Lead Infrastructure Engineer
Hatch ITFull Time
Expert & Leadership (9+ years)
Candidates must have 5+ years of experience in DevOps, SRE, or Infrastructure Engineering roles with hands-on experience in IL5 or FedRAMP High environments. A deep familiarity with AWS GovCloud or Azure Government, strong Infrastructure-as-Code experience using Terraform, Terragrunt, or similar tooling, and proficiency in scripting (e.g., Python, Bash) for automating system tasks are required. Experience building secure CI/CD workflows, knowledge of STIG hardening, CIS benchmarks, and compliance automation, an understanding of zero-trust principles and secure enclave architectures, and the ability to work collaboratively with security and compliance stakeholders are also essential. Preferred qualifications include prior experience contributing to an ATO process for a FedRAMP or DoD deployment, familiarity with Kubernetes in a high-compliance environment, experience with secrets management (Vault, AWS KMS, etc.), and exposure to vulnerability scanning, compliance drift detection, or SIEM integration.
The Senior DevOps Engineer will be responsible for designing, implementing, and managing IL5-compliant infrastructure in AWS GovCloud and/or Azure Government, and automating infrastructure provisioning using Infrastructure-as-Code best practices. They will build and maintain secure CI/CD pipelines in compliance with FedRAMP High / IL5 requirements, and collaborate with security and compliance teams to ensure proper controls, monitoring, and reporting. The role involves configuring logging, alerting, and telemetry in restricted environments, hardening operating systems and container runtimes to meet DISA STIGs and other security benchmarks, and supporting secure secrets management, access controls (RBAC, ABAC), and audit logging. Additionally, the engineer will participate in architecture discussions to ensure infrastructure is scalable, resilient, and compliant, and assist with documentation and evidence collection for audits and ATO processes.
Cybersecurity solutions for data protection
Keeper Security provides cybersecurity solutions aimed at protecting sensitive data for individuals and businesses. Its main product is a zero-knowledge security platform, which means that the company cannot access the data stored by its users, ensuring high levels of privacy and security. This platform is scalable, allowing it to adapt to the needs of various organizations, from small businesses to large enterprises. Unlike many competitors, Keeper Security is recognized for its extensive audits and certifications, which enhance user trust. The company operates on a subscription-based model, offering tailored plans for personal, family, student, business, and enterprise use, with options for multi-year commitments that provide savings. The goal of Keeper Security is to deliver reliable data protection while ensuring continuous updates and support for its users.