Military & Veteran Health (Template)
The DevSecOps Cloud Engineer will build, secure, automate, and operate the cloud environments supporting Tria Federal's Payment Integrity Validation and Oversight Tool (PIVOT), a proposed software-as-a-service solution for the U.S. Department of Veterans Affairs (VA). PIVOT is designed to help VA identify improper payments and fraud, waste, and abuse across Community Care claims and invoices. The engineer will support the Databricks FedRAMP Moderate software-as-a-service foundation and the surrounding infrastructure, deployment pipelines, security tooling, observability, and operational controls required for a reliable VA implementation.
This is a hands-on platform engineering role focused on infrastructure as code, secure continuous integration and continuous delivery, environment configuration, cloud security, logging and monitoring, vulnerability remediation, release automation, and recovery. The engineer will work with the Cloud and Solutions Architect, cybersecurity lead, software developers, data engineers, and quality engineers. Data pipeline design, payment-integrity rules, and machine-learning model development remain primarily with the data and application engineering teams.
The ideal candidate has operated cloud platforms in a federal or regulated environment and can convert architecture and security requirements into repeatable configurations, automated controls, and auditable evidence. The candidate should be comfortable troubleshooting across infrastructure, platform services, application delivery, identity, networking, and security boundaries.
This position is contingent upon contract award and successful completion of customer onboarding requirements.
Requirements:
Five or more years of experience in cloud engineering, DevOps, DevSecOps, site reliability engineering, platform engineering, or a related discipline.
Hands-on experience provisioning and operating production cloud infrastructure using infrastructure-as-code tools such as Terraform or an equivalent platform.
Experience administering Linux-based environments and troubleshooting cloud networking, identity and access management, encryption, secrets, storage, and compute services.
Experience building and maintaining continuous integration and continuous delivery pipelines with automated build, test, deployment, rollback, and approval controls.
Experience integrating security into delivery pipelines through static application security testing, software composition analysis, secrets scanning, infrastructure-as-code scanning, container or artifact scanning, and vulnerability management.
Experience implementing centralized logging, metrics, dashboards, alerts, and operational telemetry for production services.
Working knowledge of the NIST Risk Management Framework, NIST SP 800-53 controls, FISMA, FedRAMP, vulnerability management, configuration management, and continuous monitoring.
Experience supporting incident response, root-cause analysis, capacity planning, backup and recovery, and release or change-management activities.
Experience delivering software and infrastructure changes within an Agile environment using Git-based version control and peer review.
Bachelor's degree in computer science, information systems, engineering, cybersecurity, or a related field, or an equivalent combination of education and professional experience.
Ability to obtain and maintain a U.S. Department of Veterans Affairs Public Trust suitability determination.
Strong analytical, documentation, and communication skills, with the ability to work effectively across engineering, security, operations, and customer teams.
Qualifications:
Hands-on Databricks platform or workspace administration experience, including identity, networking, compute policies, serverless or autoscaling services, secrets, audit logs, and Unity Catalog permissions.
Experience operating cloud infrastructure on Amazon Web Services or Microsoft Azure in a federal environment.
Experience supporting FedRAMP or agency authorization activities, including control inheritance, System Security Plan evidence, Security Assessment Plan and Report support, Plans of Action and Milestones, continuous-monitoring scans, and independent assessor requests.
Familiarity with VA security requirements, including VA Handbook 6500 and 6517, Federal Identity Credential and Access Management, PIV authentication, Trusted Internet Connection 3.0, IPv6, and Zero Trust principles.
Experience forwarding cloud and Databricks audit data to a security information and event management platform and supporting security-event investigations.
Experience conducting load, failover, recovery, fault-injection, or resilience testing in controlled non-production environments.
Familiarity with Delta Lake, Parquet, Spark, streaming workloads, or other lakehouse concepts sufficient to support platform reliability and performance troubleshooting.
Relevant certifications from a cloud provider, Databricks, HashiCorp, or a security organization, such as AWS Solutions Architect, Azure Administrator, Databricks Platform Administrator, Terraform Associate, Security+, or CISSP.
Experience delivering within the Scaled Agile Framework.
Responsibilities:
Cloud Platform and Environment Engineering
Provision and maintain Development, Test, Pre-Production, and Production environments using approved infrastructure-as-code and configuration-management practices.
Configure cloud and Databricks platform services according to approved architecture, security, availability, capacity, and cost-management requirements.
Implement identity, network, storage, encryption, secrets-management, and access-control configurations using least-privilege principles.
Maintain environment consistency, configuration baselines, deployment inventories, and traceability between approved changes and deployed resources.
Support Databricks workspace administration, compute policies, resource quotas, platform integrations, audit logging, and governed access in coordination with data engineering and cybersecurity personnel.
DevSecOps and Release Automation
Build and maintain delivery pipelines that automate infrastructure validation, application builds, testing, security checks, deployment approvals, release promotion, and rollback.
Integrate code, dependency, secrets, infrastructure, container or artifact, and vulnerability scanning into the delivery process and retain auditable results.
Use version-controlled templates and reusable modules to produce repeatable deployments across environments.
Partner with development and quality teams to troubleshoot pipeline failures, reduce manual release steps, and improve deployment reliability.
Security Authorization and Continuous Monitoring
Implement and document PIVOT-specific technical controls while identifying controls inherited from the Databricks FedRAMP Moderate authorization boundary.
Produce configuration records, scan results, logs, diagrams, and other technical evidence requested by the cybersecurity lead, VA security stakeholders, or independent assessors.
Support System Security Plan updates, security assessment activities, Plans of Action and Milestones, control validation, and remediation tracking.
Automate and monitor vulnerability, configuration-compliance, and security scans; prioritize findings and coordinate remediation within required timelines.
Maintain evidence that infrastructure and platform changes follow approved configuration, access-control, and change-management procedures.
Observability Reliability and Recovery
Implement logging, metrics, dashboards, alerts, and telemetry for platform availability, latency, capacity, data-ingest health, deployment status, and security events.
Establish alert thresholds, escalation paths, runbooks, and operational dashboards that support timely incident detection and response.
Support performance and surge testing by monitoring platform behavior, diagnosing bottlenecks, and validating autoscaling and capacity controls.
Implement and test backup, restoration, failover, rollback, and disaster-recovery procedures against VA-approved recovery objectives.
Participate in incident response, root-cause analysis, corrective-action tracking, and lessons-learned reviews.
Collaboration and Delivery Support
Deliver infrastructure and automation changes through two-week Agile sprints and support working demonstrations and release-readiness reviews.
Coordinate with architects, software and data engineers, cybersecurity personnel, quality engineers, and VA stakeholders to resolve cross-system dependencies.
Document environments, pipelines, configurations, access patterns, operational procedures, and recovery processes.