container registries, versioned configuration baselines, deployment manifests, and release evidence.
  • Serve as the technical cybersecurity operations lead for DDMP, partnering with the cloud architect and program security stakeholders.
  • Implement and maintain cloud IAM, Kubernetes RBAC, least-privilege access, service identities, secrets management, encryption, key management, and privileged-access controls.
  • Operate continuous security monitoring, centralized audit logging, threat detection, security alerting, and vulnerability-management processes.
  • Coordinate ACAS/Nessus scans, assess findings, validate remediation, document false positives or mitigations, and manage vulnerabilities through closure.
  • Apply, validate, document, and sustain required DISA STIG and SRG configurations for operating systems, containers, Kubernetes, databases, applications, and supporting infrastructure.
  • Support RMF and ATO activities by collecting, organizing, and maintaining technical evidence for implemented controls and continuous monitoring.
  • Maintain POA&M items, security risk registers, remediation plans, and compliance status reports.
Qualifications
  • BS  Degree
  • 11+ years of progressively responsible experience in systems administration, cloud operations, DevSecOps, cybersecurity engineering, site reliability engineering, or a comparable infrastructure/security discipline.
  • 3+ years of experience operating cloud-hosted, containerized, or hybrid enterprise applications in production.
  • Strong Linux systems-administration experience, preferably Ubuntu and Red Hat Enterprise Linux or derivatives; working knowledge of Windows Server is required for transition from the current DDMP state.
  • Top Secret Clearance with SCI eligibility
  • Proven hands-on experience administering Docker and Kubernetes, including, cluster and workload operations; Namespace, RBAC, resource quota, ingress, storage, and network-policy management; Helm or equivalent package/deployment tooling; pod, node, container, certificate, networking, and deployment troubleshooting; and upgrade, patching, backup, recovery, scaling, and availability procedures.
  • Direct experience supporting a DoD IL5 environment, a DISA-hosted service, NIPRNET-connected workloads, or a system operating under a DoW ATO.
  • Experience supporting CAC/PKI-based authentication, ICAM federation, certificate lifecycle management, and zero-trust access patterns.
  • Experience performing or supporting ISSO, ISSM, SCA-V, security-control assessor, ATO, or continuous-monitoring functions.
  • Experience developing or maintaining RMF artifacts, including, System Security Plan; Control Implementation statements; Control Inheritance matrices; Security Assessment evidence; POA&Ms; Continuous-monitoring Strategy; Incident-response Plan; and Contingency Plan and Disaster-recovery Test evidence.
  • Experience with eMASS or another DoW governance, risk, and compliance system.
  • Experience with GitLab security capabilities or equivalent tools for static application security testing, dynamic application security testing, software composition analysis, secrets detection, container image scanning, infrastructure-as-code scanning, and SBOM generation and software supply-chain controls.
  • Experience implementing Kubernetes security controls, including workload identity, pod-security standards, admission control, image provenance, runtime protection, network segmentation, and audit logging.
  • Experience with Splunk, Elastic, Prometheus, Grafana, OpenTelemetry, cloud-native monitoring, or comparable observability platforms.
  • Experience administering PostgreSQL, including backup and restoration validation, maintenance, performance triage, replication monitoring, access controls, and encryption.
  • Experience securing API gateways, REST/GraphQL APIs, API tokens, service-to-service authentication, and external-system integrations.
  • Experience supporting Microsoft 365/SharePoint Online integrations, especially where SharePoint serves as an authoritative artifact repository.
  • Familiarity with the security considerations for managed AI/LLM services, including CUI/data-boundary protection, access controls, audit logging, prompt/data retention, output validation, and human-in-the-loop decision processes.
  • Experience with ITIL-aligned incident, problem, change, configuration, and service-level management.
Pay Transparency StatementAMERICAN SYSTEMS is committed to pay transparency for our applicants and employee-owners. The salary range for this position is USD $135,000.00/Yr. - USD $195,000/Yr. Actual compensation will be determined based on several factors permitted by law. AMERICAN SYSTEMS provides for the welfare of its employees and their dependents through a comprehensive benefits program by offering healthcare benefits, paid leave, retirement plans, insurance programs, and education and training assistance. EEO StatementEEO Race/Sex/Disability Status/Veteran Status

