Tangram Flex is seeking a Senior DevSecOps / Platform Engineer with 5+ years of experience to lead and advance our cloud-native platform infrastructure, secure software delivery pipelines, and DevSecOps strategy. In this role, you will architect, optimize, and scale cloud-native application build environments and CI/CD pipelines supporting critical internal products and customer deployments across unclassified and classified domains.
As a Senior Engineer, you will serve as a technical anchor—mentoring engineers, driving platform architecture decisions, and collaborating closely with cross-functional software teams to accelerate Continuous Authority to Operate (cATO) processes and integrate robust, shift-left security practices.
What We Do: Our team and products provide solutions to enable innovators to design, develop, verify, and advance critical systems, while accelerating innovation that advances our nation's security. By accelerating delivery of critical systems, Tangram is transforming the way our nation solves complex software challenges.
JOB RESPONSIBILITIES
Pipeline Architecture, Leadership & Software Delivery
- Lead the architecture, design, and continuous optimization of enterprise CI/CD pipelines using GitLab CI or alternative deployment platforms.
- Architect and mature GitOps workflows using FluxCD or ArgoCD to manage multi-cluster state across complex environments.
- Establish automated testing, automated vulnerability gates, caching strategies, and performance benchmarks to dramatically shorten build and release cycles.
- Provide tier-3 escalation support and root-cause analysis for build, deployment, or automation pipeline failures.
- Drive technical standards, best practices, and code reviews across DevOps/DevSecOps practices within the engineering organization.
Infrastructure Architecture & Platform Engineering
- Architect, deploy, and maintain secure, highly available Cloud-Native infrastructure using AWS GovCloud and Kubernetes.
- Design scalable Infrastructure-as-Code (IaC) frameworks (e.g., Terraform, OpenTofu) for automated provisioning of cloud, on-premises, and air-gapped environments.
- Establish containerization standards, custom Helm chart templates, and orchestration patterns across multi-tenant Kubernetes clusters.
- Lead deployment architectures and secure baseline configurations across multiple security enclaves (NIPRNet, SIPRNet, JWICS, C2S/SC2S).
Continuous Security, cATO & Compliance Strategy
- Architect end-to-end "Shift-Left" security controls into the delivery workflow, including automated SAST/DAST, container scanning, software bill of materials (SBOM) generation, and dependency tracking.
- Lead compliance-as-code initiatives to enforce DoD Cybersecurity directives, STIGs, and NIST SP 800-53 controls to accelerate cATO approval frameworks.
- Champion the integration and adoption of DoD Enterprise DevSecOps reference architectures (e.g., Platform One, Big Bang) and hardened container pipelines using Iron Bank.
Observability, Site Reliability & Platform Operations
- Architect enterprise observability and telemetry stacks (Prometheus, Grafana, Loki, Jaeger) to enable proactive system health monitoring, alert automation, and operational insights.
- Lead disaster recovery, high-availability, and business continuity strategy, including automated backup and restore procedures for core Kubernetes clusters and stateful services.
- Evaluate, pilot, and introduce emerging cloud-native and DevSecOps technologies to elevate overall team capabilities and platform efficiency.
REQUIRED SKILLS & QUALIFICATIONS
- Education: Bachelor’s degree in Computer Science, Computer Engineering, IT, Cybersecurity, or equivalent practical experience.
- Experience: 5+ years of hands-on experience in software deployment, cloud platform engineering, DevOps, or DevSecOps role in an enterprise or DoW environment.
- Clearance: U.S. Citizenship required; must possess an active Secret security clearance, or possess the ability to obtain and maintain a U.S. Government Top Secret/SCI Security Clearance.
- Core Technical Capabilities: Expert-level proficiency with AWS / AWS GovCloud, Kubernetes architecture, Docker/container runtimes, and Linux enterprise administration/scripting (Bash, Python, Go).
- Advanced experience designing enterprise-grade GitLab CI/CD pipelines and infrastructure orchestration with Terraform.
- DoD 8570/8140 Compliance: Active IAT Level II or IAM Level II/III certification (e.g., Security+ CE, CySA+, CISSP, CISM)
- Willingness and ability to travel up to 20% to client sites, customer locations, and industry conferences as required.
NICE TO HAVE SKILLS & QUALIFICATIONS
- Deep expertise in container security scanning and governance tools (e.g., Anchore, Trivy, SonarQube, NeuVector, Sysdig).
- Strong experience with central authentication and identity providers (Okta, Keycloak, OIDC/SAML).
- Proven experience mentoring mid-level and junior engineers on cloud-native practices, secure coding guidelines, and operational excellence.
- Strong technical writing ability to author architectural blueprints, compliance documentation, and standard operating procedures (SOPs).
- Excellent communication skills with the ability to bridge technical requirements between software development teams, product managers, and government stakeholders.
- Flexibility to support high-priority operational deployment windows or mission-critical outage resolutions.
- Direct hands-on experience with Air Force Platform One, Big Bang architecture, Iron Bank hardened container baselines, and AWS C2S/SC2S cloud environments.
- Proven track record assisting or leading cATO accreditation efforts for defense or intelligence customer software applications.
WHAT WE OFFER
We are committed to staying rooted in our core value of Team First. For that reason, we've designed a highly competitive benefits program and supportive work environment to engage employees and their families.
- Hybrid work options
- Flexible working hours, 10 paid holidays, and generous Paid Time Off (PTO)
- Employer-paid Medical, Dental, Vision, and Short/Long-Term Disability Insurance
- Access to group rating plans for Life Insurance
- Employer contribution to Health Savings Account (HSA)
- Competitive 401(k) employer match
- A vibrant engineering culture that fosters transparency, collaboration, and continuous professional growth via internal tech community events (Lightning Talks, Integration Events)
Tangram Flex is an Equal Opportunity Employer, and provides reasonable accommodation for qualified individuals with disabilities and disabled veterans in its application procedures and in accordance with federal law. All qualified candidates will receive consideration for employment based on business needs, job requirements, and individual qualifications. EEO/AA Vet/Disabled Employer / E-Verify.