user avatar

Senior Cloud Systems Administrator / DevSecOps Security Engineer

American Systems Corporation

Posted today

Job Requirements

Alexandria, VA
Top Secret/SCI Polygraph Unspecified
Career Level not specified
$135,000 - $195,000

Job Description

AMERICAN SYSTEMS is an employee-owned federal government contractor supporting national priority programs through our strategic solutions in the areas of Information Technology, Engineering & Analysis, Test & Evaluation, and Training.

Responsibilities

Operate, sustain, automate, continuously improve, and secure DTE&A Data Management Platform (DDMP) environments across development, test, training, and production, with emphasis on availability, configuration compliance, observability, release support, and user-impacting operational excellence. This hybrid role combines senior system administration, site reliability engineering, cloud operations, DevSecOps, cybersecurity engineering, and RMF/ATO support for an IL5 CUI system.

Key Responsibilities
  • Administer and sustain DDMP cloud environments across Development, Test, Training, and Production.
  • Operate the managed Kubernetes environment supporting DDMP containerized application services, including deployment support, capacity monitoring, auto-scaling, patching, upgrades, and incident troubleshooting.
  • Maintain cloud infrastructure, networking, storage, managed databases, integrations, service endpoints, certificates, and DNS in accordance with approved architecture and security baselines.
  • Support the transition from the current VDI-hosted Linux/Windows server model to an elastic, multi-AZ, cloud-native platform.
  • Maintain backup, recovery, high-availability, disaster-recovery, and restore-validation procedures for application, database, configuration, and infrastructure assets.
  • Monitor availability, latency, performance, capacity, backup success, error rates, deployment health, and cloud-resource utilization.
  • Develop operational dashboards and service-level metrics to support mission leadership and platform engineering decisions.
  • Administer, maintain, and improve CI/CD pipelines for application, infrastructure, database, and configuration releases.
  • Implement repeatable, auditable deployment and rollback procedures for Test, Training, and Production environments.
  • Embed automated security checks into CI/CD pipelines, including source-code, dependency, secrets, container-image, IaC, and vulnerability scanning.
  • Maintain secure artifact repositories, container registries, versioned configuration baselines, deployment manifests, and release evidence.
  • Serve as the technical cybersecurity operations lead for DDMP, partnering with the cloud architect and program security stakeholders.
  • Implement and maintain cloud IAM, Kubernetes RBAC, least-privilege access, service identities, secrets management, encryption, key management, and privileged-access controls.
  • Operate continuous security monitoring, centralized audit logging, threat detection, security alerting, and vulnerability-management processes.
  • Coordinate ACAS/Nessus scans, assess findings, validate remediation, document false positives or mitigations, and manage vulnerabilities through closure.
  • Apply, validate, document, and sustain required DISA STIG and SRG configurations for operating systems, containers, Kubernetes, databases, applications, and supporting infrastructure.
  • Support RMF and ATO activities by collecting, organizing, and maintaining technical evidence for implemented controls and continuous monitoring.
  • Maintain POA&M items, security risk registers, remediation plans, and compliance status reports.


Qualifications

  • BS Degree
  • 11+ years of progressively responsible experience in systems administration, cloud operations, DevSecOps, cybersecurity engineering, site reliability engineering, or a comparable infrastructure/security discipline.
  • 3+ years of experience operating cloud-hosted, containerized, or hybrid enterprise applications in production.
  • Strong Linux systems-administration experience, preferably Ubuntu and Red Hat Enterprise Linux or derivatives; working knowledge of Windows Server is required for transition from the current DDMP state.
  • Top Secret Clearance with SCI eligibility
  • Proven hands-on experience administering Docker and Kubernetes, including, cluster and workload operations; Namespace, RBAC, resource quota, ingress, storage, and network-policy management; Helm or equivalent package/deployment tooling; pod, node, container, certificate, networking, and deployment troubleshooting; and upgrade, patching, backup, recovery, scaling, and availability procedures.
  • Direct experience supporting a DoD IL5 environment, a DISA-hosted service, NIPRNET-connected workloads, or a system operating under a DoW ATO.
  • Experience supporting CAC/PKI-based authentication, ICAM federation, certificate lifecycle management, and zero-trust access patterns.
  • Experience performing or supporting ISSO, ISSM, SCA-V, security-control assessor, ATO, or continuous-monitoring functions.
  • Experience developing or maintaining RMF artifacts, including, System Security Plan; Control Implementation statements; Control Inheritance matrices; Security Assessment evidence; POA&Ms; Continuous-monitoring Strategy; Incident-response Plan; and Contingency Plan and Disaster-recovery Test evidence.
  • Experience with eMASS or another DoW governance, risk, and compliance system.
  • Experience with GitLab security capabilities or equivalent tools for static application security testing, dynamic application security testing, software composition analysis, secrets detection, container image scanning, infrastructure-as-code scanning, and SBOM generation and software supply-chain controls.
  • Experience implementing Kubernetes security controls, including workload identity, pod-security standards, admission control, image provenance, runtime protection, network segmentation, and audit logging.
  • Experience with Splunk, Elastic, Prometheus, Grafana, OpenTelemetry, cloud-native monitoring, or comparable observability platforms.
  • Experience administering PostgreSQL, including backup and restoration validation, maintenance, performance triage, replication monitoring, access controls, and encryption.
  • Experience securing API gateways, REST/GraphQL APIs, API tokens, service-to-service authentication, and external-system integrations.
  • Experience supporting Microsoft 365/SharePoint Online integrations, especially where SharePoint serves as an authoritative artifact repository.
  • Familiarity with the security considerations for managed AI/LLM services, including CUI/data-boundary protection, access controls, audit logging, prompt/data retention, output validation, and human-in-the-loop decision processes.
  • Experience with ITIL-aligned incident, problem, change, configuration, and service-level management.


Pay Transparency Statement

AMERICAN SYSTEMS is committed to pay transparency for our applicants and employee-owners. The salary range for this position is USD $135,000.00/Yr. - USD $195,000/Yr. Actual compensation will be determined based on several factors permitted by law. AMERICAN SYSTEMS provides for the welfare of its employees and their dependents through a comprehensive benefits program by offering healthcare benefits, paid leave, retirement plans, insurance programs, and education and training assistance.

EEO Statement

EEO Race/Sex/Disability Status/Veteran Status
group id: RTL010594