Description
We are looking for a DevSecOps Engineer to bridge the gap between our cloud infrastructure, on-premise training environments, and our cybersecurity operations. This role focuses heavily on maintaining both functionality and security across our technical environments, spanning from backend servers and AWS cloud initiatives to localized physical classroom setups and end-user devices. The position takes ownership of general systems administration, including daily Active Directory management, enterprise mobile device management (MDM), and the deployment of physical training hardware, while simultaneously driving our AWS cloud initiatives forward. Because the organization operates in a highly regulated space, a major part of the job involves translating complex security frameworks into actionable technical controls. The ultimate goal of this position is to keep our systems resilient, hardened, and fully compliant with federal security mandates across all infrastructure whether cloud-hosted or locally deployed in closed networks.
Responsibilities
- The core of this position involves a mix of cloud infrastructure management, local classroom administration, security operations, endpoint management, and compliance tracking.
- On the infrastructure side, the role requires architecting, deploying, and managing AWS resources.
- This includes provisioning EC2 instances, setting up subnets, and building automated deployment pipelines.
- In addition to cloud environments, this engineer will physically and logically support local classroom setups, maintaining on-premises hardware and ensuring localized training systems are operational and secure.
- This work is paired with managing the Active Directory environment, handling general user and computer management, and establishing integrations between our identity systems and the AWS cloud.
- Additionally, this engineer will oversee our mobile device management (MDM) platform, ensuring that all ERDs, tablets, and remote endpoints are properly enrolled, monitored, and secured with configuration policies.
- Beyond infrastructure and endpoints, active defense and vulnerability management are critical day-to-day tasks.
- The engineer is responsible for hardening EC2 instances, the broader cloud architecture, local classroom workstations, and all managed mobile devices against potential threats.
- This includes routinely running ACAS and DISA STIG scans, analyzing the results, and taking the initiative to patch, fix, and remediate any vulnerabilities found during those scans across cloud, physical servers, and mobile platforms.
- Finally, the role requires drafting, managing, and updating critical system documentation directly mapped to NIST SP 800-171 and NIST SP 800-53 standards, ensuring all regulatory and audit obligations are consistently met.
Qualifications
- A strong technical foundation in both systems administration and hybrid cloud/on-premise environments is required for this position.
- Candidates must have hands-on experience administering Active Directory and enterprise MDM solutions, alongside a practical understanding of AWS services (EC2, networking, pipelines) and local physical network topologies used in classroom or closed-network settings.
- A deep understanding of federal compliance frameworks is also critical, particularly working with NIST 800-171 and NIST 800-53.
- The successful candidate must have direct experience using vulnerability assessment tools like ACAS and applying DISA STIGs to secure operating systems, network infrastructure, and mobile endpoints.
- It is not enough to just identify vulnerabilities; candidates need a strong operational track record of engineering solutions, applying patches, enforcing endpoint policies, and successfully fixing those findings across both cloud and physical infrastructure.
- Finally, to meet the baseline compliance standards for this position, applicants must hold at least a Bachelor's degree as well as an active CompTIA Security+ certification.
- Must be a US citizen capable of obtaining and maintaining a Secret Security clearance.
Job ID2026-24936
Work TypeOn-Site