M

Senior DevSecOps/SRE - Cloud Platform Engineering (Remote Contract)

Medasource Washington Dc-baltimore Area
Remote
This Job is No Longer Active This position is no longer accepting applications
AI Summary

Seeking a Senior DevSecOps/SRE to architect, automate, and operate secure, compliant, and cost-optimized cloud environments on Azure (AKS) and AWS (EKS). This hands-on role focuses on standardizing DevSecOps patterns, building GitOps workflows with Argo CD, and implementing secure CI/CD pipelines. Key responsibilities include IaC, security policy enforcement, cost optimization, and ensuring resilience for HIPAA/NIST-aligned workloads.

Key Highlights
Architect, automate, and operate secure, compliant, and cost-optimized cloud environments for NBS modernization platform.
Standardize DevSecOps patterns across Azure (AKS) and AWS (EKS) using GitOps (Argo CD) and secure CI/CD (GitHub Actions).
Implement security policies, optimize costs, and ensure resilience for HIPAA- and NIST-aligned workloads.
Hands-on engineering role defining the golden path for JMC projects.
Map IaC and CI/CD controls to HIPAA / NIST 800-171 / FedRAMP evidence.
Technical Skills Required
Kubernetes AKS EKS Terraform Helm Argo CD GitHub Actions OIDC Python Bash PowerShell Azure Defender AWS Security Hub AWS Inspector OPA Gatekeeper Kyverno Azure Monitor Prometheus Grafana AWS CloudWatch OpenTelemetry Velero Azure Blob Storage AWS S3
Benefits & Perks
100% Remote
6-month contract with possibility to extend
ASAP Start

Job Description


Position: Sr. DevSecOps/SRE

Location: 100% Remote

Duration: 6 month contract with possibility to extend

Start: ASAP


Our client s seeking a Senior DevSecOps/Site Reliability Engineer to architect, automate, and operate secure, compliant, and cost-optimized cloud environments for the NBS modernization platform. You will standardize DevSecOps patterns across Azure (AKS) and AWS (EKS), build GitOps workflows with Argo CD, and implement secure CI/CD pipelines with GitHub Actions and Terraform/Helm. This is a hands-on engineering role that defines the golden path for all JMC projects—automating provisioning, enforcing security policies, optimizing costs, and ensuring resilience for HIPAA- and NIST-aligned workloads.


Key Responsibilities

· Design, deploy, and maintain multi-environment AKS and EKS clusters, including node pools, autoscaling, and private networking.

· Standardize Terraform + Helm modules for cross-cloud provisioning, secrets management, and network baselines.

· Build Argo CD App-of-Apps pipelines for environment promotion and policy-based synchronization.

· Create GitHub Actions workflows using OIDC federated identity, including build, scan, sign, SBOM, and deployment stages.

· Implement Azure Defender and AWS Security Hub / Inspector; integrate OPA Gatekeeper or Kyverno for cluster policy enforcement.

· Deploy Azure Monitor, Managed Prometheus/Grafana, and AWS CloudWatch / OpenTelemetry pipelines with shared dashboards.

· Automate right-sizing, spot-pool scaling, and retention policies; create FinOps dashboards and budget alerts.

· Map IaC and CI/CD controls to HIPAA / NIST 800-171 / FedRAMP evidence.

· Write runbooks, disaster-recovery procedures, and reusable templates for developers.


Required Qualifications

· 5+ years in DevOps / SRE roles operating Kubernetes in production.

· Hands-on experience with AKS and EKS, Terraform, Helm, and Argo CD.

· Expertise in GitHub Actions (build/test/scan/deploy) and cloud IAM/OIDC.

· Strong understanding of containerization, networking, autoscaling, and observability.

· Proficiency in scripting (Python, Bash, PowerShell).

· Knowledge of HIPAA, NIST 800-171, or FedRAMP security standards.

US Citizen or Green Card required


Preferred Qualifications

· Experience with both Azure and AWS network/security stacks.

· Familiarity with OPA Gatekeeper, Kyverno, and admission-control policies.

· Working knowledge of FinOps, cost analysis, and infrastructure efficiency.

· Prior work supporting public-health / government cloud programs.


Success Indicators

· Within 90 days: baseline AKS/EKS clusters operational via Terraform + Argo CD.

· Developer onboarding time

· 25–40% reduction in runtime and tooling costs through native integrations and automation.

· Security posture visible and auditable across both clouds.


Core Stack OverviewLayerTools / Services (Azure + AWS)NotesCloud PlatformAzure (AKS, ACR, Key Vault) / AWS (EKS, ECR, KMS, Secrets Manager)Private clusters, managed identitiesIaC / TemplatesTerraform + HelmShared modules, environment overlaysGitOps / CDArgo CD (App-of-Apps)Cross-cloud sync, policy gatesCI / BuildGitHub Actions + OIDCSBOM → scan → sign → deploySecurityAzure Defender, Security Hub, OPA/KyvernoNative first, compliance mappedObservabilityAzure Monitor + Prometheus/Grafana / CloudWatch + OpenTelemetryUnified dashboardsDR / BackupVelero → Azure Blob / S3Cross-region restoreCost / FinOpsNative budgets + tagging / cost explorerRuntime + storage optimizationAutomationPython/Bash scripts + GitHub Actions cron jobsDaily policy/health checks


Similar Jobs

Explore other opportunities that match your interests

DevOps Engineer

Devops
7h ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Mid-Senior level

joblet-ai

Egypt
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Mid-Senior level

EY

Poland
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Mid-Senior level

Bright Vision Technologies

United State

Subscribe our newsletter

New Things Will Always Update Regularly