Cloud DevSecOps Engineer
Indexed description
About The Job
- Architect, provision, configure, and maintain production-grade Kubernetes cluster environments hosting containerized front-end, backend, and identity services.
- Deploy, configure, and administer a highly available Keycloak Identity Broker instance running in Kubernetes, federating authentication to enterprise Okta via SAML 2.0 and OIDC.
- Configure identity brokering rules, realm roles, client scopes, and token exchange policies within Keycloak to power secure authentication for React and Spring Boot services.
- Design, build, and maintain end-to-end CI/CD pipelines for automated image builds, vulnerability scanning, automated testing gates, and zero-downtime rolling deployments via Helm.
- Implement robust platform security controls, including Kubernetes Ingress controllers (NGINX/Traefik), TLS certificate automation (cert-manager), network policies, and container image scanning (Trivy).
- Automate secrets management and configuration injection across environments using tools such as HashiCorp Vault, AWS Secrets Manager, or Kubernetes External Secrets Operator.
- Provision, monitor, and maintain supporting backing infrastructure including managed PostgreSQL instances and secure Amazon S3 storage buckets.
- Establish centralized logging, monitoring, and alerting frameworks (Prometheus, Grafana, Loki or EFK stack) to ensure high system observability and reliability.
- Must be a US Citizen with the ability to pass a Public Trust background check
- Bachelor’s degree in a relevant field
- 10+ years of relevant work experience
- 6+ years of systems engineering, DevOps, and cloud infrastructure experience in enterprise Linux and cloud environments.
- 4+ years of hands-on experience provisioning, operating, and troubleshooting containerized workloads in production Kubernetes clusters.
- 3+ years of dedicated experience configuring and managing enterprise Identity and Access Management (IAM) systems, specifically Keycloak and Okta (OIDC, OAuth 2.0, SAML 2.0).
- Strong experience building and maintaining automated CI/CD pipelines (e.g., GitLab CI, GitHub Actions, Jenkins) integrating security scans and container image registries.
- Proficiency in Infrastructure as Code (IaC) and configuration management using Terraform, Helm charts, and Kubernetes YAML manifests.
- Solid background in networking, DNS, TLS/SSL termination, reverse proxy routing, and cloud network access policies.
- Strong scripting skills in Bash, Python, or Go for automated infrastructure management and operational tooling.
- Proactive problem-solving capabilities with a security-first engineering mindset and clear technical communication skills.
- Certified Kubernetes Administrator (CKA) or Certified Kubernetes Security Specialist (CKS).
- Direct experience deploying and operating the Keycloak Kubernetes Operator and backing relational databases in high-availability configurations.
- Hands-on experience securing AWS cloud environments and configuring least-privilege IAM policies, S3 bucket security, and VPC networking.
- Experience implementing DevSecOps security automation tools such as Trivy, SonarQube, OWASP ZAP, or Snyk within continuous deployment workflows.
- Familiarity with GitOps deployment methodologies utilizing ArgoCD or Flux.
- Familiarity working in Agile / Scrum software development environments within public trust or federal contexts.
Our work powers mission-critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow.
We Value:
- Attracting and developing top talent and high-performing teams
- Fostering a culture that is engaging, accountable, and mission-driven
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search