Cloud/Network Infrastructure Engineer, Senior

Everforth ECS

Arlington (VA)

On-site

USD 150,000 - 190,000

Full time

33 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Everforth ECS seeks a Senior Infrastructure Engineer to design, build, and operate secure AWS environments (FedRAMP/ATO governed). You will own infrastructure across GovCloud and commercial accounts, focusing on EKS, Terraform, DNS, and connectivity.

The role requires hands-on AWS engineering, strong automation discipline, and collaboration with Security and Application teams to ensure compliance and production readiness.

Qualifications

  • Bachelor's degree or 8 years of relevant experience.
  • 6+ years designing, implementing, securing, and maintaining AWS Cloud infrastructure.
  • 5+ years troubleshooting hybrid/cloud network connectivity (VPC routing, TGW, DNS, DHCP, TLS/certificates, SGs, NACLs).
  • 5+ years with Terraform (advanced modules, state management, policy enforcement).
  • 5+ years Kubernetes networking, ingress, CoreDNS, and connectivity between EKS workloads and AWS/external services.
  • 5+ years infrastructure experience related to network security and secure cloud operations.
  • Experience in security compliance environments (FedRAMP, FISMA, NIST 800-53) and RMF/ATO documentation.

Responsibilities

  • Troubleshoot and support enterprise load-balancing and ingress patterns (F5, DNS, TLS, routing).
  • Coordinate with application teams, Security, stakeholders, and program leadership to resolve connectivity and production readiness issues.
  • Design, build, and maintain Infrastructure-as-Code using Terraform (modules, remote state, policy integration).
  • Provision, upgrade, and manage EKS clusters, namespaces, and Helm add-ons; manage IAM roles for service accounts.
  • Configure AWS VPC networking, including routing, TGWs, DNS, DHCP, endpoints, NACLs, and security groups.
  • Implement and secure microservices on EKS with connectivity to S3, ECR, Secrets Manager, IAM.
  • Automate deployments with GitHub Actions or self-hosted runners; manage cross-account IAM role assumptions and CI/CD policy gates.
  • Enforce least-privilege IAM, automate compliance evidence collection, and support RMF/ATO documentation.
  • Diagnose issues across containers, Kubernetes networking, and AWS layers (VPC–security).
  • Support observability, logging, and monitoring with Elastic, ScienceLogic, or AppDynamics to meet SLA and audit requirements.
  • Mentor junior engineers and drive process standardization and knowledge sharing.
  • Develop SOPs and playbooks aligned with program governance; improve design for resiliency and policy compliance.
  • Support legacy-to-CAWS migrations, including connectivity, cutover, and validation of network paths.

Skills

Strong communication
Security compliance
Cross-team collaboration
Automation and IaC
Operational discipline
Problem solving

Education

Bachelor's degree or 8 years relevant experience

Tools

Terraform
AWS
EKS
Kubernetes
GitHub Actions
NIST/FedRAMP controls

Job description

#4946

Job Description

Everforth ECS is seeking a Senior Infrastructure Engineer (AWS / Terraform / EKS) to join the Infrastructure & Cloud Team supporting the C DM Data Service federal programs under DHS CISA. This role focuses on designing, building, and operating secure, repeatable AWS environments within a FedRAMP and ATO-governed context . The engineer will work in an environment where all deployments are infrastructure-as-code, peer-reviewed, and fully auditable. The successful candidate will combine hands‑on AWS engineering depth with a strong sense of operational discipline, automation, and compliance awareness . This is not just EKS/Terraform build work; it is operational own ership across commercial and GovCloud AWS accounts for connectivity, routing, DNS, F5/load balancing, EKS, Terraform, security remediation, migrations, and stakeholder coordination.

We are seeking dynamic , energetic, and engaging team members who love challenges ! The ideal candidate will be able to align to the following duties:

