Site Reliability Engineer FedRAMP Vulnerability Management

<strong>Job Description<br><br></strong>Must Have Technical/Functional Skills:<br><br><ul><li> 5+ years of experience in Site Reliability Engineering, DevOps, Infrastructure Engineering, or a related role supporting cloud-based production environments.</li><li> Practical vulnerability-management experience; familiarity with Qualys, JFrog Xray,<br><br></li></ul>SCA/SBOM, or equivalent tooling; as well as knowledge of dependency-management for Ruby/Bundler, Python/pip, and Go modules. Experience with direct versus transitive dependencies, version constraints, lockfiles, go.mod/go.sum, and verifying the effective version shipped in a built artifact.<br><br><ul><li> Experience developing and maintaining infrastructure automation using Ansible.</li><li> Experience administering and troubleshooting Linux-based systems and distributed infrastructure environments.</li><li> Experience designing, implementing, and maintaining CI/CD pipelines, including GitLab CI.</li><li> Experience supporting large-scale infrastructure environments consisting of hundreds or thousands of systems.</li><li> Available to be online from 9am-4pm PST.<br><br></li></ul><strong>Roles & Responsibilities<br><br></strong>Own findings for FedRAMP Vulnerability Management from intake through validated remediation and closure. Triage and prioritize host, OS-package, container, base-image, and application-dependency findings using exploitability, asset criticality, and remediation timelines. Identify the real source of vulnerable software and determine whether the right action is a dependency update, image rebuild, promotion, host change, deviation, false-positive correction, or ticket cleanup. Implement or coordinate fixes through Ansible, GitLab CI, package managers, container builds, Artifactory, and Federal promotion-train workflows and validated promoted artifacts. Validate fixes using effective package versions, build artifacts, image manifests, deployed-host evidence, and scanner rescans before resolving vulnerability tickets. Maintain Jira evidence, ownership, due-date escalation, exception rationale, backlog metrics, runbooks, automation, and knowledge transfer. Success will mean reducing the overdue backlog, improving ownership and evidence quality, delivering repeatable automation and runbooks, and transferring a sustainable process to the CSI team for future use.Develop and maintain automation solutions that improve the reliability, scalability, security and operational efficiency of infrastructure and processes for the hosts in our FedRAMP cloud environments, as well as new innovations that allow us to adjust to changing compliance requirements. Design and enhance deployment pipelines, testing frameworks, and operational tooling to support the continued growth of a platform serving a rapidly growing number of managed devices worldwide. Troubleshoot complex infrastructure and distributed systems issues to ensure high availability while helping teams adapt their infrastructure, applications and processes to FedRAMP controls and requirements. Contribute to critical projects such as refactoring our deployment process, and new cluster build outs by building automation that enables manual toil reduction, as well as rapid and repeatable processes for new purpose-built cloud environments. Partner with other engineering teams, product management, and business partners across multiple teams and time zones to understand platform dependencies, seek opportunities for improvement, and deliver solu tions that enhance reliability and performance while reducing operational overhead.<br><br><strong>Good To Have<br><br></strong><ul><li> Familiarity with AWS or other public cloud platforms and hybrid infrastructure environments.</li><li> Knowledge of monitoring, observability, and reliability engineering practices and tooling.</li><li> Familiarity with Kubernetes concepts and containerized application platforms.</li><li> Experience employing AI-assisted development tools to improve software development, automation, operational analysis, and engineering productivity.</li><li> Experience managing fleet wide software deployments</li><li> Experience providing incident support and triage.<br><br></li></ul>In order to comply with U.S. laws and regulations applicable to this position, the person(s) hired must possess the ability to obtain US Security Clearance which requires that the person be a U.S. Citizen, a U.S. Permanent Resident (i.e., a “Green Card Holder”), or a Political Asylee or Refugee.<br><br>Salary Range: $86,000 - $120,000 a year<br><br>

Back to blog

Other Jobs To Apply

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...