Senior DevOps/Compliance Engineer (FedRAMP Continuous Compliance)

UBERETHER INC

Sterling (VA)

Hybrid

USD 150,000 - 190,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Medical, Dental, Vision
401K
Paid time off
Education budget

Job summary

UberEther Inc. is seeking a Senior DevOps Engineer in Sterling, VA to lead DevOps strategy and continuous compliance for FedRAMP 20x. You will own CI/CD pipelines, IaC for GCP deployments, and evidence packaging to maintain ongoing compliance post‑deployment.

You will collaborate with Compliance BU, Platform Engineering, and customer engineering to implement automated security gates, policy as code, and OSCAL‑based evidence while mentoring engineers on DevSecOps practices.

Qualifications

  • Bachelor's degree in Computer Science, Engineering, or related field; equivalent experience considered.
  • 8+ years in DevOps, SRE, or platform automation roles.
  • 3+ years building CI/CD pipelines on Google Cloud Platform (GCP).
  • Experience with FedRAMP, DoD, or federal compliance in operations.
  • Strong knowledge of KSI concepts and automation/verification in pipelines.

Responsibilities

  • Define and lead DevOps strategy to implement FedRAMP 20x KSI requirements in CI/CD and operations.
  • Own end‑to‑end CI/CD pipelines, IaC (Terraform/Deployment Manager), and evidence packaging.
  • Develop SOPs and runbooks; support 3PAO assessments and ongoing compliance.
  • Ensure security gates, policy as code, and OSCAL‑based evidence across pipelines.
  • Mentor teams and collaborate cross‑functionally with engineering and compliance.

Skills

DevOps
Site Reliability
CI/CD
Terraform
GCP
Kubernetes
GitLab CI/CD
Security & Compliance
OSCAl/Policy as Code

Education

Bachelor's degree in Computer Science or related field

Tools

Terraform
Deployment Manager
GitLab CI/CD
GKE
OSCAl tooling

Job description

The Team

UberEther is a leader in the hyper-secure infrastructure space for Identity and Access Management (IAM), #ZeroTrust, and compliance acceleration. Our platform and expert services team enable government and commercial customers to have ultimate control over access to critical information. We are employee-first, with outstanding benefits and a track record of upskilling and fostering growth. We're looking for employees who get excited about pioneering novel solutions to new, complex challenges.

This role sits within UberEther's Compliance Business Unit, supporting a FedRAMP 20x advisory project built on Google Cloud Platform (GCP). As Senior DevOps Engineer, you will build and operate the CI/CD pipelines, automation, and monitoring that put FedRAMP 20x Key Security Indicator (KSI) requirements into practice, and author the Standard Operating Procedures (SOPs) that keep Ping's platform in continuous compliance long after go‑live.

