{"id":1472539,"url":"https://alion.io/job/defense-unicorns-senior-platform-engineer-2","title":"Senior Platform Engineer (FedD237)","company":{"id":8737,"name":"Defense Unicorns","domain":"defenseunicorns.com","url":"https://alion.io/company/defense-unicorns","size_band":"51-200","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Greenhouse","truth_index":{"grade":"B","score":75,"open_postings":5,"ghost_share":0,"stale_share":0.8,"repost_share":0,"time_to_fill_p50_days":67,"computed_at":"2026-10-01T05:45:00Z"}},"role":"DevOps","role_family":"DevOps","seniority":"senior","employment_type":null,"work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":148750,"max":201250,"currency":"USD","period":"year","gross":null,"usd_annual":201250},"salary_estimate":null,"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":true,"technologies":[{"name":"AI Agents","optional":false},{"name":"Ansible","optional":false},{"name":"AWS","optional":false},{"name":"Bash","optional":false},{"name":"CI/CD","optional":false},{"name":"Configuration Management","optional":false},{"name":"GitLab CI","optional":false},{"name":"GitOps","optional":false},{"name":"Helm","optional":false},{"name":"IAM","optional":false},{"name":"Kubernetes","optional":false},{"name":"Linux","optional":false},{"name":"NIST 800-53","optional":false},{"name":"OpenShift","optional":false},{"name":"Platform Engineering","optional":false},{"name":"Pulumi","optional":false},{"name":"Python","optional":false},{"name":"Red Hat","optional":false},{"name":"SBOM","optional":false},{"name":"Terraform","optional":false},{"name":"ArgoCD","optional":true},{"name":"Azure","optional":true},{"name":"GCP","optional":true},{"name":"Grafana","optional":true},{"name":"Keycloak","optional":true},{"name":"Kustomize","optional":true},{"name":"Kyverno","optional":true},{"name":"LLM Guardrails","optional":true},{"name":"OpenTelemetry","optional":true},{"name":"Prometheus","optional":true},{"name":"SLSA","optional":true},{"name":"Snyk","optional":true},{"name":"SonarQube","optional":true},{"name":"Trivy","optional":true}],"status":"live","first_seen_at":"2026-09-29T15:07:02Z","employer_posted_date":"2026-09-30","last_verified_at":"2026-10-02T01:18:48Z","board_verified":true,"closed_at":null,"days_open":2,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":2},"description":"DEFENSE UNICORNS\nSenior DevSecOps Engineer \nEmbedded Engineering | Secure Cloud-Native Platforms | AI Delivery\nRole Description\nDefense Unicorns is seeking a senior DevSecOps Engineer to embed with a government team and its technology partners building an emerging AI-powered engineering ecosystem.\nThis role sits at the intersection of platform engineering, cybersecurity, compliance, and software delivery. The engineer will help establish secure, automated, and repeatable pipelines that allow software, AI models, and agentic capabilities to move rapidly from development into operational environments while identifying cybersecurity and compliance risks early-before formal security testing.\nThe ideal candidate is a hands-on DevSecOps engineer with deep experience in Kubernetes, cloud infrastructure, CI/CD, NIST 800-53, and the RMF/ATO process. They should be comfortable working directly with government personnel and multiple commercial technology partners, troubleshooting across technical boundaries, and translating security requirements into practical engineering controls rather than treating compliance as a downstream gate.\nThis is an embedded engineering role-not a traditional security or compliance staff-augmentation position. The engineer will help the team move quickly, build security into the development lifecycle, and create repeatable patterns that can scale from the initial prototype environment into higher-classification operational environments.\nResponsibilities\nDesign, implement, and continuously improve secure CI/CD and GitOps pipelines for cloud-native software, AI models, and agentic applications.\nWork hands-on with Kubernetes and Red Hat OpenShift/OpenShift AI environments to automate secure build, test, promotion, deployment, and lifecycle workflows.\nTranslate NIST SP 800-53 controls and RMF requirements into practical engineering controls, policies, pipeline checks, and automated evidence collection.\nIdentify cybersecurity, compliance, configuration, and supply-chain risks early in the development lifecycle-before formal security testing or authorization activities.\nSupport the end-to-end ATO/RMF lifecycle, including control implementation, technical evidence generation, security artifacts, remediation tracking, and preparation for assessment.\nBuild and maintain automated security checks across source code, dependencies, container images, infrastructure, configurations, and deployment pipelines.\nImplement software supply-chain security practices including SBOM generation, provenance, artifact signing, vulnerability scanning, policy enforcement, and controlled artifact promotion.