A

Lead DevOps Engineer — IAM Platform

Posted today

Job Requirements

Fort George G Meade, MD
Top Secret/SCI Full Scope Polygraph
Mid Level Career (5+ yrs experience)
Salary not specified
Join Premium to unlock estimated salaries

Job Description

Lead DevOps Engineer — IAM Platform
Location: Maryland Area
Clearance: TS/SCI w/ Full-Scope Poly
Employment Type: Full-time

About the Role
We're seeking a Lead DevOps Engineer to serve as the technical anchor for a large-scale enterprise identity platform deployment inside a highly secure, air-gapped government cloud environment. This is a hands-on leadership role: you will own the underlying Kubernetes/cloud infrastructure, CI/CD and artifact-delivery pipelines, and the operational foundation that a broader identity and access management (IAM/IGA) platform is built on top of.
Due to the classified nature of the target environment, program- and client-specific details will be shared directly with candidates after initial screening. What we can share now: this is a multi-year, phased deployment supporting a large user base and a large application portfolio, the environment will be built on Kubernetes in a government cloud comparable to commercial hyperscaler offerings but operating under stricter security and connectivity constraints (including limited or no internet egress).
This role is DevOps/platform-engineering first. Deep identity product expertise is not required — we need someone who can own infrastructure, automation, and delivery pipelines, and who is comfortable picking up identity/access concepts and vendor tooling on the job alongside our identity architects.

What You'll Do
• Own and operate Kubernetes-based infrastructure in a secure/classified cloud environment, including cluster lifecycle, capacity planning, and production support
• Build and maintain CI/CD (GitOps-style) pipelines to deploy and update containerized platform components across dev, test, and production tiers
• Design and manage the process for moving software artifacts (container images, Helm charts, license files, patches) into an air-gapped or restricted-connectivity environment, including validation and change-control steps
• Apply security hardening (STIG-equivalent), patching cadence, and compliance controls to infrastructure and supporting services
• Partner closely with identity architects/engineers to support deployment of directory, authentication, federation, and identity governance services
• Stand up and maintain observability, logging, and SIEM integration for platform components
• Own backup/restore procedures and support disaster-recovery and failover testing
• Lead day-to-day technical delivery for a small team of engineers; report progress, risks, and blockers to program/practice leadership
• Produce clear infrastructure-as-code, runbooks, and operational documentation to support an eventual transition/handover to client operations staff

Required Qualifications
• 5+ years of DevOps, Platform Engineering, or Site Reliability Engineering experience
• 2+ years operating Kubernetes in production environments
• Strong hands-on experience with a major cloud provider (AWS strongly preferred); experience with government/GovCloud or restricted-connectivity cloud environments is a significant plus
• Experience with infrastructure-as-code tooling (Terraform, Ansible, or similar) and container packaging/deployment tools (IronBanks)
• Experience building and maintaining CI/CD or GitOps pipelines (e.g., ArgoCD, Jenkins, GitLab CI, or similar)
• Working familiarity with federal security hardening and compliance frameworks (e.g., STIG/DISA baselines, NIST 800-53/800-171, RMF/ATO processes) — you don't need to be a compliance expert, but you should be comfortable operating within one
• General working knowledge of identity and access management concepts — SAML, OIDC, LDAP/directory services, PKI, MFA/smart-card (PIV/CAC) authentication — enough to collaborate effectively with identity specialists; deep product-level expertise is not required
• Strong written and verbal communication skills; comfortable engaging directly with client technical stakeholders

Nice to Have
• Direct hands-on experience with any enterprise identity/IAM or identity governance (IGA) platform (e.g., Ping Identity, ForgeRock, Okta, SailPoint, Saviynt, Microsoft Entra) — willingness to ramp up on a specific vendor stack is valued more than prior depth
• Prior experience working in air-gapped, disconnected, or classified cloud/enclave environments
• Experience supporting ATO/RMF documentation, audit evidence collection, or continuous monitoring programs
• Background supporting large-scale application onboarding or migration efforts
• Veteran or prior DoD/IC program experience is a plus, not a requirement
group id: 10529568