Job Title: Principal Platform / DevSecOps Architect
Place of Performance: Chantilly, VA
Employment Type: Full-Time
Experience Required: Minimum 10 years of relevant experience, including at least 8 years of AWS engineering experience
Job Summary
We are seeking a Principal Platform / DevSecOps Architect to serve as a hands-on technical architect responsible for designing, building, operating, and continuously improving secure AWS-based application platforms.
The successful candidate will provide technical leadership across Kubernetes/EKS, GitLab CI/CD, GitOps, Infrastructure as Code, containerization, DevSecOps, networking, identity, security, and platform observability while developing automated, reusable, secure, and maintainable platform solutions.
Key Responsibilities
- Architect, operate, and troubleshoot production Kubernetes environments, primarily Amazon EKS.
- Design, develop, and maintain sophisticated GitLab CI/CD pipelines and reusable pipeline templates.
- Implement GitOps practices for Kubernetes applications and infrastructure.
- Build and maintain secure AWS infrastructure using Infrastructure as Code (IaC).
- Develop reusable Helm charts, Kubernetes manifests, deployment patterns, and platform automation.
- Support containerized applications using Docker.
- Integrate security scanning, secrets management, IAM, and other DevSecOps controls into delivery pipelines.
- Troubleshoot complex issues spanning applications, containers, Kubernetes, AWS, networking, certificates, and identity.
- Support authentication and authorization capabilities, including:
IAM
RBAC
OAuth2/OIDC
LDAP
TLS/mTLS
Certificate-based authentication
- Improve logging, monitoring, auditing, and overall platform observability.
- Automate recurring operational tasks and convert manual processes into reusable platform solutions.
- Develop standardized deployment, pipeline, and infrastructure templates.
- Document technical solutions, operational procedures, and architecture decisions.
- Mentor engineers across development, infrastructure, platform, and security teams.
- Lead technical troubleshooting and resolution across multiple technology layers.
Required Qualifications
- Active Top Secret/SCI security clearance, with the ability to obtain and maintain a polygraph.
- Minimum 10 years of experience in software engineering, cloud engineering, DevOps, DevSecOps, platform engineering, or related technical disciplines.
- Minimum 8 years of AWS engineering experience.
- Strong hands-on production experience with Kubernetes, preferably Amazon EKS.
- Deep experience building and troubleshooting GitLab CI/CD pipelines.
Networking
IAM
Compute
Storage
Load balancing
Monitoring
- Strong Docker and containerization experience.
- Experience with GitOps and Infrastructure as Code.
- Experience creating reusable deployment, pipeline, and infrastructure templates.
- Strong Linux, networking, and command-line troubleshooting skills.
- Software development or scripting experience with Python, Go, Java, Ruby, Bash, or comparable languages.
- Strong understanding of:
IAM and RBAC
Authentication and authorization
TLS and certificates
DNS
HTTP
Routing
Load balancing
- Ability to independently troubleshoot complex systems across multiple technology layers.
- Strong technical communication, documentation, and collaboration skills.
Preferred Qualifications & Certifications
- Security or DevSecOps certifications.
- Experience with:
Terraform
CloudFormation
- Experience with Keycloak, LDAP, OAuth2/OIDC, PKI, CAC/PIV, or client-certificate authentication.
- Experience with Prometheus/Grafana, CloudWatch, ELK/OpenSearch, or comparable observability platforms.
- Experience integrating security scanning and compliance controls into CI/CD environments.
- Experience working in regulated or security-sensitive environments.
Additional Requirements
- Must maintain the required Top Secret/SCI security clearance and meet applicable polygraph requirements.