Skills Required

  • Bachelor's degree
  • 11+ years of progressively responsible experience in systems administration, cloud operations, DevSecOps, cybersecurity engineering, site reliability engineering, or a comparable infrastructure/security discipline
  • 3+ years of experience operating cloud-hosted, containerized, or hybrid enterprise applications in production
  • Strong Linux systems administration experience, preferably Ubuntu and Red Hat Enterprise Linux or derivatives
  • Working knowledge of Windows Server
  • Top Secret clearance with SCI eligibility
  • Hands-on experience administering Docker and Kubernetes, including cluster and workload operations, namespaces, RBAC, resource quotas, ingress, storage, network policies, Helm, troubleshooting, upgrades, patching, backup, recovery, scaling, and availability
  • Experience supporting a DoD IL5 environment, DISA-hosted service, NIPRNET-connected workloads, or a system operating under a DoD ATO
  • Experience supporting CAC/PKI-based authentication, ICAM federation, certificate lifecycle management, and zero-trust access patterns
  • Experience performing or supporting ISSO, ISSM, SCA-V, security-control assessor, ATO, or continuous-monitoring functions
  • Experience developing or maintaining RMF artifacts, including System Security Plans, control implementation statements, control inheritance matrices, security assessment evidence, POA&Ms, continuous-monitoring strategies, incident-response plans, and contingency/disaster-recovery test evidence
  • Experience with eMASS or another DoD governance, risk, and compliance system
  • Experience with GitLab security capabilities or equivalent tools for SAST, DAST, software composition analysis, secrets detection, container image scanning, infrastructure-as-code scanning, SBOM generation, and software supply-chain controls
  • Experience implementing Kubernetes security controls, including workload identity, pod-security standards, admission control, image provenance, runtime protection, network segmentation, and audit logging
  • Experience with Splunk, Elastic, Prometheus, Grafana, OpenTelemetry, cloud-native monitoring, or comparable observability platforms
  • Experience administering PostgreSQL, including backup and restoration validation, maintenance, performance triage, replication monitoring, access controls, and encryption
  • Experience securing API gateways, REST/GraphQL APIs, API tokens, service-to-service authentication, and external-system integrations
  • Experience supporting Microsoft 365 and SharePoint Online integrations
  • Familiarity with security considerations for managed AI/LLM services, including CUI/data-boundary protection, access controls, audit logging, data retention, output validation, and human-in-the-loop processes
  • Experience with ITIL-aligned incident, problem, change, configuration, and service-level management
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
2,235 Employees
Year Founded: 1975

What We Do

AMERICAN SYSTEMS is an employee-owned government services contractor that delivers professional, technical, information technology, engineering, analysis, testing, evaluation, and training solutions for complex national-priority programs. Based in McLean, Virginia, the company supports federal customers—particularly defense and other Department of Defense missions—with mission-essential and information engineering, digital engineering, systems integration, cybersecurity, cloud, data, and lifecycle IT services across critical public-sector environments.

Similar Jobs

Spectrum Logo Spectrum

Account Executive

Information Technology • Internet of Things • Mobile • On-Demand • Software
In-Office
Chesapeake, VA, USA
100000 Employees
40K-73K Annually

HiBob Logo HiBob

Sales Manager

HR Tech • Information Technology • Professional Services • Sales • Software
Remote or Hybrid
US
1350 Employees
130K-165K Annually

Capital One Logo Capital One

Artificial Intelligence Engineer

Fintech • Machine Learning • Payments • Software • Financial Services
Hybrid
4 Locations
55000 Employees
230K-286K Annually

Capital One Logo Capital One

Product Manager

Fintech • Machine Learning • Payments • Software • Financial Services
Hybrid
6 Locations
55000 Employees
209K-286K Annually

Similar Companies Hiring

Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Outpost Space Thumbnail
Aerospace • Defense
US
24 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account