Full Job Description
Must be a US Citizen with an active TS or eligible for TS. No Third Party.
ABOUT THE ROLE
Strategic Innovation Group (SIG) is seeking a Configuration Manager to own the platform-engineering and configuration-control backbone of a new analytics platform being built inside a federal client's on-premises FedRAMP Moderate environment. This role combines classic configuration management - baselines, change control, artifact integrity, document control - with hands-on DevSecOps: the CI/CD pipeline, container builds and security scanning, Kubernetes deployment, dependency approvals, and log integration. The successful candidate is the person who makes sure code moves from a developer's branch into the client environment repeatably, securely, and with a record, and who works directly with client CIO staff and the security lead to keep the pipeline aligned to the System Security Plan.
RESPONSIBILITIES
- Establish and operate the CI/CD pipeline (Jenkins or Azure DevOps) integrated with GitLab for code delivery, covering build, automated test, security scanning, artifact creation, and deployment to designated environments.
- Manage container image builds, image and dependency vulnerability scanning, SBOM generation, and the process for requesting client approval of new dependencies and licenses.
- Deploy and maintain application workloads on the client's Rancher-managed Kubernetes platform; manage environment configuration, secrets handling, and promotion between development, test, and production namespaces.
- Define and maintain the configuration management plan: baselines for code, infrastructure-as-code, data models, and documents; change control and release procedures; version and tagging conventions.
- Integrate application and platform logging with the client's Splunk instance and support audit-logging requirements from the security lead.
- Coordinate the technical establishment of interconnections and environment access with client CIO staff; track and resolve blockers to environment readiness.
- Maintain deliverable and document configuration control, including the source-code and documentation package delivered to the client repository at acceptance.
- Support the System Security Plan with configuration-management (CM family) control implementation evidence.
- Deliver pipeline and platform runbooks and knowledge transfer to the client-designated support team during transition.
REQUIRED QUALIFICATIONS
- Bachelor's degree in Computer Science, Information Technology, or a related field; equivalent experience may be considered.
- 3+ years in configuration management, release engineering, DevOps, or platform engineering roles, including 1+ years operating CI/CD and container platforms in a federal or FedRAMP environment (3+ years with a Master's degree).
- Hands-on experience administering CI/CD pipelines in Jenkins and/or Azure DevOps, integrated with GitLab or a comparable Git platform.
- Hands-on experience deploying and operating containerized applications on Kubernetes (Rancher, OpenShift, or comparable enterprise distribution).
- Experience integrating security scanning (SAST, container image, dependency/SCA) into pipelines and managing findings with development teams.
- Experience establishing configuration baselines, change control, and release management under a documented CM plan.
- Working knowledge of NIST SP 800-53 configuration-management controls and experience supporting an ATO or FedRAMP authorization package.
- Scripting proficiency (Bash, Python, or PowerShell) and infrastructure-as-code experience (Helm, Terraform, Ansible, or equivalent).
PREFERRED QUALIFICATIONS
- Experience working inside an on-premises federal environment with restricted internet access and Government-approved software lists.
- Experience managing database schema migrations, connection secrets, and backup/restore procedures within a CI/CD pipeline (PostgreSQL or comparable RDBMS).
- Splunk administration or log-forwarding configuration experience.
- ITIL Foundation, Certified Kubernetes Administrator (CKA), or Azure DevOps certification.
- Experience supporting GPU-enabled Kubernetes workloads.