Responsibilities
DevOps Strategy & Continuous Compliance Leadership
  • Serve as the principal DevOps authority for implementing FedRAMP 20x KSI requirements into the CI/CD and operations model
  • Define and maintain the automation roadmap for operationalizing all the KSIs across the FedRAMP KSI families within the Advantage DevOps toolchain
  • Lead design sessions with engineering to determine how each KSI is enforced, tested, and evidenced in the deployment pipeline
  • Drive technical decision‑making on pipeline gating, automated policy checks, and continuous monitoring instrumentation
  • Partner with the Senior Architect and Compliance BU leadership to translate KSI mapping decisions into working DevOps procedures
  • Establish DevOps standards and design patterns for KSI enforcement that can be reused across future GCP engagements
DevOps Implementation & Automation
  • Own the end‑to‑end implementation of CI/CD pipelines and automation that enforce FedRAMP 20x KSI requirements across Advantage deployments on Google Cloud Platform
  • Build and maintain Infrastructure as Code (Terraform, Deployment Manager) that encodes KSI controls directly into GCP deployments
  • Implement automation that continuously collects and packages compliance evidence for each of the KSIs
  • Stand up container security scanning, network segmentation enforcement, and secrets management within the CI/CD pipeline
  • Build and maintain GitLab CI/CD pipelines, Terraform modules, and secure deployment tooling for the environment
  • Champion DevSecOps practices, ensuring KSI‑aligned security gates are built into every pipeline stage from day one
SOP Development & Continuous Compliance
  • Author and maintain Standard Operating Procedures (SOPs) covering deployment, monitoring, incident response, and KSI verification for the platform
  • Lead working sessions with engineering to document repeatable, auditable procedures for maintaining KSI compliance post‑authorization
  • Produce SOP documentation suitable for assessor review, mapping each procedure back to its corresponding KSI
  • Support 3PAO assessments and FedRAMP 20x reviews by walking through operational procedures and evidence pipelines
  • Translate compliance requirements into operational runbooks that align with Advantage delivery standards
  • Drive continuous improvement of SOPs based on assessor feedback, CR26 verification results, and evolving FedRAMP 20x guidance
Monitoring, Evidence & Compliance Integration
  • Work closely with the Compliance Architect and SoC functions to ensure monitoring dashboards and alerting satisfy KSI evidence requirements
  • Build automated KSI verification jobs that continuously confirm each of the KSI families remains in a compliant state
  • Maintain remediation runbooks and system hardening procedures specific to the GCP‑hosted environment
  • Support 3PAO assessments and audits by producing and explaining automated evidence packages tied to each KSI
  • Implement Policy as Code and machine readable/OSCAL‑based evidence generation across the CI/CD pipeline
  • Ensure proper integration between GCP‑native security tooling, pipeline automation, and UberEther's compliance evidence model
Cross‑Team Collaboration & Mentorship
  • Foster technical collaboration between UberEther's Compliance BU, Platform Engineering, and customer engineering team
  • Mentor engineers on DevSecOps practices, GCP automation, and FedRAMP 20x continuous monitoring requirements
  • Lead retrospectives focused on improving pipeline reliability and KSI enforcement for future GCP engagements
  • Participate in Level 10 (L10) meetings, providing DevOps insight on progress and cross‑team dependencies
  • Develop training content and SOP walkthroughs to help engineers operate within FedRAMP 20x continuous compliance requirements
  • Serve as a technical ambassador for UberEther's DevOps and continuous compliance capabilities with Ping and future GCP customers
Primary Qualifications
Education & Experience
  • Bachelor's degree in Computer Science, Engineering, or related technical field; equivalent experience considered
  • 8+ years of experience in DevOps, site reliability engineering, or platform automation roles
  • 3+ years of experience building CI/CD pipelines and automation on Google Cloud Platform (GCP)
  • Proven track record of implementing security or compliance controls directly into deployment pipelines
  • Experience supporting FedRAMP, DoD, or other federal compliance frameworks in an operational capacity
Technical Expertise
  • Expert‑level knowledge of Google Cloud Platform (GCP) services, IAM, networking, and security tooling, with relevant certifications (Professional Cloud DevOps Engineer preferred)
  • Strong understanding of FedRAMP 20x Key Security Indicators (KSIs) and how they translate into pipeline and operational controls
  • Deep expertise in Infrastructure as Code tools (Terraform, Deployment Manager) and GitOps workflows
  • Strong experience with containerization and orchestration (Docker, Kubernetes/GKE) in secure, compliance‑focused environments
  • Hands‑on experience with CI/CD platforms such as GitLab CI/CD, including pipeline security gating and policy enforcement
  • Experience with compliance automation and evidence‑generation tooling, including OSCAL and Policy as Code frameworks
Compliance & Security Knowledge
  • Solid understanding of FedRAMP 20x requirements, KSI families, and continuous compliance obligations
  • Working knowledge of NIST 800‑53 security controls and how they are operationalized in a CI/CD environment
  • Experience supporting Assessment & Authorization (A&A) activities from an operations or DevOps perspective
  • Experience with FISMA, FIPS 140‑2, and related federal security requirements
  • Proven ability to translate compliance requirements into working automation, SOPs, and evidence pipelines
Leadership & Communication
  • Strong communication skills with ability to document clear, assessor‑ready SOPs and explain automation to technical and non‑technical audiences
  • Proven ability to work cross‑functionally with architects, engineers, and compliance staff without direct authority
  • Strong customer‑facing skills with experience supporting federal customers and compliance assessors during technical reviews
  • Demonstrated ability to manage multiple automation and documentation workstreams simultaneously
  • Track record of driving pipeline and process improvements in fast‑paced, dynamic environments
Differentiators
  • Professional certifications: Google Professional Cloud DevOps Engineer, CKA/CKAD, AWS/GCP security certifications, or CISSP
  • Prior experience supporting a FedRAMP 20x pilot engagement
  • Background in writing SOPs or operational documentation for federally authorized systems
  • Experience building automated OSCAL or KSI evidence pipelines
  • Experience with compliance automation frameworks such as OSCAL, InSpec, or similar Policy as Code tools
  • Hands‑on experience operating IAM platforms such as Ping Identity, SailPoint, CyberArk, or Radiant Logic
  • Track record of building internal tooling or automation that reduced manual compliance effort
Location

