eSimplicity is a modern digital services company partnering with government agencies to enhance the lives of Americans. They are seeking an experienced Senior DevOps Engineer to support the Centers for Medicare and Medicaid Services, focusing on integrating security best practices and automation into CI/CD pipelines and cloud infrastructure. The role involves working in a large-scale AWS environment to ensure the security and compliance of critical healthcare systems.
Responsibilities:
- Design, build, and maintain secure CI/CD pipelines using GitHub Actions to deliver applications and infrastructure
- Embed security controls, tools (SAST, DAST, SCA), and processes throughout the software development lifecycle
- Manage and secure cloud infrastructure using Infrastructure as Code (IaC) with Terraform and Terragrunt
- Implement and manage security for containerized applications using Docker
- Collaborate with development teams (Java, Python, Django) to identify and remediate security vulnerabilities in code and dependencies
- Automate security monitoring, logging, and incident response procedures within the AWS cloud environment
- Ensure systems and applications meet federal compliance standards (e.g., FISMA, NIST) and CMS-specific security requirements
- Support the security of data platforms and services, including Databricks and Redshift
- Work with cross-functional teams to foster a culture of security awareness and best practices
Requirements:
- All candidates must pass public trust clearance through the U.S. Federal Government. This requires candidates to either be U.S. citizens or pass clearance through the Foreign National Government System which will require that candidates have lived within the United States for at least 3 out of the previous 5 years, have a valid and non-expired passport from their country of birth and appropriate VISA/work permit documentation
- 8+ years of previous DevOps Engineer experience
- Bachelor's degree in Computer Science, Engineering, or a related technical field; OR
- In lieu of a degree, 10 additional years of relevant professional experience and 8 years of specialized experience may be substituted
- Proven experience in a DevSecOps, DevOps, or Security Engineering role
- Strong hands-on experience with AWS services and cloud security principles
- Proficiency with Infrastructure as Code (IaC) tools, specifically Terraform and Terragrunt
- Demonstrated experience building and managing CI/CD pipelines, preferably with GitHub Actions
- Solid understanding of containerization technologies, including Docker security
- Proficiency in at least one scripting language, such as Python or Bash
- Must be a U.S. Citizen or Green Card holder and able to obtain a Public Trust clearance
- Prior experience supporting CMS or other federal government agencies
- Familiarity with federal compliance frameworks like FISMA and NIST
- Experience with build tools such as Maven
- Knowledge of data platforms and warehousing solutions like Databricks and Redshift
- Experience securing web applications built with frameworks like Django
- Familiarity with tools in our stack, including Chompy
- Relevant industry certifications (e.g., AWS Certified Security - Specialty, CISSP, GSEC)
- Experience Administering/Sizing Clusters, such as Redshift/DataBricks/Hadoop
- Experience configuring and maintaining DevSecOps tools, infrastructure automation, and security scanning solutions (e.g., Nessus, BurpSuite, OWASP, etc.)
- Expertise in security best practices with an emphasis on AWS: IAM policies/Roles, security groups and network security