Sr. DevSecOps Engineer

Penta Research, Inc.

Huntsville (AL)

On-site

USD 140,000 - 190,000

Full time

5 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Penta Research, Inc. seeks a Senior DevSecOps Engineer to run and evolve cloud infrastructure used by engineering teams. The role spans AWS, Kubernetes, and CI, with a shift to a GovCloud environment defined entirely as code.

You will ensure health of existing systems while standing up the new platform and enabling secure workloads and AI tooling. The position emphasizes security-by-design, automating guardrails, and clear design documentation.

Qualifications

  • Proficiency in Python and/or Go, plus shell scripting.
  • Deep hands-on AWS experience in a multi-account org with IaC.
  • Experience building secure, code-based security guardrails and evidence.
  • CI/CD and container supply chain experience including image signing and verification.
  • Hands-on with hosted model services or LLM gateway tooling.
  • Familiarity with NIST SP 800-171, CMMC, or related controls is a plus.
  • Experience operating Kubernetes in production, preferably EKS.
  • Strong written design notes, runbooks, and merge request reviews.

Responsibilities

  • Operate and improve AWS environments, Kubernetes clusters, and CI, migrating workloads as the new org comes online.
  • Build a new multi-account AWS GovCloud organization as code.
  • Design and operate segmented network planes and secure ingress/egress.
  • Own the software supply chain from commit to cluster with signed artifacts and private PKI.
  • Translate security requirements into automated guardrails and evidence with security teams.
  • Write clear design notes and runbooks; improve AI-assisted workflows used by the team.
  • Roll out and support AI developer tooling and review MCP servers and runtimes.

Skills

Terraform / OpenTofu
Python
Go
Shell scripting
AWS multi-account
CI/CD
Kubernetes (EKS)
Technical writing
AI tooling / coding agents

Education

BS in Computer Science/Engineering

Tools

Argo CD
Flux
Terraform

Job description

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.

Full Time Huntsville, AL, US

Full Time

Active Secret Security Clearance Required

JOB SUMMARY

We are seeking a Senior DevSecOps Engineer to operate the cloud infrastructure our engineering teams depend on today and to build its successor from the ground up. The current environment spans AWS, Kubernetes, and CI. The next one is a new AWS GovCloud organization defined entirely as code, with the networking, identity, and software supply chain that a regulated engineering organization needs.

You will keep the existing environment healthy while the new one takes shape, then move workloads into it. You will also run the tooling that gives our engineers governed access to AI models and coding agents.

This is a building role on a small team, and the scope is broad by design. You will not maintain a compliance binder; you will turn security requirements into code that produces its own evidence.

Key Responsibilities
  • Operate and improve our existing AWS environments, Kubernetes clusters, and CI platform, and migrate workloads into the new organization as it comes online
  • Build a new multi-account AWS GovCloud organization as code
  • Build and operate segmented network planes: Transit Gateway, Firewalls, IPAM, PrivateLink, and VPNs to our facilities
  • Deliver secure environment ingress / egress
  • Own the software supply chain from commit to cluster: CI/CD runner fleets, FIPS-validated images, signed artifacts, replicated registries, private PKI
  • Partner with security and compliance to translate NIST SP 800-171 and CMMC controls into automated guardrails and evidence, and to triage and burn down security findings
  • Write clear design notes, merge request reviews, and runbooks, and help improve the shared AI-assisted workflows the team uses every day
  • Roll out and support AI developer tooling (Claude Code and similar) with managed settings, and review, harden, and operate the MCP servers and agent runtimes our teams depend on
Required Skills and Experience
  • Production Terraform or OpenTofu: reusable modules, state management, imports and refactors, and careful plan review
  • Proficiency in Python and/or Go, plus shell scripting
  • Clear, concise technical writing
  • Deep hands-on AWS experience in a multi-account organization: IAM policy evaluation, Organizations and service control policies, and Identity Center or equivalent federation with an external IDP
  • Cloud networking you can debug under pressure: VPC design, Transit Gateway routing and segmentation, firewalls and inspection, DNS, PrivateLink, and site-to-site VPN with BGP; you can answer “why can’t X talk to Y” across accounts
  • CI/CD and container supply chain experience, including image builds, signing and verification, secrets management, and vulnerability scanning
  • Hands-on experience running access to a hosted model service (Amazon Bedrock, Azure OpenAI, Vertex AI, or similar) or an LLM gateway
  • Experience with AI coding agents (Claude Code or equivalent), with a working understanding of its risks: prompt injection, excessive agency, token and secret exposure, and untrusted tool servers
Desired Skills and Experience
  • AWS GovCloud experience, or work inside FedRAMP, NIST SP 800-171, CMMC, or ITAR-controlled environments
  • Greenfield landing-zone or account-vending work, including AWS Network Firewall and IPAM
  • Private PKI (for example AWS Private CA), HSM-backed key management, and mTLS
  • Service mesh (Istio or similar) and GitOps tooling (Argo CD, Flux, or similar)
  • LLM gateway operations (LiteLLM or equivalent), per-user cost attribution, and model invocation logging
  • Building or securing MCP servers and agent workflows
  • Shared AI workflows you built that other engineers adopted: hooks, commands, rules files, skills, or agent pipelines
  • Operating Kubernetes in production, preferably EKS
  • FIPS 140-3 validated cryptography and hardened container images
  • Experience in aerospace, defense, or other export-controlled programs
Education & Work Experience
  • BS in Computer Science, Computer Engineering, or a related field, or equivalent practical experience
  • 7+ years in infrastructure, platform, security, or site reliability engineering, including 3+ years building on AWS with infrastructure as code
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cloud/Network Infrastructure Engineer, Senior
Cloud/Network Infrastructure Engineer, Senior

ecsfederal • Virginia (MN)

Hybrid
USD 123,000 - 184,000
DevOps Engineer II
DevOps Engineer II

RiskForce • Northern (KY)

On-site
USD 110,000 - 160,000
Senior AWS Cloud Architect — Security & DevOps Lead
Senior AWS Cloud Architect — Security & DevOps Lead

Gsc Llc • Washington

Hybrid
USD 120,000 - 150,000
Continuous learning environment
Professional growth opportunities
Modern enterprise technology stack
Junior DevSecOps Engineer
Junior DevSecOps Engineer

Phizenix • Ruston (LA)

On-site
USD 70,000 - 100,000
Junior DevSecOps Engineer
Junior DevSecOps Engineer

Phizenix Inc. • Reston (VA)

On-site
USD 70,000 - 95,000
AWS GovCloud
AWS GovCloud

Caduceus • Bayamón (PR)

On-site
USD 150,000 - 210,000
Junior DevOps Engineer
Junior DevOps Engineer

webAI • United States

Remote
USD 110,000 - 160,000
Equity options
Parental leave
401(k)
+3
DevSecOps Engineer
DevSecOps Engineer

Tari Labs, LLC. • United States

On-site
USD 135,000 - 220,000
Senior Cloud Operations Engineer
Senior Cloud Operations Engineer

JumpMind, LLC • Columbus (OH)

On-site
USD 120,000 - 180,000
Junior DevSecOps Engineer
Junior DevSecOps Engineer

Inadev • Reston (VA)

On-site
USD 80,000 - 115,000