  • Troubleshoot and support enterprise load- balancing and ingress patterns, including F5 or equivalent technologies, DNS, TLS/certificate paths, routing, and endpoint reachability.
  • Coordinate directly with application teams, Security, stakeholders, network owners, and program lea dership to resolve connectivity, access, migraiton , and production readiness issues.
  • Design, build, and maintain Infrastructure-as-Code using Terraform (modules, S3/DynamoDB remote state, OPA/ tfsec policy integration).
  • Provision, upgrade, and manage EKS clusters, including namespaces, Helm-based add-ons (cert-manager, ESO, Confluent Operator), and IAM roles for service accounts.
  • Design, configure, and troubleshoot AWS VPC networking, including routing, TGWs, DNS, DHCP, endpoints, NACLs, and security groups.
  • Implement and secure microservices on EKS with proper connectivity to AWS services (S3, ECR, Secrets Manager, IAM).
  • Automate infrastructure deployments using GitHub Actions (or self-hosted runners), cross-account IAM role assumptions, and CI/CD policy gates.
  • Collaborate with security and applications teams to enforce least-privilege IAM, automate compliance evidence collection, and support RMF/ATO documentation.
  • Diagnose and resolve complex issues spanning containers, Kubernetes networking, and AWS layers (VPC – Zscaler - C - TIPS - SaaS endpoints).
  • Support observability, logging, and monitoring through integration with Elastic, ScienceLogic, or AppDynamics to meet SLA and audit requirements.
  • Mentor and guide junior engineers through knowledge sharing, paired engineering, and process standardization.
  • Evaluate and improve infrastructure design for policy compliance, resiliency, and performance tuning.
  • Develop and maintain SOPs and playbooks that align with program governance.
  • Support legacy-to-CAWS migration activities, including RabbitMQ/app-server connectivity, environment cutover support , dependency discovery, and validation of network paths across lower and production environments .
  • Quickly build working knowledge of inherited environments , document tribal knowledge, create diagrams/runbooks, and transfer operational context to primary and ba ckup owners.
  • Operate within a formal change-control, evidence, and audit expectations, including CR support, implementation evidence, rollback planning, and post -change validation.
  • Must be a US citizen with the ability to obtain Public Trust Suitability .
  • Bachelor's degree or 8 years of relevant experience .
  • 6+ years designing, implementing, securing, and maintaining AWS Cloud infrastructure (CAWS, GovCloud, or equivalent).
  • 5 + years troubleshooting hybrid/cloud network connectivity, including VPC routing, TGW, DNS, DHCP, TLS/certificates , security groups, NACLs, endpoints, and load balancers.
  • 5+ years of experience with Terraform (advanced modules, state management, policy enforcement).
  • 5+ years' Experience with Kubernetes networking, ingress, CoreDNS , service exposure, node/sec urity group behavior , and connectivity between EKS workloads and AWS/external services.
  • 5+ years of infrastructure experience related to network security
  • Strong networking foundation: TCP/IP, DNS, DHCP, TLS, routing, subnetting, NACLs, and endpoint connectivity.
  • Proficient scripting/automation using Python or Bash, YAML/JSON templating, and Git-based workflows.
  • Experience in security compliance environments (FedRAMP, FISMA, NIST 800-53) and supporting ATO documentation.
  • Demonstrated ability to collaborate cross-functionally with Security, DevSecOps , and CI/CD teams to maintain compliant, auditable infrastructure.
  • Strong communication skills with the ability to interface effectively with stakeholders from engineers to senior management.
Desired Skills
  • Prior DHS CISA mission experience or experience in federal secure cloud operations.
  • Experience designing and documenting security controls for System Security Plans (SSPs) and FISMA accreditation.
  • Experience operating in multi-account AWS environments with strong IAM, SCP, and segmentation practices.
  • Familiarity with observability tooling (Elastic, ScienceLogic, AppDynamics) and integrating metrics/log pipelines with EKS.
  • Understanding Zero Trust architecture and Cloud-Native ATO automation practices.
  • Experience in TLS and certificate management (ACM, ACM-PCA).
  • AWS Associate or Professional-level certification(s) (e.g., Solutions Architect, DevOps Engineer).

#EverforthECS1

ECSFederal LLCis an equal opportunity employer and does not discriminate or allow discrimination on the basisany characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or localjurisdictionlaw.

Everforth ECS is the federal segment of Everforth , a $4B global organization with over 10,000 employees. Ournearly 3,500professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies. Our work powers mission-critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow.

We value:

  • Attracting and developing top talent and high-performing teams
  • Fostering a culture that is engaging, accountable, and mission-driven

Meet the challenge. Make a difference withEverforthECS!

undefined

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cloud/Network Infrastructure Engineer, Senior
Cloud/Network Infrastructure Engineer, Senior

ECS Corporate Services • Arlington (VA)

On-site
USD 123,000 - 184,000
Cloud DevOps Engineer
Cloud DevOps Engineer

Everforth ECS • Arlington (VA)

Hybrid
USD 110,000 - 150,000
Cloud DevOps Engineer
Cloud DevOps Engineer

ECS • Arlington (VA)

Hybrid
USD 130,000 - 160,000
Senior Cloud Engineer
Senior Cloud Engineer

ECS • Fairfax (VA)

Hybrid
USD 170,000 - 200,000
Hybrid work model
Senior Cloud Engineer
Senior Cloud Engineer

Everforth ECS • Merrifield (VA)

Hybrid
USD 120,000 - 160,000
Technical Lead
Technical Lead

ECS • Fairfax (VA)

Hybrid
USD 170,000 - 210,000
Senior DevOps Engineer
Senior DevOps Engineer

ECS • Virginia (MN)

On-site
USD 140,000 - 160,000
Cloud Engineer
Cloud Engineer

ECS • Fairfax (VA)

Hybrid
USD 120,000 - 160,000
Cloud Platforms Engineer
Cloud Platforms Engineer

ECS • Fairfax (VA)

Hybrid
USD 180,000 - 210,000
DevOps Engineer
DevOps Engineer

ECS • Fort Meade (FL)

Hybrid
USD 120,000 - 160,000