Senior Cloud & DevOps Engineer - 23416-1

Sumeru Solutions
  • NULL, NULL
  • Remote
  • Quick Apply
8 days ago

Job Description

Job Title: Senior Cloud & DevOps Engineer

Location: Remote

Role Overview

The Senior Cloud & DevOps Engineer is a hybrid role that combines cloud infrastructure expertise with DevOps platform engineering to support the AWS GovCloud Landing Zone modernization program. This individual will both architect and operate core cloud infrastructure components - including multi-account networking, IAM, and security services - while simultaneously building and maintaining CI/CD pipelines, Terraform modules, and Kubernetes-based provisioning workflows. The role is ideal for a hands-on engineer who can bridge cloud platform operations with software delivery practices in a FedRAMP/IL2-compliant environment.

Required Qualifications

8+ years of combined cloud and DevOps/platform engineering experience.

Strong AWS expertise: VPC, Transit Gateway, Network Firewall, IAM, EKS, Security Hub, GuardDuty, KMS, CloudTrail, and S3.

Expert-level Terraform skills including module development, TFE, state management, and OIDC integration.

Deep GitLab CI/CD experience: pipeline authoring, runners, registry management, and GitOps workflows.

Solid Kubernetes experience (EKS or equivalent): cluster administration, RBAC, Helm, Kustomize, and security hardening.

Working knowledge of FIPS 140-2 requirements applied to networking, encryption, and secrets management.

Experience with centralized logging, SIEM integration (Splunk/Cribl), and observability tooling (Prometheus, Grafana, Fluent Bit).

Familiarity with FedRAMP, FISMA, NIST SP 800-53, or DoD IL2 compliance frameworks.

U.S. Citizenship required for onshore role - GovCloud access requires US-persons confirmation.

Preferred Qualifications

AWS Certified DevOps Engineer - Professional and/or AWS Certified Solutions Architect - Professional.

Certified Kubernetes Administrator (CKA) or Certified Kubernetes Security Specialist (CKS).

Experience supporting a FedRAMP, C3PAO, or DoD IL2 authorization process.

Familiarity with eMASS, AWS Audit Manager, and NIST SP 800-37 Risk Management Framework.

Exposure to supply-chain security frameworks: SLSA, Sigstore, Cosign, and OPA/Gatekeeper.

Experience with Terraform Enterprise and GitLab Dedicated for Government deployments.

Prior engagement on USG or FedRAMP cloud migration or modernization programs.

Key Responsibilities

Cloud Infrastructure

Design and deploy multi-account VPC architecture, subnets, route tables, security groups, Transit Gateway, Network Firewall.

Configure VPC Endpoints, FIPS-compliant AWS service access, and Route 53 DNS (private hosted zones, resolver rules).

Implement AWS IAM governance: permission boundaries, SCPs, cross-account roles, and federated identity (Entra ID / GCC High).

Deploy and operationalize AWS security services: Security Hub, GuardDuty, Macie, KMS (FIPS 140-2), and Secrets Manager.

Set up centralized logging: CloudTrail with Object Lock, AWS Security Lake, VPC Flow Logs, and SIEM integration via Splunk/Cribl.

Configure AWS Config conformance packs aligned to NIST 800-53 / FedRAMP controls and support AWS Audit Manager evidence collection.

DevOps & CI/CD Platform

Build and maintain reusable Terraform modules converted from CloudFormation (LZA Universal Config to multi-account TF modules).

Deploy and configure GitLab Dedicated for Government and Terraform Enterprise (TFE) - including OIDC integration and encrypted state management.

Implement CI/CD pipelines for CFB application deployments NPE and production environments.

Design and operate Kubernetes (CKP) provisioning pipelines via GitLab CI/CD and TFE; manage cluster lifecycle across NPE and PROD.

Apply Kubernetes security hardening: RBAC, network policies, pod security standards, mTLS, and FIPS-compliant configurations.

Deploy and maintain observability stack: Prometheus, Grafana, and Fluent Bit across CKP clusters.

Implement supply-chain security controls including container image scanning, SBOM, and admission controllers.

Support DR exercises, runbook development, and operational readiness activities.

Numbers & Facts

LocationNULL, NULL (
Remote
)

More jobs like this

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.