Sr. Staff Systems Engineer (Fedramp)

Palo Alto Networks•Office - USA - CA - Headquarters, CA
•$153,700 - $248,600•Onsite

About The Position

As a Sr. Staff Systems Engineer (FedRAMP), you will be a senior technical leader in our Engineering & Infrastructure organization and the operational backbone of our automated cloud platforms across strictly governed public sector boundaries. You will have technical ownership over our automated infrastructure, deployment pipelines, and container platforms—challenged to design, harden, and scale systems across our FedRAMP environments. This role provides a unique opportunity to work cross-functionally with Information Security, R&D, and FedRAMP Production Operations teams, placing you at the critical intersection of advanced DevOps systems engineering, cloud automation, and defense-grade compliance strategy.

Requirements

  • 8+ years of experience in DevOps, Site Reliability Engineering (SRE), or Systems Engineering supporting complex, highly regulated cloud environments.
  • Deep hands-on experience provisioning, securing, and maintaining infrastructure on GCP, with practical working knowledge of GCP Assured Workloads, Cloud IAM, and VPC Service Controls.
  • Proven expertise in architecting and operating Google Kubernetes Engine (GKE) or Kubernetes clusters in mission-critical production environments.
  • Advanced proficiency in writing and maintaining modular, testable infrastructure automation using Terraform and configuration management tools (e.g., Ansible).
  • Strong background configuring, securing, and scaling enterprise CI/CD pipelines with integrated security testing.
  • Demonstrated experience implementing and enforcing security controls aligned to FedRAMP Moderate/High (NIST SP 800-53) and/or DoD Cloud Computing SRG (IL4/IL5).
  • Fluency in Python and Bash for operational scripting, systems integration, and tool development.
  • Solid experience working within formal IT Change Management frameworks and utilizing enterprise ticketing systems.
  • U.S. Citizenship with the ability to pass background checks and security investigations required for DoD IL5 and federal boundary access.

Nice To Haves

  • Google Cloud Certified Professional Cloud DevOps Engineer, Google Cloud Certified Professional Cloud Security Engineer, or Certified Kubernetes Administrator (CKA).
  • Familiarity with BigQuery for telemetry log aggregation, querying, and audit reporting.
  • Practical experience with service mesh technologies (e.g., Anthos Service Mesh)
  • Experience with systems programming languages such as Golang and Rust.

Responsibilities

  • Architect, deploy, and maintain modular Infrastructure as Code (IaC) using Terraform and Ansible across Google Cloud Platform (GCP) and GCP Assured Workloads, enforcing consistent baseline configurations across all FedRAMP boundaries.
  • Build, manage, and harden automated CI/CD pipelines to support zero-trust software delivery, integrating static analysis, automated container image scanning, vulnerability gates, and automated artifact provenance signing.
  • Manage, optimize, and scale production Google Kubernetes Engine (GKE) clusters, enforcing strict network isolation, zero-trust pod security standards (PSS/PSA), mutual TLS, and role-based access controls within defense enclaves.
  • Act as a critical technical bridge to Information Security and FedRAMP compliance teams by automating technical controls for NIST SP 800-53 and DoD CC SRG IL5, generating programmatic Continuous Monitoring (ConMon) evidence, and driving rapid POA&M remediation.
  • Design and maintain unified monitoring, centralized audit logging, and proactive alerting frameworks across all boundary enclaves utilizing Google Cloud Operations Suite (Cloud Logging, Cloud Monitoring) and BigQuery to maintain audit readiness and operational health.
  • Implement and uphold zero-trust identity architectures within FedRAMP boundaries, leveraging GCP Cloud IAM, Identity-Aware Proxy (IAP), VPC Service Controls, and hardware-backed multi-factor authentication (CAC/PIV tokens).
  • Apply formal change management procedures to deployment workflows, execute blue/green and canary deployment patterns to minimize operational risk, and lead technical incident response to rapidly diagnose and resolve production service disruptions.
  • Provide self-service automation tooling and compliant enclave access for internal support and development teams, mentoring junior engineers in cloud security, GitOps practices, and systems automation.
  • Participate in an on-call rotation to support critical FedRAMP cloud infrastructure, responding to high-priority operational incidents, system alerts, and security escalations to maintain SLA availability across regulated environments.

Benefits

  • Restricted stock units
  • Bonus
  • Employee benefits may be found here.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service