SecDevOps Engineer (Jr.)

Knox Systems

Washington (District of Columbia)

On-site

USD 90,000 - 110,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical
Dental
Vision
Life & Disability
401k plan

Job summary

Knox Systems in Washington, DC is seeking a Junior SecDevOps Engineer to support the security, monitoring, and automation of our federal cloud infrastructure across AWS, Azure, and GCP.

On-site role focusing on identity administration, configuration monitoring, vulnerability triage, and secure, repeatable operations under senior engineers. Strong Linux, scripting, and cloud fundamentals are valued as you grow in Zero Trust architecture and compliance engineering.

Qualifications

  • 1–2 years in an entry-level technical role (IT Support, Junior Systems Administrator, Helpdesk/NOC, or relevant cloud internship/bootcamp).
  • Location: must be able to work fully on-site at our Washington, DC office.
  • Linux fundamentals: comfortable with the command line, permissions, logs, and basic tasks.
  • Foundational cloud exposure (AWS preferred) and basic Git workflows (cloning, commits, PRs).
  • Basic scripting ability (Python or Bash) to automate tasks or parse logs.
  • Security mindset: understanding of least privilege, MFA, IAM basics, and encryption.

Responsibilities

  • Monitor Zero Trust Network Access tools (Zscaler ZPA / PRA) and verify connectors and remote access.
  • Assist secrets management with HashiCorp Vault, including basic credential updates and rotations.
  • Review IAM permissions to align with least privilege under senior review.
  • Run Terraform modules across dev/staging in AWS, Azure, or GCP; identify drift.
  • Triage CI/CD pipeline failures in GitHub Actions, GitLab CI, or Azure DevOps.
  • Support FedRAMP ConMon evidence gathering and POA&M tracking.
  • Maintain Grafana/CloudWatch dashboards and incident response readiness.

Skills

Linux basics
Networking basics
Cloud concepts
Scripting (Python/Bash)
Security mindset
Growth mindset

Tools

Terraform
CloudFormation
Docker
Kubernetes
GitHub Actions
GitLab CI
Azure DevOps
Jira
ServiceNow
CloudWatch
Grafana

Job description

About Knox

Knox runs the largest Federal and DoW managed cloud, building and operating secure cloud and AI environments that support the U.S. government’s most critical missions — from national security and public safety to essential public services. Our customers rely on Knox to deploy production systems that meet the highest standards for security, reliability, and compliance.

Work at Knox is high-impact and purpose-driven. The problems we solve are high stakes, the expectations are high, and the results are visible. Speed, rigor, and trust matter here - because the environments we secure cannot fail. Your contributions are visible, your expertise is relied upon, and the impact of your work is immediate and measurable. We operate at federal scale, securing some of the most sensitive government environments in the country - because the systems we build must perform without fail.

The Junior SecDevOps Engineer supports the maintenance, monitoring, and security auditing of Knox’s cloud infrastructure and CI/CD pipelines across AWS, Azure, and GCP. Operating on-site in Washington, DC, within our FedRAMP-authorized boundaries, this role focuses on day-to-day identity administration, configuration monitoring, and vulnerability triage—helping ensure secure, repeatable operations across federal cloud environments under the direct mentorship of senior engineers.

The ideal candidate has strong technical fundamentals (Linux, basic networking, Git, and scripting), a passionate curiosity for cloud security and automation, and a strong security-first mindset. This is a growth-oriented role designed to build elite technical expertise in Zero Trust architectures, automated compliance engineering, and multi-cloud environments.

Role Focus & Technical Matrix

Zero Trust & Identity: Monitoring Zscaler connectors, HashiCorp & Vault basic secret updates.

Infrastructure as Code: Running pre-written Terraform plans, Git PR workflows, fundamental CloudFormation playbooks.

Security & Compliance: FedRAMP baselines, sorting Wiz/Qualys vulnerability alerts, basic CrowdStrike endpoint checks

Observability & Ops: Grafana dashboard upkeep, CloudWatch metrics, ServiceNow ticketing, shadow on-call protocols

