Tech Stack
AWSAzureCloudCyber SecurityJenkinsKubernetesPythonTerraformVault
About the role
- Responsible for designing and maintaining cloud infrastructure, CI/CD pipelines, and automation in IL5-compliant deployments
- Design, implement, and manage IL5-compliant infrastructure in AWS GovCloud and/or Azure Government
- Automate infrastructure provisioning using Terraform and Infrastructure-as-Code best practices
- Build and maintain secure CI/CD pipelines in compliance with FedRAMP High / IL5 requirements
- Collaborate with security and compliance teams to ensure proper controls, monitoring, and reporting
- Configure logging, alerting, and telemetry in restricted environments
- Harden operating systems and container runtimes to meet DISA STIGs and other security benchmarks
- Support secure secrets management, access controls (RBAC, ABAC), and audit logging
- Participate in architecture discussions to ensure infrastructure is scalable, resilient, and compliant
- Assist with documentation and evidence collection for audits and ATO processes
- Play a hands-on role in automating, deploying, and securing infrastructure that powers Keeper's cybersecurity platform
- Ensure systems are highly available, scalable, and audit-ready
Requirements
- 5+ years of experience in DevOps, SRE, or Infrastructure Engineering roles
- Hands-on experience with IL5 or FedRAMP High environments (required)
- Deep familiarity with AWS GovCloud or Azure Government
- Strong IaC experience using Terraform, Terragrunt, or similar tooling
- Proficiency in scripting (e.g., Python, Bash) and automating system tasks
- Experience building secure CI/CD workflows (GitHub Actions, Jenkins, GitLab CI)
- Knowledge of STIG hardening, CIS benchmarks, and compliance automation
- Understanding of zero-trust principles and secure enclave architectures
- Ability to work collaboratively with security and compliance stakeholders
- Prior experience contributing to an ATO process for a FedRAMP or DoD deployment (preferred)
- Familiarity with Kubernetes in a high-compliance environment (preferred)
- Experience with secrets management (Vault, AWS KMS, etc.) (preferred)
- Exposure to vulnerability scanning, compliance drift detection, or SIEM integration (preferred)