Cloud DevSecOps Engineer

ECS Tech Inc•Arlington, VA
•$130,000 - $175,000•Remote

About The Position

ECS is seeking a Cloud DevSecOps Engineer to work remotely. We are seeking a highly skilled Senior DevSecOps Engineer with extensive experience in cloud-native infrastructure engineering, Kubernetes container orchestration, and enterprise Identity and Access Management (IAM). Tools necessary for excelling in this role include Kubernetes, Docker, Helm, Keycloak Identity Broker, Okta SSO/OIDC, Terraform/IaC, CI/CD pipelines (GitLab CI, GitHub Actions, or Jenkins), and security scanning tooling (Trivy). This role will serve as the infrastructure and security authority within a lean, agile modernization team rebuilding an enterprise Microsoft Power Apps system into a cloud-native platform. You will play a critical role in provisioning and securing Kubernetes cluster environments, engineering automated build and deployment pipelines, deploying and managing high-availability Keycloak identity broker services federated to enterprise Okta, and safeguarding all infrastructure, database, and storage assets across non-production and production environments.

Requirements

  • Must be a US Citizen with the ability to pass a Public Trust background check
  • Bachelor’s degree in a relevant field
  • 10+ years of relevant work experience
  • 6+ years of systems engineering, DevOps, and cloud infrastructure experience in enterprise Linux and cloud environments.
  • 4+ years of hands-on experience provisioning, operating, and troubleshooting containerized workloads in production Kubernetes clusters.
  • 3+ years of dedicated experience configuring and managing enterprise Identity and Access Management (IAM) systems, specifically Keycloak and Okta (OIDC, OAuth 2.0, SAML 2.0).
  • Strong experience building and maintaining automated CI/CD pipelines (e.g., GitLab CI, GitHub Actions, Jenkins) integrating security scans and container image registries.
  • Proficiency in Infrastructure as Code (IaC) and configuration management using Terraform, Helm charts, and Kubernetes YAML manifests.
  • Solid background in networking, DNS, TLS/SSL termination, reverse proxy routing, and cloud network access policies.
  • Strong scripting skills in Bash, Python, or Go for automated infrastructure management and operational tooling.
  • Proactive problem-solving capabilities with a security-first engineering mindset and clear technical communication skills.

Responsibilities

  • Architect, provision, configure, and maintain production-grade Kubernetes cluster environments hosting containerized front-end, backend, and identity services.
  • Deploy, configure, and administer a highly available Keycloak Identity Broker instance running in Kubernetes, federating authentication to enterprise Okta via SAML 2.0 and OIDC.
  • Configure identity brokering rules, realm roles, client scopes, and token exchange policies within Keycloak to power secure authentication for React and Spring Boot services.
  • Design, build, and maintain end-to-end CI/CD pipelines for automated image builds, vulnerability scanning, automated testing gates, and zero-downtime rolling deployments via Helm.
  • Implement robust platform security controls, including Kubernetes Ingress controllers (NGINX/Traefik), TLS certificate automation (cert-manager), network policies, and container image scanning (Trivy).
  • Automate secrets management and configuration injection across environments using tools such as HashiCorp Vault, AWS Secrets Manager, or Kubernetes External Secrets Operator.
  • Provision, monitor, and maintain supporting backing infrastructure including managed PostgreSQL instances and secure Amazon S3 storage buckets.
  • Establish centralized logging, monitoring, and alerting frameworks (Prometheus, Grafana, Loki or EFK stack) to ensure high system observability and reliability.

Benefits

  • General Description of Benefits [https://ecstech.com/careers/benefits]
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service