ForgeApply · Job listing
Site Reliability Engineer / DevSecOps Engineer
Openteams
See all 11 open roles at Openteams →
Tailor your resume for this Openteams job in about a minute.
ForgeApply rewrites your resume for this exact posting, then autofills the application on Openteams's site with it. You review everything before it's sent. Free trial, no card required.
About this role
Who We Are
Every organization runs on intelligence: years of accumulated knowledge, decisions, and context. As AI takes on more of that work, companies face a choice: rent that intelligence from vendors who keep the data, the context, and the results, or own it.
OpenTeams exists to make ownership possible.
Founded by Travis Oliphant, creator of NumPy and SciPy, and built by people with deep roots across the open-source ecosystem, including NumPy, SciPy, PyTorch, and Jupyter, we help enterprises and governments build AI they control, govern, and evolve themselves.
If that sounds like your kind of work, we'd like to meet you.
Site Reliability Engineer / DevSecOps Engineer
Location: Washington, DC; Denver, CO; or Colorado Springs, CO preferred (hybrid). Highly qualified candidates outside these locations may also be considered for unclassified work.
Work Authorization: U.S. citizenship required
Clearance: An active TS/SCI clearance with CI polygraph is strongly preferred. Candidates without an active clearance may be considered for unclassified work but must be eligible to obtain and maintain a U.S. security clearance.
Salary Range: $145,000–$250,000 USD, dependent on experience level and location
About the Role
We're looking for a SRE/DevSecOps Engineer to build and own the secure delivery pipeline for an AI/ML platform deployed into tightly controlled environments. This is a role for someone who treats security as something you build into the delivery path, not something you inspect for at the end of it.
You own the supply chain end to end — pipelines that produce hardened, signed release artifacts with a software bill of materials attached, with scanning, policy enforcement, and secrets handling built into the path rather than bolted alongside it. That path has to survive promotion into isolated and limited-connectivity environments, which means it works when the network doesn't and can prove what it shipped when nobody can reach back to check. It also has to produce the compliance evidence — audit and accreditation artifacts that fall out of the build automatically instead of getting assembled by hand under deadline.
Reliability comes with the territory. Once the platform is deployed, you're part of keeping it healthy: observability, alerting, and incident response are shared work on this team, and the person who built the release path is usually the one who can tell you what changed.
The engineers who do well here have worked inside a formal compliance framework and know the difference between a pipeline that passes a security review and one that produces the review. Experience packaging or promoting software into air-gapped or otherwise disconnected environments matters a lot — it's the part that's hardest to learn on the fly.
This position is contingent upon contract award. Travel of up to 15% may be required, primarily to Government facilities and between company locations. Unclassified work may be performed remotely, while classified promotion and validation activities require onsite work in an accredited facility and the appropriate security clearance.
Key Responsibilities
• Build and operate the CI/CD pipeline that produces versioned, signed release packages with SBOM manifests, hardened container images, deployment runbooks, and validation procedures for each promotion gate
• Execute the recurring low-to-high promotion cadence through Government-approved transfer mechanisms, including cross-domain solution submission packages, and verify environment parity after each promotion
• Integrate vulnerability management, image signing, dependency scanning, and continuous monitoring into the pipeline so accreditation evidence is generated once and reused at each promotion
• Work with the program's security engineers to keep pipeline outputs aligned to the RMF body of evidence
• Define and track service level objectives, and build monitoring, logging, and alerting with tools such as Prometheus, Grafana, and OpenTelemetry
• Lead incident response and run postmortems to closure
• Operate sanitized defect and telemetry feedback paths so issues observed in production environments are reproduced and fixed where the full toolchain is available
• Enforce the constraint that platform dependencies are limited to services confirmed available in the target environments, with development-only dependencies gated behind feature flags
• Maintain deployment runbooks, validation procedures, and operational documentation to a standard suitable for Government review and for execution by other cleared personnel
Required Skills & Experience
• U.S. citizenship and eligibility to obtain and maintain a U.S. security clearance
• 6+ years of experience in DevSecOps, site reliability engineering, platform engineering, or production operations
• 3+ years of experience supporting Department of Defense, Intelligence Community, or similarly regulated programs
• Hands-on experience packaging or promoting software into classified, air-gapped, or limited-connectivity environments
• Strong Kubernetes and cloud operations experience, including operating containerized production workloads in AWS
• Working knowledge of DevSecOps practices for regulated environments, including hardened containers, image signing, software bill of materials generation, vulnerability management, and continuous monitoring
• Experience working within the Risk Management Framework or a comparable security and compliance framework
• Proficiency in scripting and automation using Python, Bash, Go, or a comparable language
• Experience with infrastructure-as-code and deployment tools such as Terraform, Helm, or equivalent technologies
• Experience implementing or operating production observability stacks and participating in incident response
• Current DoD 8140/8570 qualifying certification, such as CISSP or CASP+, or the ability to obtain an appropriate certification within 90 days of hire
• Bachelor’s degree in c
Salary insight
The midpoint of this range ($198k) is about 55% above the median disclosed salary for Denver roles listed on ForgeApply ($128k across 1,225 jobs).
See full DevOps / SRE salary data for Denver →
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this Openteams role before you apply.
Tailor my resume for this jobSimilar jobs
- Site Reliability Engineer (DevOps) — Accenturefederalservices · Annapolis Junction, MD
- Site Reliability Engineer (DevOps) — Accenturefederalservices · Reston, VA
- DevOps / Site Reliability Engineer — Generalmatter · Los Angeles, CA
- Site Reliability Engineer — Apex Technology Inc · Los Angeles
- Site Reliability Engineer — Xai · Memphis, Tennessee; Southaven, Mississippi
- Site Reliability Engineer — Skydio · Remote
- Site Reliability Engineer — Supabase · Remote
- Site Reliability Engineer — Trimble · US - CO, Westminster
More like this: DevOps & SRE Jobs · DevOps & SRE Jobs in Denver · Browse all jobs
Free ATS checker · How to Autofill Greenhouse Job Applications (Without Sending Junk)