1,007,442open jobs
59,919companies
166,736added this week
Browse all
Salary
≈ $111k – $216k per year (Estimated)
Location
In office (Arlington)
Seniority
Senior · 5+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Oct 1, 2026. First seen by Alion on Sep 30, 2026.

Overview
Company
Impact
Profile match
FedRAMP Low, Moderate, and High are becoming Class A, B, C, and D. Learn what's changing and how Knox remains the fastest path to FedRAMP authorization.

About Knox

Knox runs the largest Federal & DoW managed cloud, building and operating secure cloud and AI environments that support the U.S. government’s most critical missions - from national security and public safety to essential public services. Our customers rely on Knox to deploy production systems that meet the highest standards for security, reliability, and compliance.

Work at Knox is high-impact and purpose-driven. The problems we solve are high-stakes, the expectations are high, and the results are visible. Speed, rigor, and trust matter here - because the environments we secure cannot fail. Your contributions are visible, your expertise is relied upon, and the impact of your work is immediate and measurable. We operate at federal scale, securing some of the most sensitive government environments in the country - because the systems we build must perform without fail.

About the Role

The SecDevOps Engineer designs, automates, and maintains Knox’s secure cloud infrastructure and CI/CD pipelines across AWS, Azure, and GCP within our FedRAMP-authorized, multi-tenant boundaries. Day-to-day, the work centers on Zero Trust access, continuous monitoring, cloud security posture, and observability - keeping secure, compliant, and repeatable operations running across federal cloud environments.

The ideal candidate brings 5-7 years of hands-on experience bridging core cloud engineering with security operations. Whether you are a proven mid-level engineer looking to step into a broader architecture scope or an experienced practitioner seeking direct operational impact, this role embeds security controls directly into the deployment fabric using Infrastructure as Code (IaC) and Policy-as-Code frameworks.

Role Focus & Technical Matrix

Zero Trust & Identity- Zscaler (ZPA / PRA), HashiCorp Vault, Okta, Azure AD / Entra ID, AWS IAM Identity Center

Infrastructure as Code - Terraform (Primary), CloudFormation, GitOps (ArgoCD / Helm)

Security & Compliance - FedRAMP (IL4 boundaries), NIST 800-53, Wiz, Qualys, CrowdStrike, OPA

Observability & Ops - Grafana, Prometheus, CloudWatch, PagerDuty, ServiceNow (CAB / eCAB)

Key Responsibilities

Zero Trust & Access Management

  • Support and operate Zero Trust Network Access (Zscaler ZPA / PRA) architectures including app connectors, privileged remote access, and private application access boundaries.
  • Manage privileged credentials, API tokens, and secrets lifecycle using HashiCorp Vault, establishing automated credential flows and programmatic rotation.
  • Integrate and maintain federated identity providers (Okta, Azure AD / Entra ID, AWS IAM Identity Center) and actively support ongoing multi-cloud identity migrations.
  • Enforce strict least-privilege access models and machine-to-machine credential rotation policies across all automation systems.

Cloud Infrastructure & Secure Automation

  • Design, build, and manage multi-tenant infrastructure across AWS, Azure, and GCP using Infrastructure as Code (Terraform as primary; CloudFormation as needed).
  • Automate end-to-end provisioning, configuration management, and environment deployment workflows via secure CI/CD and GitOps paradigms.
  • Manage cloud networking, IAM topologies, and security group configurations tailored strictly to FedRAMP controls and Impact Level 4 (IL4) boundaries.

CI/CD, Policy-as-Code & Container Security

  • Develop and maintain secure CI/CD pipelines utilizing GitLab CI, Azure DevOps, or Jenkins.
  • Integrate Policy-as-Code frameworks (such as OPA or Azure Policy) into pipeline gates to enforce organizational compliance before infrastructure provisioning.
  • Embed automated static application security testing (SAST), software composition analysis (SCA), and container vulnerability scans into active deployment workflows.
  • Build, deploy, and troubleshoot containerized workloads within managed Kubernetes environments (EKS, AKS, GKE) using Helm, ArgoCD, or Kustomize.

