Koniag Data Solutions, a Koniag Government Services company, is seeking an experienced
Harness/Traceable Integration Engineer (Senior) to support enterprise DevSecOps operations, API security, and IT administrative and operational support services for a federal government client. This position requires an active security clearance or the ability to obtain and maintain a government background investigation and all requisite IT access authorizations prior to performing work. Specific clearance requirements will be confirmed at time of offer. Primary work will be performed at the client site in Washington, DC and approved remote/telework locations.
We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.
This role serves as a critical senior technical function responsible for the architecture, engineering, implementation, administration, and continuous improvement of enterprise Harness software delivery platform and Traceable AI API security capabilities across a complex, geographically distributed federal IT environment spanning on-premises infrastructure, cloud platforms, and hybrid environments.
The ideal candidate is a highly experienced and technically authoritative DevSecOps and API security engineer with deep, hands-on expertise across the Harness platform portfolio-including Harness Continuous Integration (CI), Continuous Delivery (CD), Feature Flags, Cloud Cost Management, and Security Testing Orchestration (STO)-and Traceable AI API security capabilities, combined with a comprehensive understanding of modern software delivery practices, API security principles, Zero Trust Architecture, and Federal cybersecurity compliance requirements. This individual must possess the technical depth, architectural vision, and operational discipline required to lead the design, implementation, and sustained operation of enterprise-grade Harness and Traceable capabilities that accelerate secure software delivery and protect Government APIs and applications in a highly regulated federal IT environment.
The Harness/Traceable Integration Engineer (Senior) will serve as the program's primary subject matter expert and technical authority for all Harness and Traceable platform capabilities, leading the architecture, engineering, implementation, administration, and continuous improvement of enterprise software delivery and API security infrastructure. This individual works closely with software developers, security engineers, cloud operations teams, DevSecOps engineers, network security engineers, and Government stakeholders to ensure Harness and Traceable platforms are architected, deployed, and operated in a manner that delivers maximum software delivery velocity, security assurance, API visibility, and compliance with Federal cybersecurity frameworks and Zero Trust Architecture objectives across the full enterprise environment.
Principal responsibilities will include but are not limited to:
Architecture & Engineering Leadership- Serve as the program's technical authority and subject matter expert for all Harness and Traceable platform capabilities, providing authoritative architectural guidance, engineering leadership, and expert technical recommendations to program leadership, functional teams, and Government stakeholders on software delivery pipeline strategy, API security architecture, and DevSecOps implementation.
- Lead the design and architecture of enterprise Harness software delivery solutions, including CI pipeline architecture, CD pipeline design, Security Testing Orchestration (STO) integration, Feature Flag management frameworks, and Cloud Cost Management configurations aligned with program delivery objectives and Federal security requirements.
- Lead the design and architecture of enterprise Traceable AI API security implementations, including API discovery and inventory management, API threat detection and protection, API behavioral analytics, and API security posture management across all Government application environments.
- Develop and maintain enterprise Harness and Traceable architecture documentation, including pipeline architecture diagrams, API security topology diagrams, integration architecture specifications, and platform configuration baselines, ensuring documentation is current, accurate, and aligned with operational reality.
- Lead security architecture reviews for new applications, infrastructure changes, and software delivery pipeline modifications, assessing Harness and Traceable platform impact, identifying security gaps, and recommending configuration and policy improvements.
- Evaluate emerging Harness and Traceable platform capabilities, DevSecOps industry developments, and API security trends, providing well-researched recommendations to program leadership and Government stakeholders on opportunities to advance software delivery maturity and API security posture.
- Provide senior technical leadership and mentorship to junior and mid-level engineers, sharing DevSecOps and API security expertise, guiding technical development, and ensuring consistent application of engineering best practices across the team.
Harness CI/CD Pipeline Engineering & Administration- Lead the engineering, implementation, and administration of enterprise Harness Continuous Integration (CI) and Continuous Delivery (CD) pipelines, designing and implementing scalable, secure, and maintainable pipeline architectures that support rapid, reliable software delivery across all program development teams and application portfolios.
- Design and implement Harness CI pipeline configurations, including build stage definitions, test automation integrations, artifact management configurations, code quality gate integrations, and parallel execution strategies that maximize build velocity and reliability.
- Design and implement Harness CD pipeline configurations, including deployment stage definitions, environment-specific deployment strategies (rolling, blue-green, canary), approval gate workflows, verification configurations, and automated rollback capabilities across development, test, staging, and production environments.
- Implement and maintain Harness pipeline-as-code configurations using YAML-based pipeline definitions, ensuring all pipeline configurations are version-controlled, well-documented, templated for reuse, and maintainable by development teams.
- Develop and maintain Harness pipeline templates, step libraries, and reusable pipeline components, promoting pipeline consistency, reducing duplication, and accelerating pipeline development across the program's application portfolio.
- Implement and maintain Harness connector configurations for all integrated platforms, including source code repositories (GitHub, GitLab, Bitbucket), artifact registries (JFrog Artifactory, Docker Hub, AWS ECR), Kubernetes clusters, cloud providers, and notification platforms.
- Configure and maintain Harness environment and infrastructure definitions, ensuring deployment targets are accurately represented, access-controlled, and consistently managed across all pipeline stages and deployment contexts.
