<h2 style="margin-bottom:4px;text-indent:-0.5pt;"><span style="font-size:16pt;"><span style="line-height:107%;"><span style="font-family:Calibri, sans-serif;"><span style="color:#0f4761;"><span style="font-weight:normal;">Role summary</span></span></span></span></span></h2><span style="font-size:12pt;"><span style="line-height:96%;"><span style="font-family:Calibri, sans-serif;"><span style="color:#000000;">We are seeking a remote Senior DevSecOps Engineer to own and evolve the platform — Terraform, EKS, GitLab CI/CD security gates, GitOps delivery, observability, and FISMA controls — and set the engineering standard for the team. You are the person who catches a backend block in the wrong module before it merges, and who makes the security gate something developers trust rather than route around.</span></span></span></span><h2 style="text-indent:-0.5pt;"><span style="font-size:16pt;"><span style="line-height:107%;"><span style="font-family:Calibri, sans-serif;"><span style="color:#0f4761;"><span style="font-weight:normal;">What you’ll do</span></span></span></span></span></h2><ul><li style="margin-bottom:2px;margin-left:7px;"><span style="font-size:12pt;"><span style="line-height:95%;"><span style="font-family:Calibri, sans-serif;"><span style="color:#000000;">Own the <b>Terraform</b> estate across the three repos and the 2-stack-perenv layout — directory-per-env roots, semver-pinned module consumption, a <b>provider-pinning contract</b> (version ranges in modules, locked in roots), S3 state with native locking, and <b>OIDC (no static keys)</b>.</span></span></span></span></li><li style="margin-left:7px;margin-bottom:2px;"><span style="font-size:12pt;"><span style="line-height:96%;"><span style="font-family:Calibri, sans-serif;"><span style="color:#000000;">Lead <b>state-safe refactors</b> — split the monolith, fold sandbox stacks into the <span style="font-size:11pt;"><span style="line-height:96%;"><span style="font-family:'Courier New';">data</span></span></span> stack using <span style="font-size:11pt;"><span style="line-height:96%;"><span style="font-family:'Courier New';">moved</span></span></span> blocks / <span style="font-size:11pt;"><span style="line-height:96%;"><span style="font-family:'Courier New';">state mv</span></span></span>, with backed-up state and zero-destroy plans on stateful resources (Aurora, Redis).</span></span></span></span></li><li style="margin-left:7px;margin-bottom:2px;"><span style="font-size:12pt;"><span style="line-height:96%;"><span style="font-family:Calibri, sans-serif;"><span style="color:#000000;">Build and <b>operate EKS</b> (toward Auto Mode), <b>GitLab CI</b> (runner-onEKS), and <b>Argo CD</b> GitOps — Helm, image signing, Kyverno admission, OPA policy decisions.</span></span></span></span></li><li style="margin-left:7px;margin-bottom:2px;"><span style="font-size:12pt;"><span style="line-height:96%;"><span style="font-family:Calibri, sans-serif;"><span style="color:#000000;">Harden the <b>CI/CD security gate</b>: container/filesystem scanning (Trivy), secret detection (Gitleaks), SBOM + signing, policy-as-code deny-gates, and ECR scan-on-push — wired so a failing gate blocks the merge.</span></span></span></span></li><li style="margin-left:7px;"><span style="font-size:12pt;"><span style="line-height:107%;"><span style="font-family:Calibri, sans-serif;"><span style="color:#000000;">Stand up the <b>AWS-native observability stack</b> (CloudWatch / </span></span></span></span></li></ul><span style="font-size:12pt;"><span style="line-height:96%;"><span style="font-family:Calibri, sans-serif;"><span style="color:#000000;">Container Insights, AMP, X-Ray/ADOT, Managed Grafana, Application Signals) with SLOs, alarms-as-code, and a <b>dead-man’s-switch</b> on the alerting path itself.<br><span style="font-size:12pt;"><span style="line-height:96%;"><span style="font-family:Calibri, sans-serif;"><span style="color:#000000;">Drive the <b>private-network migration</b> (TGW egress, VPC endpoints, no NAT/IGW) and close FISMA gaps (CloudTrail/Config, Security Hub NIST 800-53, KMS where required, audit-account separation).</span></span></span></span></span></span></span></span><ul style="margin-bottom:13px;"><li style="margin-bottom:13px;margin-left:7px;"><span style="font-size:12pt;"><span style="line-height:107%;"><span style="font-family:Calibri, sans-serif;"><span style="color:#000000;"><b>Review teammates’ IaC and set the standards.</b></span></span></span></span></li></ul><h2 style="text-indent:-0.5pt;"><span style="font-size:16pt;"><span style="line-height:107%;"><span style="font-family:Calibri, sans-serif;"><span style="color:#0f4761;"><span style="font-weight:normal;">Must-haves</span></span></span></span></span></h2><ul><li style="margin-left:7px;margin-bottom:2px;"><span style="font-size:12pt;"><span style="line-height:96%;"><span style="font-family:Calibri, sans-serif;"><span style="color:#000000;"><b>Terraform at scale</b> — root vs. child modules, state isolation, <span style="font-size:11pt;"><span style="line-height:96%;"><span style="font-family:'Courier New';">for_each</span></span></span>/<span style="font-size:11pt;"><span style="line-height:96%;"><span style="font-family:'Courier New';">count</span></span></span>/<span style="font-size:11pt;"><span style="line-height:96%;"><span style="font-family:'Courier New';">dynamic</span></span></span>, drift, provider-pin conflicts, and <b>state migration</b> (<span style="font-size:11pt;"><span style="line-height:96%;"><span style="font-family:'Courier New';">moved</span></span></span>/<span style="font-size:11pt;"><span style="line-height:96%;"><span style="font-family:'Courier New';">state mv</span></span></span>) without destroying data. Writes modules others reuse. Can explain why workspaces ≠ directory-per-env.