Key Responsibilities
Zero Trust & Identity Operations
  • Assist in monitoring Zero Trust Network Access tools (Zscaler ZPA / PRA), verifying application connectors and remote access pathways remain operational.
  • Support secrets management workflows within HashiCorp Vault, including basic credential generation, entry updates, and confirming automated rotations execute without error.
  • Review basic IAM permissions and cloud role policies to ensure alignment with least privilege models under senior engineering review.
Infrastructure & Automation Support
  • Run, test, and troubleshoot pre-defined Terraform modules across development and staging environments in AWS, Azure, or GCP.
  • Identify and log configuration drift or environment resource issues, assisting senior engineers with standard infrastructure patching and remediation tasks.
  • Review cloud security groups, public endpoint configurations, and basic network routes to cross-check them against compliance baselines.
CI/CD & Pipeline Maintenance
  • Monitor and triage failing CI/CD pipeline runs within GitHub Actions, GitLab CI, or Azure DevOps, escalating systemic errors to the team.
  • Review automated security scan readouts (SAST, SCA, and container scans) embedded in the pipeline.
  • Assist in updating, building, and running security base-image layers for containers (Docker) destined for managed Kubernetes clusters (EKS, AKS, GKE).
Compliance Monitoring & Change Administration
  • Assist compliance with the programmatic gathering of audit evidence for ongoing FedRAMP Continuous Monitoring (ConMon) cycles, specifically targeting CM-2, CM-6, AU-2, and SC-12 controls.
  • Assist with Plan of Action and Milestones (POA&M) ticket creation, tracking remediation deadlines across the platform.
  • Draft and submit technical change requests within ServiceNow, ensuring correct structural documentation for review by the Change Advisory Board (CAB).
Observability & Incident Support
  • Maintain and adjust basic Grafana and CloudWatch dashboards, ensuring alert notifications are mapped accurately to operational notification streams.
  • Monitor standard system health indicators, performing low-severity alert triaging to prevent production fatigue.
  • Maintain open telemetry operations for ongoing application monitoring.
  • Participate in a shadow on-call rotation capacity (PagerDuty) alongside senior engineers to develop live diagnostic and real-time incident resolution skills.
Qualifications
Required Experience & Core Aptitude
  • Experience: 1–2 years of experience in an entry-level technical role (e.g., IT Support, Junior Systems Administrator, Helpdesk/NOC, Cyber Operations, or relevant cloud engineering internship/bootcamp).
  • Location: Must be able to work fully on-site at our Washington, DC office.
  • Linux Fundamentals: Comfortable navigating the Linux command line (Bash), managing file permissions, viewing system logs, and executing basic terminal commands.
  • Networking Core: Solid grasp of foundational networking concepts (DNS, TCP/IP, HTTP/HTTPS, SSH, Subnets, and basic firewall/security group rules).
  • Cloud & Version Control Exposure: Foundational exposure to public cloud concepts (AWS preferred) and basic Git workflows (cloning, branching, commits, Pull Requests).
  • Basic Scripting: Ability to read and write fundamental scripts in Python or Bash to automate repetitive tasks, parse logs, or interact with simple APIs.
  • Security Mindset: Strong conceptual understanding of core security principles (Least Privilege, Multi-Factor Authentication, IAM basics, Encryption).
  • Soft Skills & Growth Mindset: High technical curiosity, excellent written documentation habits, and a strong eagerness to learn directly from senior engineers on-site.
Nice to Have (Bonus Experience / Technologies You Will Learn)
  • Exposure to Infrastructure as Code concepts (Terraform or CloudFormation).
  • Familiarity with container basics (Docker) or CI/CD pipelines (GitHub Actions, GitLab CI).
  • Basic experience using ticketing or monitoring tools (Jira, ServiceNow, CloudWatch, Grafana).
  • Conceptual awareness of federal security or compliance frameworks (FedRAMP, NIST 800-53, or SOC 2).
Desirable Certifications
  • CompTIA Security+ or Linux+
  • AWS Certified Cloud Practitioner or Solutions Architect (Associate)
  • HashiCorp Certified: Terraform Associate (or actively pursuing)
  • Certified: Terraform Associate (or actively pursuing)
  • Microsoft Certified: Azure Fundamentals
Hiring Requirement

Due to the nature of our work with federal government clients and compliance with applicable regulations, this position requires U.S. citizenship. Dual citizenship is not permitted for this role. Candidates must be able to provide documentation verifying sole U.S. citizenship status as part of the background check process.

Any offer of employment is contingent upon the successful completion of all required pre-employment screenings, including a background check, in accordance with applicable laws and government contract requirements.

Compensation Range

$90k to $110k plus bonus and equity.

Benefits & Perks

Knox offers a competitive employee benefits package including Medical, Dental, Vision, Life & Disability, unlimited PEO, and an employee funded 401k plan. Please note, benefits are subject to change.

We are an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. Employment decisions are made without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, veteran status, or any other legally protected status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SecDevOps Engineer (Jr.)
SecDevOps Engineer (Jr.)

Knox Systems • Arlington (VA)

On-site
USD 90,000 - 110,000
Medical benefits
401k plan
Equal opportunity
SecDevOps Engineer (Jr.)
SecDevOps Engineer (Jr.)

Knox Systems, Inc. • Virginia (MN)

On-site
USD 90,000 - 110,000
Medical, Dental, Vision, Life &Dis
Disability coverage
401k plan
SecDevOps Engineer
SecDevOps Engineer

Knox Systems • Washington

On-site
USD 100,000 - 130,000
Medical, Dental, Vision, Life & Disability Insurance
Unlimited Paid Time Off
Employee 401k Plan
SecDevOps Engineer
SecDevOps Engineer

Knox Systems, Inc. • Arlington (VA)

On-site
USD 125,000 - 130,000
Medical
Dental
Vision
+2
SecDevOps Engineer (Jr.)
SecDevOps Engineer (Jr.)

Knox Systems, Inc. • United States

On-site
USD 90,000 - 110,000
Medical
Dental
Vision
+2
Technical Implementation Manager II - FedRAMP
Technical Implementation Manager II - FedRAMP

Knox Systems, Inc. • Arlington (VA)

Hybrid
USD 100,000 - 140,000
Medical
Dental
Vision
+2
Technical Implementation Manager II - FedRAMP
Technical Implementation Manager II - FedRAMP

Knox Systems • United States

Hybrid
USD 100,000 - 140,000
Medical, Dental, Vision, Life & DI
401k plan (employee funded)
Junior SecDevOps Engineer - Federal Cloud Security
Junior SecDevOps Engineer - Federal Cloud Security

Knox Systems • Washington

On-site
USD 90,000 - 110,000
Medical
Dental
Vision
+2
Director of Channels
Director of Channels

Knox Systems • New York (NY)

On-site
USD 180,000 - 225,000
Medical, Dental, Vision benefits
Unlimited Paid Time Off
Employee funded 401k plan
Junior SecDevOps Engineer - Federal Cloud Security
Junior SecDevOps Engineer - Federal Cloud Security

Knox Systems, Inc. • United States

On-site
USD 90,000 - 110,000
Medical
Dental
Vision
+2