Senior Cloud Systems Administrator / DevSecOps Security Engineer
- Salary
- $135K–$195KUSD
- Hiring from
- United States
- Work type
- Hybrid
- Posted
- Sep 29, 2026
Overview
AMERICAN SYSTEMS is an employee-owned federal government contractor supporting national priority programs through our strategic solutions in the areas of Information Technology, Engineering & Analysis, Test & Evaluation, and Training.
Responsibilities
Operate, sustain, automate, continuously improve, and secure DTE&A Data Management Platform (DDMP) environments across development, test, training, and production, with emphasis on availability, configuration compliance, observability, release support, and user-impacting operational excellence. This hybrid role combines senior system administration, site reliability engineering, cloud operations, DevSecOps, cybersecurity engineering, and RMF/ATO support for an IL5 CUI system.
Key Responsibilities
- Administer and sustain DDMP cloud environments across Development, Test, Training, and Production.
- Operate the managed Kubernetes environment supporting DDMP containerized application services, including deployment support, capacity monitoring, auto-scaling, patching, upgrades, and incident troubleshooting.
- Maintain cloud infrastructure, networking, storage, managed databases, integrations, service endpoints, certificates, and DNS in accordance with approved architecture and security baselines.
- Support the transition from the current VDI-hosted Linux/Windows server model to an elastic, multi-AZ, cloud-native platform.
- Maintain backup, recovery, high-availability, disaster-recovery, and restore-validation procedures for application, database, configuration, and infrastructure assets.
- Monitor availability, latency, performance, capacity, backup success, error rates, deployment health, and cloud-resource utilization.
- Develop operational dashboards and service-level metrics to support mission leadership and platform engineering decisions.
- Administer, maintain, and improve CI/CD pipelines for application, infrastructure, database, and configuration releases.
- Implement repeatable, auditable deployment and rollback procedures for Test, Training, and Production environments.
- Embed automated security checks into CI/CD pipelines, including source-code, dependency, secrets, container-image, IaC, and vulnerability scanning.
- Maintain secure artifact repositories, container registries, versioned configuration baselines, deployment manifests, and release evidence.
- Serve as the technical cybersecurity operations lead for DDMP, partnering with the cloud architect and program security stakeholders.
- Implement and maintain cloud IAM, Kubernetes RBAC, least-privilege access, service identities, secrets management, encryption, key management, and privileged-access controls.
- Operate continuous security monitoring, centralized audit logging, threat detection, security alerting, and vulnerability-management processes.
- Coordinate ACAS/Nessus scans, assess findings, validate remediation, document false positives or mitigations, and manage vulnerabilities through closure.
- Apply, validate, document, and sustain required DISA STIG and SRG configurations for operating systems, containers, Kubernetes, databases, applications, and supporting infrastructure.
- Support RMF and ATO activities by collecting, organizing, and maintaining technical evidence for implemented controls and continuous monitoring.
- Maintain POA&M items, security risk registers, remediation plans, and compliance status reports.
Qualifications
- BS Degree
- 11+ years of progressively responsible experience in systems administration, cloud operations, DevSecOps, cybersecurity engineering, site reliability engineering, or a comparable infrastructure/security discipline.
- 3+ years of experience operating cloud-hosted, containerized, or hybrid enterprise applications in production.
- Strong Linux systems-administration experience, preferably Ubuntu and Red Hat Enterprise Linux or derivatives; working knowledge of Windows Server is required for transition from the current DDMP state.
- Top Secret Clearance with SCI eligibility
- Proven hands-on experience administering Docker and Kubernetes, including, cluster and workload operations; Namespace, RBAC, resource quota, ingress, storage, and network-policy management; Helm or equivalent package/deployment tooling; pod, node, container, certificate, networking, and deployment troubleshooting; and upgrade, patching, backup, recovery, scaling, and availability procedures.
- Direct experience supporting a DoD IL5 environment, a DISA-hosted service, NIPRNET-connected workloads, or a system operating under a DoW ATO.
- Experience supporting CAC/PKI-based authentication, ICAM federation, certificate lifecycle management, and zero-trust access patterns.
- Experience performing or supporting ISSO, ISSM, SCA-V, security-control assessor, ATO, or continuous-monitoring functions.
- Experience developing or maintaining RMF artifacts, including, System Security Plan; Control Implementation statements; Control Inheritance matrices; Security Assessment evidence; POA&Ms; Continuous-monitoring Strategy; Incident-response Plan; and Contingency Plan and Disaster-recovery Test evidence.
- Experience with eMASS or another DoW governance, risk, and compliance system.
- Experience with GitLab security capabilities or equivalent tools for static application security testing, dynamic application security testing, software composition analysis, secrets detection, container image scanning, infrastructure-as-code scanning, and SBOM generation and software supply-chain controls.
- Experience implementing Kubernetes security controls, including workload identity, pod-security standards, admission control, image provenance, runtime protection, network segmentation, and audit logging.
- Experience with Splunk, Elastic, Prometheus, Grafana, OpenTelemetry, cloud-native monitoring, or comparable observability platforms.
- Experience administering PostgreSQL, including backup and restoration validation, maintenance, performance triage, replication monitoring, access controls, and encryption.
- Experience securing API gateways, REST/GraphQL APIs, API tokens, service-to-service authentication, and external-system integrations.
- Experience supporting Microsoft 365/SharePoint Online integrations, especially where SharePoint serves as an authoritative artifact repository.
- Familiarity with the security considerations for managed AI/LLM services, including CUI/data-boundary protection, access controls, audit logging, prompt/data retention, output validation, and human-in-the-loop decision processes.
- Experience with ITIL-aligned incident, problem, change, configuration, and service-level management.