\nDevelop Infrastructure as Code using Terraform, Pulumi, Ansible, or similar technologies to make environments consistent, auditable, and repeatable.\nConfigure and improve GitLab CI/CD pipelines, runners, registries, and automated workflows across multiple environments.\nIntegrate identity, secrets management, policy enforcement, logging, monitoring, and security tooling into the broader engineering platform.\nCollaborate with platform, data, AI/agent, and architecture engineers to ensure security and compliance requirements are designed into the system rather than bolted on later.\nWork directly with commercial technology partners to resolve cross-platform security, deployment, identity, networking, and integration issues.\nHelp establish repeatable approaches for promoting software and AI capabilities across security domains and into classified operational environments.\nDevelop security automation and compliance-as-code patterns that reduce manual effort and accelerate authorization decisions.\nCreate and maintain architecture decision records, security documentation, technical standards, runbooks, and implementation guidance.\nContinuously identify recurring security and compliance work that can be standardized, automated, or productized rather than solved manually for each environment.\nOperate effectively in a fast-moving, ambiguous environment where requirements and architecture will continue to evolve.\nTravel / Onsite Expectations: Must be local to the National Capital Region and able to work onsite at the government campus in Springfield, VA as mission requirements evolve. The initial prototype environment may support a hybrid schedule, but the role should be prepared for increasing onsite and SCIF interaction as the effort transitions to higher-classification environments.\nMinimum Experience and Qualifications\nActive TS/SCI clearance.\nMust reside in or be local to the National Capital Region with the ability to work onsite in Springfield, VA as required.\nDeep hands-on experience with Kubernetes and containerized application environments.\nExperience deploying and operating workloads on Red Hat OpenShift and/or enterprise Kubernetes platforms.\nStrong experience with GitLab CI/CD or comparable software delivery platforms.\nStrong working knowledge of NIST SP 800-53 and the Risk Management Framework (RMF).\nPractical understanding of the government ATO process, including control implementation, security evidence, POA&M/remediation, assessment, and authorization activities.\nExperience identifying and remediating security risks in software and infrastructure before formal security testing.\nExperience developing and managing Infrastructure as Code using Terraform, Pulumi, Ansible, or similar technologies.\nStrong experience with Helm, Kubernetes manifests, GitOps, and declarative configuration management.\nExperience with cloud environments such as AWS, including networking, IAM, compute, storage, and Kubernetes services.\nStrong Linux systems knowledge and ability to troubleshoot across application, container, Kubernetes, network, and infrastructure layers.\nExperience with container security, vulnerability management, artifact repositories/registries, and software supply-chain controls.\nStrong scripting or programming ability using Python, Go, Bash, or similar languages.\nAbility to work directly with government personnel and multiple technology vendors to diagnose and resolve complex technical and security issues.\nAbility to operate with significant autonomy and turn loosely defined mission objectives into working technical solutions.\nPreferred Experience and Qualifications\nExperience supporting production systems at Secret or TS/SCI classification levels.\nExperience implementing NIST 800-53 controls in Kubernetes or cloud-native environments.\nExperience with continuous authorization / continuous ATO (cATO) approaches and automated compliance evidence.\nExperience with Red Hat OpenShift AI or similar enterprise AI platforms.\nExperience with AI/ML infrastructure, model serving, GPU-enabled environments, MLOps, or agentic AI systems.\nExperience securing AI/agent workloads, including model provenance, tool access, data access, guardrails, and policy enforcement.\nExperience with GitOps tooling such as Flux or Argo CD.\nExperience with security and compliance tools such as Kyverno, OPA/Gatekeeper, SonarQube, Trivy, Snyk, Anchore, or comparable technologies.\nExperience with SBOM, SLSA/provenance, artifact signing, and software supply-chain security frameworks.\nExperience with identity and access management platforms such as Keycloak or comparable enterprise IAM technologies.\nExperience with observability and telemetry tooling such as Prometheus, Grafana, OpenTelemetry, ELK, or similar platforms.\nExperience moving software, images, or artifacts across multiple security domains or into disconnected/air-gapped environments.\nFamiliarity with UDS, Zarf, Pepr, Iron Bank, or similar secure software delivery technologies.