IT Infrastructure, Security & DevOps Engineer

TrustPoint•Dulles, VA
•$139,000 - $172,000

About The Position

Join TrustPoint and Build the World’s First Commercial GPS System in Space. GPS is a ubiquitous global utility in modern society; knowing one’s location is critical for government, commercial, and personal applications. Still, today’s solutions for determining location are inaccurate, slow, unencrypted, and susceptible to jamming and spoofing. TrustPoint is building the world’s first commercial, authenticated GPS system in space to deliver secure, precise positioning, navigation, and timing to customers worldwide. As TrustPoint’s IT Infrastructure, Security & DevOps Engineer, you will design, deploy, and manage the IT infrastructure, cloud environments, networking, and developer platforms that power our engineering organization. The role bridges traditional IT operations and modern DevOps practice, ensuring our engineers have a secure, scalable, and automated environment to develop, test, and deploy the software behind our satellites, ground systems, and products. You will own everything from office networking and endpoint management to AWS infrastructure, CI/CD pipelines, infrastructure automation, security, and developer enablement. Your work will directly improve developer productivity, system reliability, and the security of environments that span our offices, cloud, and globally distributed field systems. You will also lead TrustPoint's IT security and compliance program. As our government business grows, our infrastructure has to meet the standards our customers operate under: CMMC for controlled unclassified information, FedRAMP-aligned practices for the services we deliver, and AWS GovCloud for regulated workloads. You will own that effort end to end, and build the IT foundation for a future facility clearance and the accredited environments that come with it.

Requirements

  • Bachelor’s degree in Computer Science, Information Technology, or equivalent experience.
  • 5+ years of experience in IT infrastructure, systems administration, or DevOps.
  • Strong Linux system administration skills.
  • Experience managing AWS environments.
  • Experience with Terraform or other infrastructure as code tools.
  • Experience with Docker and containerized applications.
  • Strong networking knowledge including TCP/IP, DNS, DHCP, VLANs, VPNs, routing, and firewalls.
  • Experience with Git and CI/CD pipelines.
  • Proficiency in Python, Bash, or PowerShell scripting.
  • Hands-on experience implementing security controls in a regulated environment: NIST SP 800-171, 800-53, CMMC, FedRAMP, or ISO 27001.
  • Experience writing and maintaining security documentation and audit evidence.
  • Strong troubleshooting and communication skills.
  • Must be a U.S. Person (U.S. citizen or permanent resident).

Nice To Haves

  • Experience with Kubernetes (EKS, k3s, or similar).
  • Experience with Zero Trust networking approaches such as NetBird, WireGuard, or Tailscale.
  • Familiarity with Prometheus, Grafana, and ELK/OpenSearch.
  • AWS Solutions Architect, SysOps Administrator, or DevOps Engineer certifications.
  • Experience supporting embedded systems, robotics, aerospace, or IoT environments.
  • Experience with software-defined radios, Linux-based embedded devices, or edge computing.
  • Experience with messaging systems such as ZeroMQ, MQTT, or NATS.
  • Familiarity with GitHub Enterprise and Python-based automation frameworks.
  • Experience taking an organization through CMMC Level 2 assessment or FedRAMP authorization.
  • Experience with AWS GovCloud or Microsoft 365 GCC High.
  • Familiarity with NISPOM and DCSA processes, or experience serving as ISSM/ISSO.
  • Familiarity with ITAR/EAR technical data controls in an engineering environment.
  • Active U.S. security clearance, or eligibility to obtain one.
  • Self-starter with a builder mindset and experience thriving in a startup environment.

Responsibilities

  • Design, configure, and maintain office, lab, and remote network infrastructure including routers, switches, firewalls, VLANs, VPNs, and Wi-Fi networks.
  • Administer Windows, Linux, and macOS systems and manage user accounts, identity, permissions, MFA, and endpoint security through Microsoft 365 or Google Workspace.
  • Design and maintain TrustPoint’s AWS infrastructure including VPCs, EC2, IAM, Route 53, S3, RDS, CloudWatch, Systems Manager, and cloud networking.
  • Deploy and manage infrastructure as code using Terraform, with secure, least-privilege IAM roles and policies, while optimizing cloud cost, performance, and security.
  • Build and maintain CI/CD pipelines using GitHub Actions, GitLab CI, or Jenkins, and maintain artifact repositories, package registries, and container registries.
  • Containerize applications using Docker and deploy workloads on ECS, Kubernetes, or similar orchestration platforms.
  • Automate provisioning and operational tasks using Python or Bash.
  • Deploy and maintain secure remote access solutions such as WireGuard, Tailscale, or NetBird for employees and field-deployed systems.
  • Create reproducible development environments and internal tooling that improve engineering onboarding and productivity.
  • Implement monitoring, alerting, and centralized logging using CloudWatch, Grafana, or Prometheus.
  • Perform vulnerability assessments and security hardening, respond to infrastructure incidents, and participate in root cause analysis.
  • Configure backup, disaster recovery, and business continuity solutions; maintain IT documentation and standard operating procedures; and procure and manage IT hardware and software assets.
  • Lead TrustPoint's CMMC readiness and certification: scope the CUI enclave, implement NIST SP 800-171 controls, maintain the SSP and POA&M, manage the SPRS score, and carry us through assessment.
  • Design and operate segmented environments for CUI and export-controlled data, including AWS GovCloud and Microsoft 365 GCC High or equivalent.
  • Own DFARS 252.204-7012 compliance and related contract flowdowns, and implement ITAR/EAR safeguards in IT systems.
  • Support FedRAMP-aligned control implementation and evidence for TrustPoint services delivered to government customers.
  • Build the IT foundation for a future facility clearance (FCL), including NISPOM requirements and accredited classified systems under RMF; grow into ISSM for those systems.
  • Run security operations: vulnerability management, patch cadence, EDR, log retention, access reviews, incident response, and security awareness training.

Benefits

  • salary
  • equity (stock options)
  • standard benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service