ForgeApply · Job listing
SecDevOps Engineer (Jr.)
Knox-systems
Apply in about a minute — without sacrificing quality.
ForgeApply autofills this application and tailors your resume to this exact posting. You review everything before it's sent. Free trial, no card required.
About this role
About Knox
Knox runs the largest Federal and DoW managed cloud, building and operating secure cloud and AI environments that support the U.S. government’s most critical missions — from national security and public safety to essential public services. Our customers rely on Knox to deploy production systems that meet the highest standards for security, reliability, and compliance.
Work at Knox is high-impact and purpose-driven. The problems we solve are high stakes, the expectations are high, and the results are visible. Speed, rigor, and trust matter here - because the environments we secure cannot fail. Your contributions are visible, your expertise is relied upon, and the impact of your work is immediate and measurable. We operate at federal scale, securing some of the most sensitive government environments in the country - because the systems we build must perform without fail.
The Junior SecDevOps Engineer supports the maintenance, monitoring, and security auditing of Knox’s cloud infrastructure and CI/CD pipelines across AWS, Azure, and GCP. Operating on-site in Washington, DC, within our FedRAMP-authorized boundaries, this role focuses on day-to-day identity administration, configuration monitoring, and vulnerability triage—helping ensure secure, repeatable operations across federal cloud environments under the direct mentorship of senior engineers.
The ideal candidate has strong technical fundamentals (Linux, basic networking, Git, and scripting), a passionate curiosity for cloud security and automation, and a strong security-first mindset. This is a growth-oriented role designed to build elite technical expertise in Zero Trust architectures, automated compliance engineering, and multi-cloud environments.
Role Focus & Technical Matrix:
-Zero Trust & Identity: Monitoring Zscaler connectors, HashiCorp & Vault basic secret updates.
Infrastructure as Code: Running pre-written Terraform plans, Git PR workflows, fundamental CloudFormation playbooks.
Security & Compliance: FedRAMP baselines, sorting Wiz/Qualys vulnerability alerts, basic CrowdStrike endpoint checks
Observability & Ops: Grafana dashboard upkeep, CloudWatch metrics, ServiceNow ticketing, shadow on-call protocols
Key Responsibilities:
Zero Trust & Identity Operations
● Assist in monitoring Zero Trust Network Access tools (Zscaler ZPA / PRA), verifying
application connectors and remote access pathways remain operational.
● Support secrets management workflows within HashiCorp Vault, including basic
credential generation, entry updates, and confirming automated rotations execute without
error.
● Review basic IAM permissions and cloud role policies to ensure alignment with least-
privilege models under senior engineering review.
Infrastructure & Automation Support
● Run, test, and troubleshoot pre-defined Terraform modules across development and
staging environments in AWS, Azure, or GCP.
● Identify and log configuration drift or environment resource issues, assisting senior
engineers with standard infrastructure patching and remediation tasks.
● Review cloud security groups, public endpoint configurations, and basic network routes to cross-check them against compliance baselines.
CI/CD & Pipeline Maintenance
● Monitor and triage failing CI/CD pipeline runs within GitHub Actions, GitLab CI, or Azure
DevOps, escalating systemic errors to the team.
● Review automated security scan readouts (SAST, SCA, and container scans) embedded
in the pipeline.
● Assist in updating, building, and running security base-image layers for containers
(Docker) destined for managed Kubernetes clusters (EKS, AKS, GKE).
Compliance Monitoring & Change Administration
● Assist compliance with the programmatic gathering of audit evidence for ongoing
FedRAMP Continuous Monitoring (ConMon) cycles, specifically targeting CM-2, CM-6,
AU-2, and SC-12 controls.
● Assist with Plan of Action and Milestones (POA&M) ticket creation, tracking remediation
deadlines across the platform.
● Draft and submit technical change requests within ServiceNow, ensuring correct structural
documentation for review by the Change Advisory Board (CAB).
Observability & Incident Support
● Maintain and adjust basic Grafana and CloudWatch dashboards, ensuring alert
notifications are mapped accurately to operational notification streams.
● Monitor standard system health indicators, performing low-severity alert triaging to
prevent production fatigue.
● Maintain open telemetry operations for ongoing application monitoring
● Participate in a shadow on-call rotation capacity (PagerDuty) alongside senior engineers
to develop live diagnostic and real-time incident resolution skills.
Qualifications
Required Experience & Core Aptitude
● Experience: 1–2 years of experience in an entry-level technical role (e.g., IT Support,
Junior Systems Administrator, Helpdesk/NOC, Cyber Operations, or relevant cloud
engineering internship/bootcamp).
● Location: Must be able to work fully on-site at our Washington, DC office.
● Linux Fundamentals: Comfortable navigating the Linux command line (Bash), managing
file permissions, viewing system logs, and executing basic terminal commands.
● Networking Core: Solid grasp of foundational networking concepts (DNS, TCP/IP,
HTTP/HTTPS, SSH, Subnets, and basic firewall/security group rules).
● Cloud & Version Control Exposure: Foundational exposure to public cloud concepts
(AWS preferred) and basic Git workflows (cloning, branching, commits, Pull Requests).
● Basic Scripting: Ability to read and write fundamental scripts in Python or Bash to
automate repetitive tasks, parse logs, or interact with simple APIs.
● Security Mindset: Strong conceptual understanding of core security principles (Least
Privilege, Multi-Factor Authentication, IAM basics, Encryption).
● Soft Skills & Growth Mindset: High technical curiosity, excellent written documentation
habits, and a strong eagerness to learn directly from seni
Salary insight
The midpoint of this range ($100k) is about 38% below the median disclosed salary for Washington DC roles listed on ForgeApply ($162k across 500 jobs).
See full DevOps / SRE salary data for Washington DC →
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Ready to apply to Knox-systems?
Apply in about a minuteSimilar jobs
- Jr. DevOps Engineer — Accenturefederalservices · Annapolis Junction, MD
- SecDevOps Engineer — Knox-systems · Washington D.C.
- SecDevOps Engineer — Accenturefederalservices · Chantilly, VA
- Junior DevOps Engineer — Accenturefederalservices · Hanover, MD
- Junior DevOps Engineer — Sprocketsecurity · Madison, WI
- Sr. DevOps Engineer — Opengov · US | Massachusetts | Boston
- DevSecOps Engineer — Accenturefederalservices · Fort Belvoir, VA
- DevSecOps Engineer — Accenturefederalservices · Reston, VA
More like this: DevOps & SRE Jobs · DevOps & SRE Jobs in Washington DC · More jobs at Knox-systems · Browse all jobs