Careers / R-03
DevSecOps Engineer (Kubernetes)
Everything from git push to a running pod is yours. There is no
legacy cluster to inherit. Day one is an empty rack and an architecture
argument.
About this role
You build the entire path a greenfield federal system travels: a Platform One / Big Bang-aligned Kubernetes environment on our own hardware, the pipeline, the hardened images, the gate evidence, and the authorization package that lets it actually go live.
The DevSecOps here is load-bearing, not ceremonial. Milestone payments are gated on promotion, and promotion is gated on scans. A blocked SCA finding is not a Jira ticket, it is a payment event. If you have spent your career being the person who says "we should really fix that" and being overruled — here the schedule is on your side.
Between delivery milestones you build infrastructure for Emma, our agentic architecture platform: long-running autonomous processes, sandboxing for agent-executed code, durable scheduling, secrets that agents can use but not exfiltrate, and observability for systems that make their own decisions about what to do next.
What you will actually do
- Stand up a local Big Bang-aligned Kubernetes environment that is a faithful rehearsal of the target platform, so nothing is discovered at the gate
- Build the pipeline: build, test, SAST, SCA, container scan, SBOM generation, image signing, digest-pinned promotion where the artifact that passes the gate is provably the artifact that runs
- Consume Iron Bank hardened base images, manage the upgrade cadence, and keep findings from accumulating
- Hold the line on dependency surface — a tracked budget, lockfile-only installs, scans run at the desk so findings never surface first at the gate
- Design secrets, identity and configuration: PKI-backed OIDC/SAML, injected secrets, no credentials in images or repositories
- Build observability and an audit trail that satisfies an assessor without leaking sensitive record existence into telemetry
- Produce the authorization artifacts — control mapping, inheritance argument, continuous monitoring — as a byproduct of the pipeline rather than a document written afterward
- Own onboarding logistics onto the government platform, which is a months-long process that starts in week one
What we need
- Kubernetes for real. Not "I deployed to a cluster someone else ran." Networking, RBAC, admission control, storage, operators, debugging it at 11pm
- You have built a CI/CD pipeline from zero, including the security gates, and you can explain what you would do differently now
- Container security in depth — hardened base images, minimal layers, non-root, image signing, SBOM, and the ability to triage a vulnerability report down to what is actually exploitable instead of escalating all four hundred findings
- Infrastructure as code — Terraform, Helm, Kustomize, GitOps. Nothing configured by hand
- Linux fundamentals and comfort at the bare-metal end. The environment runs on our own hardware and you drive it remotely, so troubleshooting a machine you cannot walk over to is part of the job
- You can write the security narrative, not only implement it. Half this job is producing an argument an assessor will accept
- You operate alone well and know when to escalate rather than quietly absorbing a risk
Helps a lot
- Direct Platform One, Big Bang, Party Bus, or Iron Bank experience — the single strongest differentiator, and we will move fast on it
- Prior ATO / cATO / RMF work; DoD IL4 or IL5 environments; eMASS
- STIG compliance; Keycloak; PostgreSQL operations
- Node.js and npm supply-chain security specifically; an offensive security background
Being straight with you about the constraints
- You are the only infrastructure person. That is the appeal and it is the risk. We are not pretending otherwise
- Milestone-gated payment. Your gates are on the critical path to revenue. Real pressure, and also real leverage
- Fully remote, DMV preferred. Occasional in-person is real — credentialing requires in-person appointments, and hands-on hardware work occasionally beats a remote console
- Government onboarding is slow and will test your patience in a way the technical work will not. Part of the job is building an environment good enough that the wait costs us nothing
- Synthetic data only. Fictional locations, fictional people
- U.S. citizenship is required, and you must be able to obtain a government-issued credential for access to a controlled-unclassified environment and pass a favorable federal background investigation. This is not a preference — it follows directly from the credentialing and platform access the work requires. No active clearance is needed to apply.
- This is a 1099 contract engagement, not employment. You invoice hourly, you carry your own taxes and insurance, and there are no benefits. The rate reflects that rather than pretending otherwise. The initial engagement runs roughly six months to an initial capability milestone; continuation beyond it is intended and not yet funded
How to apply
Email careers@digitaladvisors.io with your resume, and tell us about a pipeline you built and one security finding you argued down correctly — or one you escalated that everyone wished you had not, and were right about anyway. If you have Platform One or Iron Bank experience, lead with it.