</span></span></span></span></li><li style="margin-bottom:2px;margin-left:7px;"><span style="font-size:12pt;"><span style="line-height:95%;"><span style="font-family:Calibri, sans-serif;"><span style="color:#000000;"><b>Strong AWS cloud engineering</b> — VPC/networking (private subnets, endpoints, TGW), IAM/OIDC, EKS, ECR, ALB/API-GW, and when SSE-S3 vs. KMS-CMK is actually <i>required</i>.</span></span></span></span></li><li style="margin-left:7px;margin-bottom:2px;"><span style="font-size:12pt;"><span style="line-height:96%;"><span style="font-family:Calibri, sans-serif;"><span style="color:#000000;"><b>EKS you have operated, not just used</b> — node/pod networking, IRSA, admission control, upgrades, troubleshooting a broken rollout.</span></span></span></span></li><li style="margin-left:7px;"><span style="font-size:12pt;"><span style="line-height:107%;"><span style="font-family:Calibri, sans-serif;"><span style="color:#000000;"><b>CI/CD security (the “Sec” in DevSecOps)</b> — </span></span></span></span></li></ul><span style="font-size:12pt;"><span style="line-height:96%;"><span style="font-family:Calibri, sans-serif;"><span style="color:#000000;">SAST/dependency/container scanning, secret scanning, supply-chain (SBOM, signing), policy-as-code, secrets hygiene. You have made a pipeline <i>block</i> on a finding.</span></span></span></span><ul style="margin-bottom:13px;"><li style="margin-left:7px;margin-bottom:2px;"><span style="font-size:12pt;"><span style="line-height:96%;"><span style="font-family:Calibri, sans-serif;"><span style="color:#000000;"><b>Federal compliance fluency</b> — NIST 800-53 / FISMA-Moderate; can map a control family (AU, CM, SC) to an actual implementation.</span></span></span></span></li><li style="margin-bottom:13px;margin-left:7px;"><span style="font-size:12pt;"><span style="line-height:107%;"><span style="font-family:Calibri, sans-serif;"><span style="color:#000000;">Writes clear PRs and <b>reviews others’ code constructively</b>.</span></span></span></span></li></ul><h2 style="text-indent:-0.5pt;"><span style="font-size:16pt;"><span style="line-height:107%;"><span style="font-family:Calibri, sans-serif;"><span style="color:#0f4761;"><span style="font-weight:normal;">Strongly preferred</span></span></span></span></span></h2><ul style="margin-bottom:15px;"><li style="margin-left:7px;margin-bottom:2px;"><span style="font-size:12pt;"><span style="line-height:96%;"><span style="font-family:Calibri, sans-serif;"><span style="color:#000000;">Observability depth (OpenTelemetry, Prometheus/Grafana, SLO/errorbudget design).</span></span></span></span></li><li style="margin-left:7px;margin-bottom:2px;"><span style="font-size:12pt;"><span style="line-height:96%;"><span style="font-family:Calibri, sans-serif;"><span style="color:#000000;">Prior regulated/federal environment (NOAA/DoD/civilian agency, ATO process), clearance or Public-Trust history.</span></span></span></span></li><li style="margin-bottom:15px;margin-left:7px;"><span style="font-size:12pt;"><span style="line-height:96%;"><span style="font-family:Calibri, sans-serif;"><span style="color:#000000;">GitLab CI specifically, Argo CD, and Kubernetes runners.</span></span></span></span></li></ul><p><span style=\"font-size:16px\"><span style=\"font-family:Trebuchet MS,Helvetica,sans-serif\">GAMA-1 also offers a variety of benefits, including health insurance coverage, life and disability insurance, 401(k) savings plan, training and career development opportunities, paid holidays and paid time off (PTO - to cover vacation, illness or disability, appointments, emergencies or other situations that require time off from work). For more information click <a href=\"https://www.gama1tech.com/gama-benefits/\">here.</a></span></span></p> <p><strong><span style=\"font-size:16px\"><span style=\"font-family:Trebuchet MS,Helvetica,sans-serif\">ABOUT GAMA-1</span></span></strong></p> <p><span style=\"font-size:16px\"><span style=\"font-family:Trebuchet MS,Helvetica,sans-serif\">GAMA-1 is a rapidly growing technology business that is based in Greenbelt, Maryland. GAMA-1 Technologies provides strategic information assurance, information security, and business enterprise and networking solutions to the Federal Government. Our success is based on the utilization of industry and agency standards, establishment of standardized processes, and IT Services expertise. At GAMA-1, we believe employees should grow, achieve, and develop just as the company grows, achieves, and develops. GAMA-1 is committed to providing our employees with opportunities for career advancement throughout their employment. For more information, visit www.gama1tech.com</span></span></p> <p><span style=\"font-size:16px\"><span style=\"font-family:Trebuchet MS,Helvetica,sans-serif\">GAMA-1 is an Equal Opportunity Employer and all qualified applicants will receive consideration for employment without regard to: veteran status, uniformed servicemember status, race, color, religion, sex, sexual orientation, gender identity, age, pregnancy (including childbirth, lactation and related medical conditions), national origin or ancestry, citizenship or immigration status, physical or mental disability, genetic information (including testing and characteristics), domestic violence victims, political orientation, status as a smoker or tobacco user, hairstyle, use of a service animal, education status, familial status, HIV/AIDS status, height, weight, reproductive healthcare decisions or any other category protected by federal, state or local law.</span></span></p>