We are seeking an experienced Senior AWS Cloud Platform & DevSecOps Engineer to design, build, secure, and operate a highly available, scalable, and resilient cloud platform for a mission-critical enterprise application hosted on AWS GovCloud.
The ideal candidate will have deep expertise in AWS cloud architecture, containerized workloads, Infrastructure as Code (IaC), cloud security, DevSecOps, production operations, and regulatory compliance. This role will be responsible for ensuring the platform meets stringent security, availability, and operational requirements while supporting continuous application delivery and long-term scalability.
- Design, implement, and manage highly available, fault-tolerant AWS infrastructure.
- Architect scalable cloud environments using AWS best practices.
- Build and maintain Infrastructure as Code (Terraform or CloudFormation).
- Design secure VPC architectures, networking, routing, load balancing, and Auto Scaling.
- Ensure production environments are resilient, repeatable, and disaster recovery ready.
- Own and administer AWS GovCloud environments.
- Manage cloud infrastructure lifecycle, upgrades, and operational readiness.
- Implement secure cloud architecture aligned with AWS GovCloud best practices.
- Maintain environment consistency across development, staging, and production.
- Design, deploy, and manage containerized applications using Docker.
- Operate production workloads on Amazon ECS or Amazon EKS (Kubernetes).
- Optimize container performance, security, and resource utilization.
- Implement rolling deployments, blue/green deployments, canary releases, and zero-downtime deployments.
- Maintain container image security, vulnerability scanning, and image lifecycle management.
- Design and maintain secure CI/CD pipelines.
- Automate application build, testing, deployment, and rollback processes.
- Manage Docker image repositories using Amazon ECR.
- Integrate automated security scanning into deployment pipelines.
- Promote Infrastructure as Code and GitOps best practices.
- Design and implement security-first cloud architectures.
- Support Authorization to Operate (ATO) processes and maintain security documentation required for government environments.
- Implement and maintain Zero Trust Architecture principles across infrastructure and applications.
- Ensure compliance with NIST 800-53, FedRAMP, CIS Benchmarks, and applicable government security frameworks.
- Implement least-privilege IAM policies, role-based access control (RBAC), and secure identity management.
- Manage AWS KMS, Secrets Manager, encryption at rest and in transit, certificate lifecycle, and secure key management.
- Conduct infrastructure security assessments, vulnerability remediation, and security hardening.
- Collaborate with security auditors and compliance teams during assessments and certification activities.
- Manage PostgreSQL environments hosted on Amazon RDS.
- Optimize database performance, indexing, connection pooling, and query execution.
- Design backup, recovery, replication, and disaster recovery strategies.
- Monitor database health and ensure high availability.
- Design centralized logging, monitoring, and observability solutions.
- Configure CloudWatch dashboards, alarms, metrics, and log aggregation.
- Implement application performance monitoring (APM) and distributed tracing.
- Establish operational runbooks, incident response procedures, and root cause analysis processes.
- Monitor platform health, capacity, and reliability.
- Design infrastructure capable of supporting high transaction volumes and 24×7 availability.
- Implement Auto Scaling, Load Balancers, health checks, and self-healing infrastructure.
- Improve platform resilience through redundancy and fault-tolerant architecture.
- Conduct performance testing, load testing, and capacity planning.
- Continuously optimize infrastructure for reliability, scalability, and cost efficiency.
- Define infrastructure standards, deployment procedures, and operational best practices.
- Maintain architecture documentation and disaster recovery documentation.
- Establish backup validation and recovery testing procedures.
- Ensure production environments meet defined Service Level Objectives (SLOs) and Service Level Agreements (SLAs).
- Drive automation to reduce manual operational effort and improve deployment consistency.
- 7+ years of experience in Cloud Infrastructure, DevOps, Platform Engineering, or Site Reliability Engineering.
- Extensive hands-on experience with Amazon Web Services (AWS).
- Strong experience with AWS GovCloud or highly regulated cloud environments.
- Expertise in Docker and containerized application deployments.
- Experience operating Amazon ECS and/or Amazon EKS (Kubernetes) in production.
- Strong knowledge of Infrastructure as Code using Terraform or CloudFormation.
- Experience building secure CI/CD pipelines.
- Strong Linux administration and shell scripting skills.
- Experience managing PostgreSQL databases in production environments.
- Strong understanding of networking, DNS, IAM, VPCs, Load Balancers, SSL/TLS, and cloud security.
- Experience implementing monitoring, logging, observability, and incident response processes.
- Experience supporting Authorization to Operate (ATO) initiatives.
- Experience implementing Zero Trust Architecture.
- Strong knowledge of NIST 800-53 security controls.
- Experience with FedRAMP Moderate or High environments.
- Experience implementing Security Information and Event Management (SIEM) solutions.
- Familiarity with OpenTelemetry, Prometheus, Grafana, ELK/OpenSearch, or similar observability platforms.
- Experience with disaster recovery planning and business continuity.
- Knowledge of cost optimization and cloud governance.
- AWS Certified Solutions Architect – Professional
- AWS Certified DevOps Engineer – Professional
- AWS Certified Security – Specialty
- Certified Kubernetes Administrator (CKA)
- Certified Kubernetes Security Specialist (CKS) (preferred)
- CompTIA Security+ or equivalent cybersecurity certification (preferred)
- React
- Java
- Spring Boot
- PostgreSQL
- AWS GovCloud
- Docker
- Amazon ECS / Amazon EKS (Kubernetes)
- Amazon ECR
- Terraform / CloudFormation
- CloudWatch
- AWS IAM
- AWS KMS
- AWS Secrets Manager
- Amazon VPC
- Application Load Balancer
- Auto Scaling
- Git-based CI/CD
The successful candidate will:
- Deliver a secure, highly available, scalable, and resilient AWS platform.
- Maintain compliance with applicable government security standards and ATO requirements.
- Implement Zero Trust security principles across infrastructure and application environments.
- Achieve reliable, repeatable, and automated deployments with minimal operational overhead.
- Maintain high production uptime, strong observability, and rapid incident response.
- Continuously improve platform performance, security, scalability, and operational excellence through automation and best practices.