Responsibilities
- Build, maintain, and improve Kubernetes clusters and containerized application deployments across cloud environments (AWS, EKS, RKE2)
- Develop and manage infrastructure as code (IaC) to provision and configure platform resources consistently and repeatably
- Own and improve CI/CD pipelines, including GitLab CI configuration, runner deployments, and automated build and deployment workflows
- Support identity and access management through tools such as Keycloak, including user onboarding, role configuration, and troubleshooting
- Implement and maintain monitoring, alerting, and logging to ensure platform health and support incident investigation
- Manage certificate lifecycle operations, including renewal of public certificates and related automation
- Contribute to platform security posture through container security practices, Iron Bank image compliance, and support for ATO processes
- Collaborate with application teams to troubleshoot deployment issues, broken pipelines, and platform integration problems
- Write and maintain technical documentation, runbooks, architecture decision records (ADRs), and operational standards
- Influence the strategic vision by contributing to the strategic planning that aligns technological advancements with the mission objectives
- Participate in on-call rotations and support platform incidents in a tier 2 role
- Mentor and support junior engineers through pairing, code reviews, and knowledge sharing
Requirements
- Hands-on experience with Kubernetes (deploying, managing, and troubleshooting clusters and workloads)
- Experience with infrastructure as code tools (e.g., Terraform, Pulumi, or similar)
- Proficiency with CI/CD tooling, particularly GitLab CI or equivalent pipeline platforms
- Working knowledge of Linux/Unix operating systems and command-line administration
- Experience with cloud platforms, preferably AWS (EC2, EKS, IAM, S3, VPC)
- Familiarity with containerization (Docker, container image builds, registry management)
- Ability to read and write YAML fluently for Kubernetes manifests, CRDs, Helm charts, and pipeline configurations
- Strong problem-solving skills and ability to work independently in a remote, asynchronous environment
- US citizenship required; must be eligible for CUI access
- Possess or ability to obtain a DoD 8570 IAT II certification (e.g., Security+ CE)
Nice to Have
- Hold or be eligible for a security clearance
- Experience with UDS Core, Iron Bank, and/or Continuous Authority to Operate (C-ATO) processes
- Familiarity with identity and access management platforms such as Keycloak or similar
- Experience with monitoring and observability tooling (e.g., Prometheus, Grafana, ELK stack, or similar)
- Proficiency in one or more programming languages (Go, Python, or Bash scripting)
- Experience working in a DevSecOps model with secure coding practices and vulnerability remediation
- Familiarity with GitOps workflows and tools (e.g., Flux, ArgoCD)
- Department of Defense experience, specifically working on a production ATO’d system
- Experience with distributed architectures and everything-as-code approaches
- AWS certifications related to platform or solutions architecture
- Experience writing architecture decision records (ADRs), operational runbooks, or engineering standards