This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Amentum is searching for a DevOps Engineer to join our team in Arlington, VA. You will be working in support of a DoW Special Programs customer developing a new application in AWS GovCloud. The mission is to modernize and sustain a secure, web-based platform that consolidates critical government workflows, enabling automated data management, role-based access control, and multi-level security capabilities in support of national security operations. The DevOps Engineer is responsible for owning the full platform lifecycle (infrastructure-as-code, CI/CD pipeline operations, environment stability, security posture, and incident response). You will deploy and configure services using AWS-native tooling, enforce change control discipline, and ensure the platform meets DoD IL4/IL5 compliance requirements at all times.
Job Responsibility
Responsible for the design, deployment, operations, patching, and maintenance of AWS GovCloud infrastructure supporting a production web application
Owns all Infrastructure-as-Code using CloudFormation and CDK with disciplined version-controlled change management i.e no manual console modifications in production
Builds and maintains end-to-end CI/CD pipelines covering build, test, artifact promotion, deployment approvals, and release documentation
Implements and maintains private networking patterns including VPC segmentation, PrivateLink, and deny-by-default egress controls
Enforces least-privilege access across all environment components and supports NIPR/SIPR connectivity requirements as applicable
Integrates security practices into the full DevOps pipeline including development, testing, deployment, and operations. Automates security testing, scanning, and compliance checks throughout the development lifecycle
Implements automated security controls including static code analysis, dynamic application security testing, container scanning, and vulnerability assessment. Establishes and maintains continuous monitoring of application and infrastructure security
Coordinates with the Information Systems Security Engineer on ATO evidence collection, POA&M inputs, and continuous monitoring obligations
Responds to incidents, conducts root cause analysis, and implements corrective actions with full documentation
Maintains complete operational documentation including architecture diagrams, runbooks, and SOPs
Requirements
Minimum of 5 years of experience collectively with the following: Operate and manage production workloads in AWS GovCloud or equivalent FedRAMP High / DoD IL4/IL5 regulated environment
Build and maintain Infrastructure-as-Code using CloudFormation and/or CDK with auditable change control
Design and operate CI/CD pipelines with artifact management, deployment approvals, and rollback procedures
Integrate security practices, tools, and measures into the full DevOps pipeline including development, testing, deployment, and operations
Automate security testing, scanning, and compliance checks throughout the development lifecycle
Implement automated security controls including static code analysis, DAST, container scanning, and vulnerability assessment
Establish mechanisms for continuous monitoring of application and infrastructure security
Mid-level experience with Python or other scripting languages with a focus on automating operational tasks
Experience working in an agile development environment
TS/SCI - This position requires an active DoD TS/SCI security clearance that has been adjudicated in the last 5 years or designated CE and the ability to obtain and maintain special accesses
Bachelor's degree in Information Systems Engineering, Computer Science, Engineering, Business, or other related fields. In absence of degree, additional years of experience may be substituted for educational requirements
5-8 Years
AWS Solutions Architect - Associate (minimum)
Professional preferred
AWS SysOps Administrator - Associate or AWS DevOps Engineer - Professional
Security+ CE
Nice to have
Experience supporting a DoW ATO or FedRAMP authorization process
Familiarity with DISA STIG compliance requirements and implementation
Experience operating PostgreSQL on Amazon RDS including patching coordination and backup/restore validation
Experience with Keycloak or equivalent OIDC/SAML identity provider integration in a GovCloud environment