SecDevOps Engineer (Jr.)

Knox SystemsWashington, DC
$90,000 - $110,000Onsite

About The Position

The Junior SecDevOps Engineer supports the maintenance, monitoring, and security auditing of Knox’s cloud infrastructure and CI/CD pipelines across AWS, Azure, and GCP. Operating on-site in Washington, DC, within our FedRAMP-authorized boundaries, this role focuses on day-to-day identity administration, configuration monitoring, and vulnerability triage—helping ensure secure, repeatable operations across federal cloud environments under the direct mentorship of senior engineers. The ideal candidate has strong technical fundamentals (Linux, basic networking, Git, and scripting), a passionate curiosity for cloud security and automation, and a strong security-first mindset. This is a growth-oriented role designed to build elite technical expertise in Zero Trust architectures, automated compliance engineering, and multi-cloud environments.

Requirements

  • 1–2 years of experience in an entry-level technical role (e.g., IT Support, Junior Systems Administrator, Helpdesk/NOC, Cyber Operations, or relevant cloud engineering internship/bootcamp).
  • Must be able to work fully on-site at our Washington, DC office.
  • Comfortable navigating the Linux command line (Bash), managing file permissions, viewing system logs, and executing basic terminal commands.
  • Solid grasp of foundational networking concepts (DNS, TCP/IP, HTTP/HTTPS, SSH, Subnets, and basic firewall/security group rules).
  • Foundational exposure to public cloud concepts (AWS preferred) and basic Git workflows (cloning, branching, commits, Pull Requests).
  • Ability to read and write fundamental scripts in Python or Bash to automate repetitive tasks, parse logs, or interact with simple APIs.
  • Strong conceptual understanding of core security principles (Least Privilege, Multi-Factor Authentication, IAM basics, Encryption).
  • High technical curiosity, excellent written documentation habits, and a strong eagerness to learn directly from senior engineers on-site.
  • Due to the nature of our work with federal government clients and compliance with applicable regulations, this position requires U.S. citizenship. Dual citizenship is not permitted for this role. Candidates must be able to provide documentation verifying sole U.S. citizenship status as part of the background check process.

Nice To Haves

  • Exposure to Infrastructure as Code concepts (Terraform or CloudFormation).
  • Familiarity with container basics (Docker) or CI/CD pipelines (GitHub Actions, GitLab CI)
  • Basic experience using ticketing or monitoring tools (Jira, ServiceNow, CloudWatch, Grafana)
  • Conceptual awareness of federal security or compliance frameworks (FedRAMP, NIST 800-53, or SOC 2)
  • CompTIA Security+ or Linux+
  • AWS Certified Cloud Practitioner or Solutions Architect (Associate)
  • HashiCorp Certified: Terraform Associate (or actively pursuing)
  • Microsoft Certified: Azure Fundamentals

Responsibilities

  • Assist in monitoring Zero Trust Network Access tools (Zscaler ZPA / PRA), verifying application connectors and remote access pathways remain operational.
  • Support secrets management workflows within HashiCorp Vault, including basic credential generation, entry updates, and confirming automated rotations execute without error.
  • Review basic IAM permissions and cloud role policies to ensure alignment with least-privilege models under senior engineering review.
  • Run, test, and troubleshoot pre-defined Terraform modules across development and staging environments in AWS, Azure, or GCP.
  • Identify and log configuration drift or environment resource issues, assisting senior engineers with standard infrastructure patching and remediation tasks.
  • Review cloud security groups, public endpoint configurations, and basic network routes to cross-check them against compliance baselines.
  • Monitor and triage failing CI/CD pipeline runs within GitHub Actions, GitLab CI, or Azure DevOps, escalating systemic errors to the team.
  • Review automated security scan readouts (SAST, SCA, and container scans) embedded in the pipeline.
  • Assist in updating, building, and running security base-image layers for containers (Docker) destined for managed Kubernetes clusters (EKS, AKS, GKE).
  • Assist compliance with the programmatic gathering of audit evidence for ongoing FedRAMP Continuous Monitoring (ConMon) cycles, specifically targeting CM-2, CM-6, AU-2, and SC-12 controls.
  • Assist with Plan of Action and Milestones (POA&M) ticket creation, tracking remediation deadlines across the platform.
  • Draft and submit technical change requests within ServiceNow, ensuring correct structural documentation for review by the Change Advisory Board (CAB).
  • Maintain and adjust basic Grafana and CloudWatch dashboards, ensuring alert notifications are mapped accurately to operational notification streams.
  • Monitor standard system health indicators, performing low-severity alert triaging to prevent production fatigue.
  • Maintain open telemetry operations for ongoing application monitoring.
  • Participate in a shadow on-call rotation capacity (PagerDuty) alongside senior engineers to develop live diagnostic and real-time incident resolution skills.

Benefits

  • Medical
  • Dental
  • Vision
  • Life & Disability
  • unlimited PEO
  • employee funded 401k plan
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service