Senior SecDevOps - Cyber Monitoring/SaaS Compliance Vendor
Zearch · Virginia, United States
Apply & track with Apply EdgeSenior SecDevOps Engineer — Federal & Defense Managed Cloud Zearch are delighted to be hiring on behalf of one of the largest managed cloud providers to Federal and defense customers. They build and run secure cloud and AI environments behind some of the U.S. government's most critical missions, from national security and public safety to essential public services.These are environments that cannot fail. Speed, rigor and trust matter, and your expertise is relied on from day one.This is a senior role built for an engineer who already brings deep expertise in Zero Trust, automated compliance engineering and multi-cloud security. If you have 5–7 years in SecDevOps, cloud security or platform engineering and want your work protecting missions that cannot fail, this could be the role for you.Why this role: You'll build security into the deployment fabric itself, using Infrastructure as Code and Policy-as-Code across AWS, Azure and GCP inside FedRAMP-authorized, multi-tenant IL4 boundaries. It suits a proven mid-level engineer ready for broader architecture scope, or an experienced practitioner who wants direct operational impact.What you'll be doing You'll design, automate and maintain secure cloud infrastructure and CI/CD pipelines, keeping federal environments secure, compliant and repeatable.Day-to-day, that means:Operating Zero Trust architectures (Zscaler ZPA / PRA), including app connectors, privileged remote access and private application boundariesOwning the secrets lifecycle in HashiCorp Vault, with automated credential flows and programmatic rotationIntegrating federated identity (Okta, Entra ID, AWS IAM Identity Center), supporting multi-cloud identity migrations and enforcing least privilegeBuilding multi-tenant infrastructure in Terraform (CloudFormation as needed), with networking, IAM and security groups mapped to FedRAMP IL4 controlsDeveloping secure CI/CD pipelines (GitLab CI, Azure DevOps, Jenkins) with OPA or Azure Policy gates and embedded SAST, SCA and container scanningDeploying and troubleshooting workloads on EKS, AKS and GKE via Helm, ArgoCD or KustomizeAutomating FedRAMP ConMon audit evidence (CM-2, CM-6, AU-2, SC-12) and driving remediation through NIST 800-53 controlsLeading changes through ServiceNow CAB / eCAB and Technical Change ReviewsBuilding observability in Grafana, Prometheus and CloudWatch, owning SLIs and SLOs, and joining on-call (PagerDuty) for P1 war rooms and root-cause analysisWhat we're looking for5–7 years in SecDevOps, Cloud Security Engineering, DevOps or Platform EngineeringHands-on production experience with at least one hyperscaler (ideally Azure or GCP), plus working exposure to AWSHigh proficiency in Terraform and strong scripting (Python, Bash or PowerShell)Practical experience with enterprise identity (Okta, Entra ID) and secrets management (Vault, AWS KMS, Azure Key Vault)Experience operating EDR, CSPM or vulnerability tools such as CrowdStrike, Wiz or QualysExperience building and troubleshooting Docker and Kubernetes environmentsA working understanding of FedRAMP, NIST 800-53 or SOC 2Sole U.S. citizenship (dual citizens cannot be considered)Nice to HaveHashiCorp Terraform AssociateAWS SysOps Administrator or Solutions Architect (Associate)Security+, CISSP or an equivalent security credentialAzure Administrator AssociateWhy ApplyMission-critical work securing some of the most sensitive government environments in the countryReal architecture scope across all three major clouds, at federal scaleA senior seat where your expertise is relied on and the impact is immediate and measurableFully on-site in Arlington, VA.