This role is offered as a hybrid or remote position based out of our Sterling, VA office. The role requires eligibility and passing a clean background check. Please ensure you meet all eligibility requirements before applying.

Salary

The base salary range for this position is between $150,000-$190,000 depending on experience.

Benefits

We understand the value of such people, reward them accordingly, and provide best‑in‑class benefits to support them and their family's well‑being. Full‑time employees are eligible to receive top‑notch Medical, Dental, Vision, 401K savings plan, Life Insurance, and Short and Long‑term Disability benefits as well as generous paid flex‑time, education and technology reimbursement.

This includes:

  • 100% employer covered health care premiums for employee AND dependents
  • 100% match up to 6% 401k
  • Education and professional development budget
  • 25 PTO days per year, which increases with tenure
  • Annual technology budget
Core Values

UberEther's Core Values are a set of guiding principles that define our expectations of employees. Please be prepared to discuss these in your interview process and provide examples of where you have demonstrated these core values.

  • Grow With Purpose - Continuously develop your skills and knowledge while helping others grow
  • Confident, Not Cocky - Bring expertise with humility and openness to learning
  • The IT Factor - Demonstrate passion, initiative, and the ability to make things happen
  • Team Player - Collaborate effectively and put team success ahead of individual recognition
  • Whole Authentic Self - Bring your complete, genuine self to work every day
All qualified applicants will receive consideration for employment without regard to race, color, religion, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior DevOps/Compliance Engineer (FedRAMP Continuous Compliance)
Senior DevOps/Compliance Engineer (FedRAMP Continuous Compliance)

UberEther • Sterling (VA)

Hybrid
USD 150,000 - 190,000
Medical, Dental & Vision
401K with company match
Paid time off
+3
Engineering Manager
Engineering Manager

UberEther • Sterling (VA)

Hybrid
USD 180,000 - 200,000
100% employer covered health care premiums
6% 401k match
25 PTO days per year
+2
Senior Security Compliance Engineer, Public Sector
Senior Security Compliance Engineer, Public Sector

Jobgether • United States

On-site
USD 139,000 - 196,000
Equity
Health benefits
Flexible PTO
+2
Senior DevOps for FedRAMP Compliance on GCP
Senior DevOps for FedRAMP Compliance on GCP

UberEther • Sterling (VA)

Hybrid
USD 150,000 - 190,000
Medical, Dental & Vision
401K with company match
Paid time off
+3
Senior DevOps & Compliance Engineer - FedRAMP 20x
Senior DevOps & Compliance Engineer - FedRAMP 20x

UBERETHER INC • Sterling (VA)

Hybrid
USD 150,000 - 190,000
Medical, Dental, Vision
401K
Paid time off
+1
Senior GRC Engineer - GOV (FedRAMP 20x)
Senior GRC Engineer - GOV (FedRAMP 20x)

Workstreet • Northern (KY)

Hybrid
USD 150,000 - 210,000
Career development
Training reimbursement
Competitive compensation
+2
Compliance Operations Lead
Compliance Operations Lead

GovSignals • New York (NY)

On-site
USD 140,000 - 190,000
100% employer-paid medical, vision, and dental
Unlimited PTO
Equity in a fast-growing startup
Federal Platform Engineer
Federal Platform Engineer

Horizon3 AI • United States

Hybrid
USD 120,000 - 190,000
FedRamp Compliance Analyst
FedRamp Compliance Analyst

Abnormalsecurity • United States

On-site
USD 115,000 - 173,000
Staff Site Reliability Engineer, EPG (FedRAMP)
Staff Site Reliability Engineer, EPG (FedRAMP)

Okta • Bellevue (WA)

On-site
USD 180,000 - 240,000