Benefits:
401(k) matching
Bonus based on performance
Competitive salary
Dental insurance
Health insurance
Paid time off
Parental leave
Training & development
Vision insurance
POSITION OVERVIEW
The Senior Platform Engineer stands up, automates, and sustains the infrastructure the Customer's enterprise API gateway runs on. The role covers container platform engineering, infrastructure-as-code, deployment automation, and the observability and high-availability work that keeps the gateway serving production traffic through upgrades, patch cycles, and failures. It is the platform counterpart to the security and application seats on the same team. This position requires an active Moderate Background Investigation (MBI) suitability determination at start.
RESPONSIBILITIES
Deploy and operate the gateway control and data planes on Kubernetes or Red Hat OpenShift — namespaces, RBAC, quotas, ingress and routes, rolling updates
Automate installation, configuration, upgrade, and patching with Helm, Terraform, and Ansible, delivered as reusable modules rather than one-off scripts
Build and maintain CI/CD pipelines in Jenkins or GitHub Actions with artifact management, image scanning, and approval gates under Government change control
Manage declarative gateway configuration as code and promote it across environment tiers with tested rollback
Architect multi-AZ high availability and disaster recovery for the gateway tier and its datastores
Provision and maintain supporting cloud infrastructure — VPC design, subnets and routing, security groups, managed databases, backups, encryption
Automate certificate lifecycle, mutual TLS, and secrets handling for platform components
Build observability across metrics, logs, and traces with dashboards and alerting tied to service objectives
Establish performance and capacity baselines, load test the gateway tier, and tune for throughput and latency
Maintain runbooks, SOPs, and design artifacts sufficient for Government and follow-on staff to sustain the platform
REQUIRED QUALIFICATIONS
Active MBI suitability determination, current and transferable as of your start date
U.S. citizenship, as required for Customer contractor personnel
Eight years of hands-on platform, DevOps, or cloud infrastructure engineering in production, including three years supporting a Federal system subject to FISMA
Production operation of Kubernetes or Red Hat OpenShift, including cluster resources, ingress controllers, operators, and Helm
Infrastructure-as-code at scale with Terraform and Ansible, including reusable modules and version-controlled state
Ownership of enterprise CI/CD pipelines in Jenkins, GitHub Actions, or GitLab, with artifact repositories and security scanning integrated
AWS-native architecture across VPC, EC2 or EKS, IAM, S3, RDS, Lambda, and CloudWatch, or equivalent depth in another major cloud
Demonstrated design and operation of multi-AZ, high-availability services meeting a stated availability commitment
Observability engineering with tools such as Prometheus, Grafana, Splunk, AppDynamics, OpenTelemetry, or the ELK stack
Linux administration on RHEL, shell or Python scripting, and troubleshooting at the OS and network layer
Certificate and secrets handling for platform services — TLS and mutual TLS, key rotation, and a secrets management platform
Experience promoting configuration through Government-controlled environments under formal change control
Technical documentation — design artifacts, runbooks, and SDLC deliverables that hold up under Government review
Agile or Scrum delivery alongside Government product owners and multiple contractor teams
Bachelor's degree in Computer Science, Engineering, or Information Systems, or equivalent hands-on experience
PREFERRED QUALIFICATIONS
An active vendor certification on the program's API gateway platform, or willingness to earn it within 90 days of start with training provided
An active platform certification such as CKA, Red Hat OpenShift, AWS Solutions Architect, Terraform Associate, or ITIL v4
Prior support to a Federal financial or tax administration program
GitOps delivery with Argo CD, and service mesh exposure such as Istio
Messaging and integration middleware such as Kafka, IBM MQ, ActiveMQ, or webMethods
Zero Trust implementation — mTLS, RBAC/ABAC, MFA, PIV, and LDAP/AD or Kerberos integration
Supporting ATO and continuous monitoring from the platform side — scan remediation and evidence collection
Flexible work from home options available.