Position SummaryThe position is part of a team of software and platform engineers building a unified, multi-tenant control plane driven by Kubernetes, Crossplane, and Cluster API (CAPI), that abstracts infrastructure differences across AWS, Azure, on-premises, and air-gapped environments.
As a Senior Principal Platform Engineer, you will act as the critical technical bridge between compliance strategy and system execution. You will collaborate closely with the Information System Security Officer (ISSO) to ingest traditional security policy, governance frameworks (e.g., NIST SP 800-37/53, DoDI 8510.01), and control requirements, translating them into actionable solutions, code, automated pipelines, and continuous platform guardrails in concert with the engineering team. Utilizing Go, Python, and cloud-native security tools, you will implement technical security controls, ranging from admission control and secrets management to zero-trust networking, ensuring the underlying infrastructure and control plane remain in an automated, continuously authorized state.
The ideal candidate is a seasoned platform engineer with deep cybersecurity domain knowledge who excels at automating compliance, streamlining secure software supply chains, and turning complex regulatory expectations into developer-friendly platform abstractions.
Key Responsibilities - Policy-as-Code & Control Enforcement: Translate NIST 800-53 controls and ISSO policy into automated admission policies, cross-cloud guardrails, and real-time compliance checks using Policy-as-Code frameworks.
- Automated Evidence & ConMon: Build pipelines and telemetry dashboards to collect compliance evidence automatically and stream real-time reporting to tools like eMASS/XACTA to support the Authorization to Operate (ATO) lifecycle.
- Secure Supply Chain: Implement end-to-end supply chain controls within CI/CD pipelines, including automated SBOM generation, artifact signing, vulnerability scanning, and provenance tracking.
- Zero-Trust Infrastructure: Package and configure core security capabilities across IAM, secrets management, service mesh, and network segmentation to ensure robust zero-trust architecture.
- Cross-Team Alignment: Partner with software and platform engineers to turn security requirements into actionable backlog items and guide teams on implementing technical controls.
Qualifications - Platform Security & Infrastructure: 5+ years of hands-on platform engineering experience, with deep technical expertise in cloud infrastructure and zero-trust architectures.
- Compliance Frameworks: Direct experience working with NIST SP 800-53, RMF (NIST SP 800-37), or FedRAMP, with a proven ability to translate control statements into software configurations.
- Software Automation & CI/CD: Proficiency in Go or Python, along with CI/CD pipeline automation (e.g., GitLab CI) and GitOps workflows.
- Supply Chain Security: Hands-on experience with vulnerability scanning, image signing, dependency management, and SBOM validation across cloud and air-gapped systems.
- Security Tooling: Experience with enterprise IAM, secrets management platforms (e.g., HashiCorp Vault), and automated policy engines.
- Active DoD Top Secret Clearance.
Preferred Qualifications- Active security or cloud certifications (e.g., CISSP, CCSP).
- Experience automating Continuous ATO (cATO) in air-gapped or heavily regulated environments.
Salary Range: $150,000 - $330,000