Everforth ECS is seeking a Senior Infrastructure Engineer (AWS / Terraform / EKS) to join the Infrastructure & Cloud Team supporting the C DM Data Service federal programs under DHS CISA. This role focuses on designing, building, and operating secure, repeatable AWS environments within a FedRAMP and ATO-governed context.
The engineer will work in an environment where all deployments are infrastructure-as-code, peer-reviewed, and fully auditable. The successful candidate will combine hands‑on AWS engineering depth with a strong sense of operational discipline, automation, and compliance awareness. This is not just EKS/Terraform build work; it is operational ownership across commercial and GovCloud AWS accounts for connectivity, routing, DNS, F5/load balancing, EKS, Terraform, security remediation, migrations, and stakeholder coordination. We are seeking dynamic, energetic, and engaging team members who love challenges!
Duties
- Troubleshoot and support enterprise load- balancing and ingress patterns, including F5 or equivalent technologies, DNS, TLS/certificate paths, routing, and endpoint reachability.
- Coordinate directly with application teams, Security, stakeholders, network owners, and program lea dership to resolve connectivity, access, migraiton , and production readiness issues.
- Design, build, and maintain Infrastructure-as-Code using Terraform (modules, S3/DynamoDB remote state, OPA/ tfsec policy integration).
- Provision, upgrade, and manage EKS clusters, including namespaces, Helm-based add-ons (cert-manager, ESO, Confluent Operator), and IAM roles for service accounts.
- Design, configure, and troubleshoot AWS VPC networking, including routing, TGWs, DNS, DHCP, endpoints, NACLs, and security groups.
- Implement and secure microservices on EKS with proper connectivity to AWS services (S3, ECR, Secrets Manager, IAM).
- Automate infrastructure deployments using GitHub Actions (or self-hosted runners), cross-account IAM role assumptions, and CI/CD policy gates.
- Collaborate with security and applications teams to enforce least-privilege IAM, automate compliance evidence collection, and support RMF/ATO documentation.
- Diagnose and resolve complex issues spanning containers, Kubernetes networking, and AWS layers (VPC - Zscaler - C - TIPS - SaaS endpoints).
- Support observability, logging, and monitoring through integration with Elastic, ScienceLogic, or AppDynamics to meet SLA and audit requirements.
- Mentor and guide junior engineers through knowledge sharing, paired engineering, and process standardization.
- Evaluate and improve infrastructure design for policy compliance, resiliency, and performance tuning.
- Develop and maintain SOPs and playbooks that align with program governance.
- Support legacy-to-CAWS migration activities, including RabbitMQ/app-server connectivity, environment cutover support , dependency discovery, and validation of network paths across lower and production environments .
- Quickly build working knowledge of inherited environments , document tribal knowledge, create diagrams/runbooks, and transfer operational context to primary and ba ckup owners.
- Operate within a formal change-control, evidence, and audit expectations, including CR support, implementation evidence, rollback planning, and post -change validation.
Salary: $123,000 - $184,000
General Description of Benefits Must be a US citizen with the ability to obtain Public Trust Suitability .
Qualifications
- Bachelor's degree or 8 years of relevant experience .
- 6+ years designing, implementing, securing, and maintaining AWS Cloud infrastructure (CAWS, GovCloud, or equivalent).
- 5 + years troubleshooting hybrid/cloud network connectivity, including VPC routing, TGW, DNS, DHCP, TLS/certificates , security groups, NACLs, endpoints, and load balancers.
- 5+ years of experience with Terraform (advanced modules, state management, policy enforcement).
- 5+ years' Experience with Kubernetes networking, ingress, CoreDNS , service exposure, node/sec urity group behavior , and connectivity between EKS workloads and AWS/external services.
- 5+ years of infrastructure experience related to network security
- Strong networking foundation: TCP/IP, DNS, DHCP, TLS, routing, subnetting, NACLs, and endpoint connectivity.
- Proficient scripting/automation using Python or Bash, YAML/JSON templating, and Git-based workflows.
- Experience in security compliance environments (FedRAMP, FISMA, NIST 800-53) and supporting ATO documentation.
- Demonstrated ability to collaborate cross-functionally with Security, DevSecOps , and CI/CD teams to maintain compliant, auditable infrastructure.
- Strong communication skills with the ability to interface effectively with stakeholders from engineers to senior management.