- Monitor Harness CI/CD pipeline health, build success rates, deployment frequency, lead time, and change failure rates, proactively identifying and resolving pipeline failures, performance bottlenecks, and reliability issues.
Harness Security Testing Orchestration (STO) Engineering- Lead the engineering, implementation, and administration of Harness Security Testing Orchestration (STO) capabilities, designing and implementing a comprehensive security testing integration framework that embeds automated security testing throughout the CI/CD pipeline lifecycle.
- Design and implement STO scanner integrations across all relevant security testing tool categories, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), container image scanning, and Infrastructure as Code (IaC) security scanning.
- Configure and maintain STO security gate policies, defining risk-based vulnerability thresholds, exemption management procedures, and pipeline enforcement rules that automatically block or flag deployments containing unacceptable security risks.
- Implement and maintain STO deduplication, normalization, and correlation capabilities, ensuring security findings from multiple scanner sources are accurately consolidated, prioritized, and presented to development teams in a clear, actionable format.
- Develop and maintain STO exemption management workflows, ensuring security finding exemptions are properly reviewed, approved, documented, and time-limited in accordance with defined governance procedures and risk acceptance criteria.
- Integrate STO security findings with the enterprise vulnerability management program and SIEM platform, ensuring pipeline security scan results are incorporated into the program's broader vulnerability tracking and security monitoring workflows.
- Monitor STO pipeline integration health, scanner coverage, and security gate effectiveness, proactively identifying and resolving scanner failures, coverage gaps, and policy enforcement issues.
Harness Feature Flags Engineering & Administration- Lead the engineering, implementation, and administration of Harness Feature Flags capabilities, designing and implementing a comprehensive feature flag management framework that supports controlled feature releases, A/B testing, progressive delivery, and kill switch capabilities across the program's application portfolio.
- Design and implement Harness Feature Flag SDK integrations across all relevant application development languages and frameworks, ensuring feature flag capabilities are consistently available and properly implemented across all supported applications.
- Configure and maintain Harness Feature Flag environments, targeting rules, and flag lifecycle management policies, ensuring feature flags are properly governed, regularly reviewed, and retired in accordance with defined flag lifecycle management procedures.
- Develop and maintain feature flag governance standards, ensuring flags are properly named, documented, scoped, and managed throughout their lifecycle to prevent flag accumulation and technical debt.
Harness Cloud Cost Management Engineering- Lead the engineering, implementation, and administration of Harness Cloud Cost Management capabilities, providing comprehensive cloud cost visibility, optimization recommendations, and governance enforcement across enterprise cloud environments.
- Configure and maintain Harness Cloud Cost Management integrations with enterprise cloud accounts, including AWS and Microsoft Azure, ensuring accurate cost attribution, resource tagging enforcement, and budget alerting are consistently applied.
- Develop and maintain cloud cost dashboards, reporting configurations, and cost anomaly alerting capabilities, providing program leadership and Government stakeholders with accurate, timely visibility into cloud spending trends and optimization opportunities.
- Support cloud cost optimization activities, identifying and implementing cost reduction opportunities through rightsizing recommendations, reserved instance analysis, idle resource identification, and workload scheduling optimizations.
Traceable AI API Security Engineering & Administration- Lead the engineering, implementation, and administration of the Traceable AI API security platform, designing and implementing comprehensive API discovery, inventory management, threat detection, and protection capabilities across all Government application environments.
- Design and implement Traceable agent deployments across all in-scope application environments, including Kubernetes-hosted applications, cloud-native services, and on-premises application deployments, ensuring comprehensive API traffic visibility and behavioral baseline collection.
- Configure and maintain Traceable API discovery and inventory management capabilities, ensuring all APIs-including undocumented, shadow, and zombie APIs-are continuously discovered, inventoried, and assessed for security risk across the enterprise application portfolio.
- Implement and maintain Traceable API threat detection policies, including API abuse detection rules, injection attack protection, authentication bypass detection, sensitive data exposure monitoring, and API-specific behavioral anomaly detection configurations.
- Configure and maintain Traceable API security posture management capabilities, ensuring APIs are continuously assessed for security misconfigurations, authentication weaknesses, excessive data exposure, and compliance with defined API security standards and OWASP API Security Top 10 requirements.
- Develop and maintain Traceable API behavioral analytics configurations, including user and service baseline modeling, anomalous traffic pattern detection, and API-level rate limiting and throttling policies.
- Integrate Traceable API security findings with the enterprise SIEM platform, vulnerability management program, and incident response workflows, ensuring API threat detections and security posture findings are incorporated into the program's broader security monitoring and remediation processes.
- Monitor Traceable platform health, agent coverage, and detection output quality, proactively identifying and resolving platform issues, API coverage gaps, and detection fidelity problems.
API Security Governance & Standards- Develop and maintain enterprise API security standards, governance frameworks, and design guidelines, ensuring all Government APIs are developed, deployed, and maintained in accordance with defined security requirements and industry best practices.
- Conduct API security architecture reviews for new and existing Government applications, identifying security risks, recommending remediation actions, and ensuring APIs meet defined security standards before deployment to production environments.
- Develop and maintain API security assessment and testing procedures, supporting periodic API security assessments and integrating API security testing into the CI/CD pipeline through Harness STO and Traceable integrations.
- Provide expert API security guidance to application development teams, supporting secure