SecDevOps Engineer (Jr.)
Job description
SecDevOps Engineer (Jr.) at Knox Systems.
About the role
You will monitor Zero Trust Network Access tools such as Zscaler ZPA and PRA to verify application connectors and remote access pathways remain operational within federal environments. You will support secrets management workflows inside HashiCorp Vault, including basic credential generation, entry updates, and confirming automated rotations execute without error. You will review basic IAM permissions and cloud role policies to ensure alignment with least-privilege models under the direct mentorship of senior engineering staff. You will run, test, and troubleshoot pre-defined Terraform modules across development and staging environments in AWS, Azure, or GCP on a daily basis. You will identify and log configuration drift or environment resource issues, assisting senior engineers with standard infrastructure patching and remediation tasks as they arise. You will monitor and triage failing CI/CD pipeline runs within GitHub Actions, GitLab CI, or Azure DevOps, escalating systemic errors to the team when patterns emerge.
Key facts
What you'll do
- Monitor Zero Trust Network Access tools including Zscaler ZPA and PRA to validate application connectivity and secure remote access routes.
- Support secrets lifecycle operations inside HashiCorp Vault, covering basic credential creation, updates, and verification of automated rotation jobs.
- Review foundational IAM permissions and cloud role assignments to confirm adherence to least-privilege principles under senior oversight.
- Execute, test, and troubleshoot predefined Terraform modules across AWS, Azure, and GCP development and staging environments.
- Detect and document configuration drift or resource anomalies, partnering with senior engineers on standard patching and remediation activities.
- Observe and triage CI/CD pipeline failures within GitHub Actions, GitLab CI, or Azure DevOps, escalating recurring issues to the team.
- Analyze automated security scan outputs including SAST, SCA, and container scans embedded in pipeline workflows for basic patterns.
- Adjust, build, and run security base-image layers for containers (Docker) intended for managed Kubernetes clusters such as EKS, AKS, and GKE.
- Maintain and refine fundamental Grafana and CloudWatch dashboards, ensuring alert notifications map correctly to operational notification streams.
- Monitor standard system health indicators and perform low-severity alert triaging to reduce production fatigue and noise.
- Keep telemetry operations open and transparent for ongoing application monitoring and baseline performance tracking.
- Shadow on-call rotations in PagerDuty alongside senior engineers to develop live diagnostic and real-time incident resolution capabilities.
- Collect and format audit evidence for FedRAMP Continuous Monitoring cycles, focusing on controls such as CM-2, CM-6, AU-2, and SC-12.
- Contribute to Plan of Action and Milestones (POA&M) ticket creation, tracking remediation deadlines across the platform.
- Draft and submit technical change requests within ServiceNow, ensuring precise structural documentation for Change Advisory Board review.
Requirements
- You must have 1-2 years of experience in an entry-level technical role, such as IT Support, Junior Systems Administrator, Helpdesk/NOC, Cyber Operations, or a relevant cloud engineering internship or bootcamp.
- You must be located in the United States and eligible to work in Arlington, VA, without sponsorship now or in the future.
- You must be able to commute to our Arlington, VA office reliably and maintain consistent in-person presence during standard Federal working hours.
- You must hold current authorization to access U.S. government systems and environments, including adherence to FedRAMP and Zero Trust security expectations.
- You must demonstrate strong technical fundamentals in Linux, basic networking, Git, and scripting within shell or Python environments.
- You must exhibit a security-first mindset when interacting with cloud infrastructure, identity systems, and automation pipelines.
- You must be comfortable working with Infrastructure as Code tools, including running pre-written Terraform plans and understanding basic CloudFormation playbooks.
- You must be able to sort and triage Wiz or Qualys vulnerability alerts and correlate findings with environment changes or configurations.
- You must be capable of performing basic CrowdStrike endpoint checks and documenting outcomes for review by senior staff.
- You must have experience or training in observability platforms such as Grafana, CloudWatch, and ticketing systems like ServiceNow.
- You must be comfortable working within FedRAMP-authorized boundaries and following defined on-site protocols in Washington, DC.
- You must be willing to participate in shadow on-call rotations and follow established escalation paths for incident response.
- You must be able to read and interpret technical documentation for CI/CD pipelines, SAST/SCA tooling, and container image workflows.
- You must be able to maintain clear communication with senior engineers and stakeholders when escalating issues or documenting changes.
Nice to have
- Familiarity with CI/CD platforms such as GitHub Actions, GitLab CI, or Azure DevOps pipelines and their log structures.
- Basic understanding of containerization and Kubernetes concepts, including image lifecycle and registry operations.
- Experience with dashboarding in Grafana and metric interpretation in CloudWatch.
- Exposure to vulnerability management workflows in tools such as Qualys or Wiz.
- Knowledge of ServiceNow change management processes and CAB documentation standards.
- Understanding of Zero Trust principles, including identity access controls and network access gateways.
- Experience with FedRAMP Continuous Monitoring requirements and evidence collection practices.
Practical notes
- Shifts are primarily during standard Federal business hours with expectation of in-person presence in Arlington, VA.
- On-call shadowing occurs on a rotating schedule and may require availability during non-business hours as defined by program needs.
- Candidates must meet U.S. government eligibility and security requirements; no sponsorship is available for this role.