Job Summary:
Amentum is searching for a DevOps Engineer to join their team in Arlington, VA. The role involves supporting a DoW Special Programs customer in developing a new application in AWS GovCloud, focusing on modernizing and sustaining a secure, web-based platform for critical government workflows.
Responsibilities:
• Responsible for the design, deployment, operations, patching, and maintenance of AWS GovCloud infrastructure supporting a production web application.
• Owns all Infrastructure-as-Code using CloudFormation and CDK with disciplined version-controlled change management i.e no manual console modifications in production.
• Builds and maintains end-to-end CI/CD pipelines covering build, test, artifact promotion, deployment approvals, and release documentation.
• Implements and maintains private networking patterns including VPC segmentation, PrivateLink, and deny-by-default egress controls.
• Enforces least-privilege access across all environment components and supports NIPR/SIPR connectivity requirements as applicable.
• Integrates security practices into the full DevOps pipeline including development, testing, deployment, and operations. Automates security testing, scanning, and compliance checks throughout the development lifecycle.
• Implements automated security controls including static code analysis, dynamic application security testing, container scanning, and vulnerability assessment. Establishes and maintains continuous monitoring of application and infrastructure security.
• Coordinates with the Information Systems Security Engineer on ATO evidence collection, POA&M inputs, and continuous monitoring obligations.
• Responds to incidents, conducts root cause analysis, and implements corrective actions with full documentation.
• Maintains complete operational documentation including architecture diagrams, runbooks, and SOPs.
• Possesses and applies expertise across multiple complex infrastructure assignments. Operates with appreciable latitude in developing methodology and presenting solutions to problems. Contributes to program deliverables and performance metrics where applicable.
Qualifications:
Required:
• Minimum of 5 years of experience collectively with the following:
• Operate and manage production workloads in AWS GovCloud or equivalent FedRAMP High / DoD IL4/IL5 regulated environment
• Build and maintain Infrastructure-as-Code using CloudFormation and/or CDK with auditable change control
• Design and operate CI/CD pipelines with artifact management, deployment approvals, and rollback procedures
• Implement private networking (VPC design, endpoints, PrivateLink, and egress restriction patterns)
• Integrate security practices, tools, and measures into the full DevOps pipeline including development, testing, deployment, and operations
• Automate security testing, scanning, and compliance checks throughout the development lifecycle
• Implement automated security controls including static code analysis, DAST, container scanning, and vulnerability assessment
• Establish mechanisms for continuous monitoring of application and infrastructure security
• Mid-level experience with Python or other scripting languages with a focus on automating operational tasks
• Experience working in an agile development environment
• TS/SCI - This position requires an active DoD TS/SCI security clearance that has been adjudicated in the last 5 years or designated CE and the ability to obtain and maintain special accesses.
• Bachelor’s degree in Information Systems Engineering, Computer Science, Engineering, Business, or other related fields. In absence of degree, additional years of experience may be substituted for educational requirements
• 5-8 Years
• AWS Solutions Architect - Associate (minimum); Professional preferred
• AWS SysOps Administrator - Associate or AWS DevOps Engineer - Professional
• Security+ CE
Preferred:
• Experience supporting a DoW ATO or FedRAMP authorization process
• Familiarity with DISA STIG compliance requirements and implementation
• Experience operating PostgreSQL on Amazon RDS including patching coordination and backup/restore validation
• Experience with Keycloak or equivalent OIDC/SAML identity provider integration in a GovCloud environment
• AWS Security- Specialty certification
• Git, GitLab, Terraform, Splunk, HashiCorp Vault, JIRA, Jenkins, Ansible
• Amazon Web Services GovCloud
• Microsoft Windows Server and Linux
• AWS Associate level or above certification
• AWS Security — Specialty.
• ITIL Foundation.
Company:
Amentum is a technology and engineering company for security, defense, and energy. Founded in 2020, the company is headquartered in Germantown, USA, with a team of 10001+ employees. The company is currently Late Stage.