\nDepartment of Defense or Intelligence Community experience working on an operational ATO’d system.\nExperience working on multidisciplinary teams consisting of government engineers, FDEs, OEM professional services teams, and multiple technology vendors.\nDemonstrated ability to turn security and compliance requirements into automated engineering patterns that can be reused across environments.\nWhat Success Looks Like\nThe successful engineer makes security an accelerator rather than a gate. They help the team identify risk early, automate compliance and evidence wherever practical, keep the delivery pipeline moving, and establish secure patterns that can be reproduced as the environment scales from prototype to classified operations.\nFull compensation packages are based on candidate experience. Compensation ranges are established using national benchmarking data and apply across all geographic locations within the United States. \nRemote - USA\n$148,750—$201,250 USD\nWho We Are\nDefense Unicorns delivers mission value by streamlining software delivery so our customers can focus on the most important challenges. We share a vision of freedom and security for the advancement of progress and innovation. Our commitment to this vision, and to our mission-driven customers, means a commitment to speed, user experience and optionality, without compromising security. Our team is composed of innovators, software engineers, and veterans with decades of experience delivering technology programs across the federal market.\nWhat We Do\nWe create and deliver secure solutions for continuous software integration and delivery. Defense Unicorns consolidates the best practices for security pipelines, testing, and deployment automation in order to meet the high security requirements valued by mission owners. Our solutions are agnostic by design and we believe that growing a robust ecosystem of secure, cloud-native software solutions can help enterprise customers inside and outside the federal market buy and integrate software more easily.\nWho We Serve\nDefense Unicorns’ customers are mission-focused leaders across public and private enterprises. We proudly support defense and civil agencies across the U.S. government and we work closely with the creators of leading-edge software solutions to deliver value to the mission-owner by improving the security and consumability of commercial software products.\nWhat We Work On\nKubernetes\nCloud Environments (AWS/GCP and Azure)\nInfrastructure-as-code (like Terraform/Pulumi)\nContinuous Delivery and automation tooling\nGitOps\nContainers\nCNCF projects and open source products and packages\nHelm/Kustomize-Value Stream Mapping\nBuilding and improving security delivery\nBuilding Kubernetes and cloud native applications\nBenefits Our Unicorns Enjoy\nHealth:\nMedical/Dental/Vision\nPremiums are 100% Company Paid\nHealth Savings Account\nLife Insurance\nDisability Insurance\nFinancial:\n401k Retirement Plan\nCompany Stock Options\nHome Office Budget\nLeave:\nWe offer all full-time Unicorns Flexible Time Off (FTO) plus all Federal Holidays, one week for Thanksgiving, and two weeks for Christmas and New Year’s\nPaid Parental Leave\nLearning:\nReimbursement for approved trainings/subscriptions\nConferences (travel, lodging, and fees)\nDon’t have all the preferred experience or qualifications? Studies show that underrepresented groups like women and people of color are less likely to apply to jobs if they don't meet every requirement listed. \nAt Defense Unicorns, we're committed to diversity. If you're enthusiastic about the role but don't match every criteria, we encourage you to apply. You could be the perfect fit for this or another role! Defense Unicorns is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, disability, sex, sexual orientation, gender identity or expression, age, national origin, veteran status, genetic information, union status and/or beliefs, or any other characteristic protected by federal, state, or local law.\nCCPA DISCLOSURE","description_format":"text","description_chars":11715,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"phd","optional":false},"security_clearance":true,"languages":[]},"benefits":["401k plan","Flexible time off","Home office","Life insurance","Parental leave","Retirement plans","Stock options"],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Military","Naval Systems","Application Security"],"lifecycle":[{"event":"open","at":"2026-09-29T16:59:08Z"}],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":1,"expected_fill_days":67,"reasons":["conf:9","velocity","win:early"],"computed_at":"2026-10-01T05:45:00Z"},"pay":{"stated_usd_annual":201250,"is_top_pay":true},"html_url":"https://alion.io/job/defense-unicorns-senior-platform-engineer-2","json_url":"https://alion.io/job/defense-unicorns-senior-platform-engineer-2.json","meta":{"generated_at":"2026-10-02T02:05:52Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2701,"day_limit":5000,"remaining_today":2299,"minute_limit":60,"resets_at":"2026-10-03T00:00:00Z"}}}