Responsibilities
- Help monitor Zero Trust Network Access solutions like Zscaler ZPA and PRA, ensuring application connectors and remote access functions operate correctly.
- Support credential lifecycle management in HashiCorp Vault, including creating credentials, updating entries, and verifying automated rotation processes complete successfully.
- Evaluate IAM permissions and cloud role configurations to confirm adherence to least-privilege principles under guidance from senior staff.
- Execute, test, and troubleshoot predefined Terraform modules in AWS, Azure, or GCP development and staging environments.
- Detect and document configuration deviations or infrastructure issues, supporting senior engineers with standard patching and remediation.
- Assess cloud security groups, public endpoint settings, and basic network routing to validate compliance with established baselines.
- Monitor and triage failed CI/CD pipeline executions in GitHub Actions, GitLab CI, or Azure DevOps, escalating recurring issues to the team.
- Review output from integrated security scanning tools in pipelines, including static application testing, software composition analysis, and container scanning.
- Help update, build, and deploy secure container base images for use in managed Kubernetes environments such as EKS, AKS, and GKE.
- Support compliance efforts by collecting audit evidence programmatically for FedRAMP Continuous Monitoring cycles, focusing on controls CM-2, CM-6, AU-2, and SC-12.
- Assist in generating and tracking Plan of Action and Milestones (POA&M) tickets, monitoring remediation timelines across systems.
- Prepare and submit technical change requests in ServiceNow, ensuring proper documentation structure for Change Advisory Board review.
- Maintain and modify basic observability dashboards in Grafana and CloudWatch to ensure alerts route correctly to operational notification channels.
- Track standard system health metrics and perform initial triage of low-severity alerts to reduce alert fatigue in production environments.
- Support telemetry operations to enable continuous monitoring of application performance and security posture.
- Participate in a shadow on-call rotation using PagerDuty alongside experienced engineers to build real-time incident diagnosis and response capabilities.
Work Arrangement
On-site — Washington, DC
Hiring Requirement
U.S. citizenship is required for this role due to federal government client engagements and regulatory compliance. Dual citizenship is not allowed. Candidates must provide proof of sole U.S. citizenship during the background check process. Employment offers are contingent upon passing all required pre-employment screenings, including a background investigation per applicable laws and government contract obligations.
Benefits & Perks
A competitive benefits package is offered, including Medical, Dental, Vision, Life & Disability insurance, unlimited PTO, and an employee-contributed 401k plan. Benefits are subject to change over time.
Equal Opportunity Employer
Diversity is valued and inclusion is prioritized across the workplace. Hiring decisions are made without discrimination based on race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, veteran status, or other legally protected characteristics. Veteran applicants and transitioning service members are strongly encouraged to apply, as their skills and experience are highly regarded.