Senior DevOps/Compliance Engineer (FedRAMP Continuous Compliance) at Uberether | Torre

Senior DevOps/Compliance Engineer (FedRAMP Continuous Compliance)

Emma highlights
This highlight was written by Emma’s AI. Ask Emma to edit it.
Full-time

Legal agreement: Employment

Provide your expected compensation while applying
location_on
Remote (for United States residents)
Shared by
Emma of Torre.ai
7 days ago

Responsibilities


The TeamUberEther is a leader in the hyper-secure infrastructure space for Identity and Access Management (IAM), #ZeroTrust, and compliance acceleration. Our platform and expert services team enable government and commercial customers to have ultimate control over access to critical information. We are employee-first, with outstanding benefits and a track record of upskilling and fostering growth. We're looking for employees who get excited about pioneering novel solutions to new, complex challenges.This role sits within UberEther's Compliance Business Unit, supporting a FedRAMP 20x advisory project built on Google Cloud Platform (GCP). As Senior DevOps Engineer, you will build and operate the CI/CD pipelines, automation, and monitoring that put FedRAMP 20x Key Security Indicator (KSI) requirements into practice, and author the Standard Operating Procedures (SOPs) that keep Ping's platform in continuous compliance long after go-live.ResponsibilitiesDevOps Strategy & Continuous Compliance LeadershipServe as the principal DevOps authority for implementing FedRAMP 20x KSI requirements into the CI/CD and operations modelDefine and maintain the automation roadmap for operationalizing all the KSIs across the FedRAMP KSI families within the Advantage DevOps toolchainLead design sessions with engineering to determine how each KSI is enforced, tested, and evidenced in the deployment pipelineDrive technical decision-making on pipeline gating, automated policy checks, and continuous monitoring instrumentationPartner with the Senior Architect and Compliance BU leadership to translate KSI mapping decisions into working DevOps proceduresEstablish DevOps standards and design patterns for KSI enforcement that can be reused across future GCP engagementsDevOps Implementation & AutomationOwn the end-to-end implementation of CI/CD pipelines and automation that enforce FedRAMP 20x KSI requirements across Advantage deployments on Google Cloud PlatformBuild and maintain Infrastructure as Code (Terraform, Deployment Manager) that encodes KSI controls directly into GCP deploymentsImplement automation that continuously collects and packages compliance evidence for each of the KSIsStand up container security scanning, network segmentation enforcement, and secrets management within the CI/CD pipelineBuild and maintain GitLab CI/CD pipelines, Terraform modules, and secure deployment tooling for the environmentChampion DevSecOps practices, ensuring KSI-aligned security gates are built into every pipeline stage from day oneSOP Development & Continuous ComplianceAuthor and maintain Standard Operating Procedures (SOPs) covering deployment, monitoring, incident response, and KSI verification for the platformLead working sessions with engineering to document repeatable, auditable procedures for maintaining KSI compliance post-authorizationProduce SOP documentation suitable for assessor review, mapping each procedure back to its corresponding KSISupport 3PAO assessments and FedRAMP 20x reviews by walking through operational procedures and evidence pipelinesTranslate compliance requirements into operational runbooks that align with Advantage delivery standardsDrive continuous improvement of SOPs based on assessor feedback, CR26 verification results, and evolving FedRAMP 20x guidanceMonitoring, Evidence & Compliance IntegrationWork closely with the Compliance Architect and SoC functions to ensure monitoring dashboards and alerting satisfy KSI evidence requirementsBuild automated KSI verification jobs that continuously confirm each of the KSI families remains in a compliant stateMaintain remediation runbooks and system hardening procedures specific to the GCP-hosted environmentSupport 3PAO assessments and audits by producing and explaining automated evidence packages tied to each KSIImplement Policy as Code and machine readable/OSCAL-based evidence generation across the CI/CD pipelineEnsure proper integration between GCP-native security tooling, pipeline automation, and UberEther's compliance evidence modelCross-Team Collaboration & MentorshipFoster technical collaboration between UberEther's Compliance BU, Platform Engineering, and customer engineering teamMentor engineers on DevSecOps practices, GCP automation, and FedRAMP 20x continuous monitoring requirementsLead retrospectives focused on improving pipeline