- Location
- Arlington, VA
- Workplace
- Remote
- Type
- Full-time
- Department
- Engineering
- Seniority
- Senior
- Visa
- Not sponsored
- Clearance
- Required
- Closing date
- Today
- Source
- ApplyToJob
Description
BAM is seeking a hands-on Senior Platform Engineer to own and administer a critical part of our infrastructure and keep it continuously compliant with federal requirements.
Responsibilities
- Administer and harden our GitHub Enterprise Server baseline: org/repo policies, SSO/SCIM, audit logging, branch protections, secret scanning, and access controls.
- Own the AWS GovCloud (US) infrastructure supporting our regulated services and integrations with Microsoft 365 GCC High, with deep ownership of Amazon EKS / Kubernetes.
- Maintain and extend our existing Terraform modules and build new ones as the environment evolves.
- Apply security-by-design across identity, networking, encryption, and secrets management.
- Continuously validate and remediate the environment against its applicable federal requirements and IL4+ security baseline, including NIST 800-53, CMMC, FedRAMP-aligned controls, and relevant DISA STIGs, while maintaining supporting evidence and documentation.
- Maintain policy-as-code guardrails to automatically enforce CMMC and other compliance rules across our Terraform-managed infrastructure.
- Monitor, patch, and improve reliability of the platform through strong automation and operational best practices.
- Respond to and remediate audit findings and vulnerability scan results in a timely manner.
To excel in this role, candidates should possess the following:
- 7+ years in Platform/Cloud Infrastructure Engineering, DevOps, or SRE, with hands-on ownership (not just oversight) of production environments.
- Experience administering GitHub Enterprise (or a comparable enterprise SCM platform) at an organizational level.
- Expert-level Kubernetes/EKS and expert-level Terraform.
- Strong AWS experience and solid cloud security fundamentals.
- Direct experience supporting GCC High, GovCloud, or other regulated/government-compliant environments.
- Ability to obtain a security clearance if needed
- Must be US citizen
- Experience with AWS GovCloud (US); Azure Government / Microsoft 365 GCC High a plus.
- Experience implementing policy-as-code (e.g., OPA, Sentinel, Checkov, or similar) to enforce compliance guardrails.
- AWS Professional certs, CKA/CKS, GitHub Advanced Security certification, HashiCorp Terraform Associate.
- Familiarity with NIST, FedRAMP, FISMA, or CMMC.