Continuous Monitoring, Vulnerability & Compliance

  • Support FedRAMP Continuous Monitoring (ConMon) cycles by implementing technical security controls, managing incident tickets, and executing technical remediation follow-through.
  • Maintain IaC, pipeline architectures, and operating configurations compliant with FedRAMP and NIST 800-53 standards.
  • Automate programmatic audit evidence generation for specific control requirements, including CM-2 (Baseline Configurations), CM-6 (Configuration Settings), AU-2 (Event Logging), and SC-12 (Cryptographic Key Establishment and Management).
  • Participate in formal enterprise change management processes via ServiceNow, preparing documentation for Technical Change Reviews and Change Advisory Board (CAB/eCAB) workflows.

Observability & Incident Reliability

  • Deploy and maintain centralized dashboards, alert definitions, log aggregation, and metrics/APM architectures using Grafana, Prometheus, or cloud-native tooling.
  • Define, track, and report on Service Level Indicators (SLIs) and Service Level Objectives (SLOs) for critical secure services.
  • Participate in the team's operational on-call rotation (PagerDuty), driving rapid incident resolution, root-cause analyses, and P1 war room execution.

Qualifications

Required Experience & Skills

  • Experience: 5-7 years of dedicated professional experience in SecDevOps, Cloud Security Engineering, DevOps, or Platform Engineering.
  • Cloud Infrastructure: Hands-on production experience with at least one major hyperscaler (AWS preferred), with functional exposure to Azure and/or GCP environments.
  • Automation & Scripting: High proficiency in Terraform (declarative IaC) and robust scripting capabilities (Python, Bash, or PowerShell).
  • Identity & Secrets: Practical experience managing enterprise identity/access tooling (Okta, Entra ID) and secrets management platforms (HashiCorp Vault, AWS KMS, or Azure Key Vault).
  • Security Tooling: Familiarity operating endpoint protection (EDR), cloud security posture management (CSPM), or vulnerability scanning platforms (e.g., CrowdStrike, Wiz, Qualys).
  • Containers: Experience building, configuring, and troubleshooting containerized environments (Docker, Kubernetes).
  • Compliance Alignment: Practical or working understanding of FedRAMP, NIST 800-53, or SOC 2 compliance frameworks.

Preferred Certifications

  • HashiCorp Certified: Terraform Associate
  • AWS Certified SysOps Administrator or Solutions Architect (Associate)
  • CompTIA Security+, CISSP, or equivalent security credential
  • Microsoft Certified: Azure Administrator Associate

Compensation Range: 155k-185k, variable annual bonus, and equity

Hiring Requirement: Due to the nature of our work with federal government clients and compliance with applicable regulations, this position requires U.S. citizenship. Dual citizenship is not permitted for this role. Candidates must be able to provide documentation verifying sole U.S. citizenship status as part of the background check process.

Any offer of employment is contingent upon the successful completion of all required pre-employment screenings, including a background check, in accordance with applicable laws and government contract requirements.

Benefits & Perks

Knox offers a competitive employee benefits package including Medical, Dental, Vision, Life & Disability, unlimited PTO, and an employee funded 401k plan. Please note, benefits are subject to change.

We are an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. Employment decisions are made without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, veteran status, or any other legally protected status.

Knox is proud to support veteran hiring - we encourage veterans and transitioning service members to apply and welcome the unique skills and experience you bring.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,007,442 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