reliability and KSI enforcement for future GCP engagementsParticipate in Level 10 (L10) meetings, providing DevOps insight on progress and cross-team dependenciesDevelop training content and SOP walkthroughs to help engineers operate within FedRAMP 20x continuous compliance requirementsServe as a technical ambassador for UberEther's DevOps and continuous compliance capabilities with Ping and future GCP customersPrimary QualificationsEducation & ExperienceBachelor's degree in Computer Science, Engineering, or related technical field; equivalent experience considered8+ years of experience in DevOps, site reliability engineering, or platform automation roles3+ years of experience building CI/CD pipelines and automation on Google Cloud Platform (GCP)Proven track record of implementing security or compliance controls directly into deployment pipelinesExperience supporting FedRAMP, DoD, or other federal compliance frameworks in an operational capacityTechnical ExpertiseExpert-level knowledge of Google Cloud Platform (GCP) services, IAM, networking, and security tooling, with relevant certifications (Professional Cloud DevOps Engineer preferred)Strong understanding of FedRAMP 20x Key Security Indicators (KSIs) and how they translate into pipeline and operational controlsDeep expertise in Infrastructure as Code tools (Terraform, Deployment Manager) and GitOps workflowsStrong experience with containerization and orchestration (Docker, Kubernetes/GKE) in secure, compliance-focused environmentsHands-on experience with CI/CD platforms such as GitLab CI/CD, including pipeline security gating and policy enforcementExperience with compliance automation and evidence-generation tooling, including OSCAL and Policy as Code frameworksCompliance & Security KnowledgeSolid understanding of FedRAMP 20x requirements, KSI families, and continuous compliance obligationsWorking knowledge of NIST 800-53 security controls and how they are operationalized in a CI/CD environmentExperience supporting Assessment & Authorization (A&A) activities from an operations or DevOps perspectiveExperience with FISMA, FIPS 140-2, and related federal security requirementsProven ability to translate compliance requirements into working automation, SOPs, and evidence pipelinesLeadership & CommunicationStrong communication skills with ability to document clear, assessor-ready SOPs and explain automation to technical and non-technical audiencesProven ability to work cross-functionally with architects, engineers, and compliance staff without direct authorityStrong customer-facing skills with experience supporting federal customers and compliance assessors during technical reviewsDemonstrated ability to manage multiple automation and documentation workstreams simultaneouslyTrack record of driving pipeline and process improvements in fast-paced, dynamic environmentsDifferentiatorsProfessional certifications: Google Professional Cloud DevOps Engineer, CKA/CKAD, AWS/GCP security certifications, or CISSPPrior experience supporting a FedRAMP 20x pilot engagementBackground in writing SOPs or operational documentation for federally authorized systemsExperience building automated OSCAL or KSI evidence pipelinesExperience with compliance automation frameworks such as OSCAL, InSpec, or similar Policy as Code toolsHands-on experience operating IAM platforms such as Ping Identity, SailPoint, CyberArk, or Radiant LogicTrack record of building internal tooling or automation that reduced manual compliance effortLocationThis role is offered as a hybrid or remote position based out of our Sterling, VA office. Please note: We are only able to consider candidates currently residing in DC, FL, IL, MD, MI, NC, NJ, OH, OR, PA, TX, VA, or WA at this time.BenefitsWe understand the value of such people, reward them accordingly, and provide best-in-class benefits to support them and their family's well-being. Full-time employees are eligible to receive top-notch Medical, Dental, Vision, 401K savings plan, Life Insurance, and Short and Long-term Disability benefits as well as generous paid flex-time, education and technology reimbursement.This includes:100% employer covered health care premiums for employee AND dependents100% match up to 6% 401kEducation and professional development budget25 PTO days per year, which increases with tenureAnnual technology budgetCore ValuesGrow With Purpose - Continuously develop your skills and knowledge while helping others growConfident, Not Cocky - Bring expertise with humility and openness to learningThe IT Factor - Demonstrate passion, initiative, and the ability to make things happenTeam Player - Collaborate effectively and put team success ahead of individual recognitionWhole Authentic Self - Bring your complete, genuine self to work every day