Senior DevSecOps Engineer
Momentus · San Jose, CA, United States
About this role
**Senior DevSecOps Engineer** **About the role** Momentus is seeking a **Senior DevSecOps Engineer** to operate the cloud infrastructure engineering teams rely on today and to build its successor from the ground up. The current environment includes **AWS, Kubernetes, and CI**. The next phase is a new **AWS GovCloud** organization defined entirely as code—covering networking, identity, and the software supply chain needed for a regulated engineering organization. You’ll keep the existing environment healthy, help bring the new GovCloud environment online, and migrate workloads into it. You’ll also run the tooling that enables **governed access to AI models and coding agents**. This is a **building role on a small team** with broad scope—turning security requirements into code that produces its own evidence. **Key Responsibilities** - Operate and improve existing **AWS environments, Kubernetes clusters, and CI**, and migrate workloads into the new organization as it comes online - Build a new **multi-account AWS GovCloud** organization as code - Build and operate segmented network planes: **Transit Gateway, Firewalls, IPAM, PrivateLink, and VPNs** - Deliver secure **environment ingress/egress** - Own the software supply chain from **commit to cluster** (CI/CD runner fleets, **FIPS-validated images**, signed artifacts, replicated registries, private PKI) - Partner with security/compliance to translate **NIST SP 800-171** and **CMMC** controls into automated guardrails and evidence; triage and burn down security findings - Write clear **design notes, merge request reviews, and runbooks**; improve shared AI-assisted workflows - Roll out and support AI developer tooling (e.g., **Claude Code**) with managed settings; review, harden, and operate **MCP servers** and agent runtimes **Required Skills & Experience** - Production **Terraform or OpenTofu** (reusable modules, state management, imports/refactors, careful plan review) - Proficiency in **Python and/or Go**, plus **shell scripting** - Clear, concise **technical writing** - Deep hands-on AWS experience in a **multi-account organization** (IAM policy evaluation, Organizations/SCPs, Identity Center or equivalent federation) - Strong cloud networking skills (VPC design, Transit Gateway routing/segmentation, firewalls/inspection, DNS, PrivateLink, site-to-site VPN with BGP; ability to debug “why can’t X talk to Y” across accounts) - CI/CD and container supply chain experience (image builds, signing/verification, secrets management, vulnerability scanning) **Work Location** Preference for **onsite**, but **hybrid and remote** candidates will be considered.
Listing freshness
CronJobs last confirmed this listing 2h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.