DevOps
Similar stack
Same company
Arlington
$92k – $167k per year • In office • Public Trust • Full-Time • 8+ years exp • Fort Worth
DevOps
Linux
Windows
Unix
Cybersecurity
Active Directory
Design
AutoCAD
Apply
$108k – $195k per year • Remote (United States) • Public Trust • Full-Time • 5+ years exp • Atlanta
Databases
Oracle
DevOps
Terraform
Ansible
GitHub
GitLab
IAM
Linux
Cybersecurity
FedRAMP
SIEM
Apply
≈ $132k – $256k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • New York
DevOps
GCP
Apply
≈ $150k – $299k per year (Estimated) • In office • 8+ years exp • Bachelor's Degree • San Jose
AI/ML
AI Agents
DevOps
GCP
Apply
≈ $88k – $179k per year (Estimated) • In office • TS/SCI • 3+ years exp • Bachelor's Degree • Reston
Python
JavaScript
C++
Bash
Perl
DevOps
GCP
Kubernetes
Linux
Apply
In office • 10+ years exp
Python
Bash
DevOps
Terraform
Ansible
GCP
Helm
GitHub Actions
Istio
Loki
OpenTelemetry
Linkerd
Prometheus
GitLab CI
Azure
CI/CD
GitOps
ArgoCD
Jenkins
AWS
Docker
Kubernetes
Grafana
Platform Engineering
Chaos Engineering
Service Mesh
Alertmanager
Incident Management
SLI/SLO/SLA
Linux
DNS
Apply
In office • 7+ years exp
Python
Bash
DevOps
Terraform
Ansible
GCP
Helm
GitHub Actions
Istio
Loki
OpenTelemetry
Linkerd
Prometheus
GitLab CI
Azure
CI/CD
GitOps
ArgoCD
Jenkins
AWS
Docker
Kubernetes
Grafana
Platform Engineering
Chaos Engineering
Service Mesh
Alertmanager
Incident Management
SLI/SLO/SLA
Linux
DNS
Apply
In office • 3+ years exp • Bachelor's Degree
Python
PowerShell
MATLAB
DevOps
HPC
Windows
Management
Jira
ServiceNow
ITIL
ITSM
Apply
Principal Engineer 11 hours ago
In office
Python
AI/ML
AI Agents
LLM
RAG
LLM Evaluation
LLM Guardrails
Multi-Agent Systems
DevOps
GCP
Azure
AWS
Platform Engineering
Apply
In office • 5+ years exp
JavaScript
Java
Java
Spring Framework
Spring Boot
Quarkus
Databases
PostgreSQL
Apache Kafka
Frontend
React.js
DevOps
Rest API
Terraform
GCP
CI/CD
Docker
Kubernetes
Apply
$125k – $135k per year • In office • Full-Time • Arlington
DevOps
Rest API
GCP
Azure
AWS
Configuration Management
Incident Management
Cybersecurity
SOC 2
HIPAA
FedRAMP
Management
ServiceNow
Agile
ITIL
ITSM
Apply
≈ $99k – $207k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Arlington
DevOps
GCP
Azure
AWS
Incident Management
Cybersecurity
ISO 27001
SOC 2
HIPAA
NIST 800-53
FedRAMP
Apply
≈ $99k – $207k per year (Estimated) • In office • Full-Time • 5+ years exp • Arlington
DevOps
GCP
Azure
AWS
Cybersecurity
FedRAMP
Apply
≈ $99k – $207k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Arlington
DevOps
GCP
Azure
AWS
Cybersecurity
FedRAMP
Apply
≈ $73k – $144k per year (Estimated) • In office • Full-Time • 3+ years exp • Arlington
Management
Jira
ServiceNow
Apply
≈ $87k – $178k per year (Estimated) • In office • TS/SCI • 4+ years exp • Bachelor's Degree • Arlington
Python
PowerShell
DevOps
VMWare
Linux
Windows
TCP/IP
Cybersecurity
Active Directory
Management
ITIL
Apply
$115k – $125k per year • In office • TS/SCI • 4+ years exp • Arlington
PowerShell
DevOps
TCP/IP
DNS
DHCP
Cybersecurity
Active Directory
Apply
$115k – $125k per year • In office • TS/SCI • 8+ years exp • Arlington
Python
Java
PHP
Ruby
PowerShell
DevOps
Terraform
Ansible
CloudFormation
CI/CD
AWS
Docker
Configuration Management
Bitbucket
AWS Lambda
Amazon EC2
GitLab
Amazon S3
IAM
Amazon CloudWatch
Management
Jira
Agile
QA
JMeter
Apply
$150k – $175k per year • In office • TS/SCI • Bachelor's Degree • Arlington
Bash
Databases
Oracle
DevOps
Ansible
Podman
VMWare
Docker
Linux
Windows
DNS
Apply
Program Manager 1 day ago
≈ $122k – $240k per year (Estimated) • In office • Top Secret • 15+ years exp • Bachelor's Degree • Arlington
Apply
See all jobs
This is one of many
1,007,442 more open roles from verified company boards, updated every day.