All Jobs Vacancy

Site Reliability Engineer FedRAMP Vulnerability Management

Posted 1 day ago by Synkriom

JOB DESCRIPTION

The SRE Compliance & Security Initiatives team is responsible for maintaining the stability, scalability, and efficiency of the infrastructure and applications that power our FedRAMP cloud platform.

As a team of five engineers distributed across the US, we combine deep infrastructure expertise with a strong focus on automation, reliability, and operational excellence.

We are the primary SRE team working together with more than 20 other teams across SRE and the broader Engineering, Security and Product organizations to support a platform that serves a rapidly growing customer base that currently manages tens of thousands of devices.

The team operates with a high degree of autonomy, giving engineers the opportunity to drive both critical initiatives and grassroots improvements that solve real operational challenges.

One of our most exciting areas of focus is expanding our ability to build highly automated processes to increase the operational efficiency and security of our cloud environments that support evolving regulatory requirements.

Everyone on the team has a voice, and engineers are encouraged to identify problems, propose solutions, and take ownership of improvements that make the platform more reliable and easier to operate.

Your Impact

Own findings for FedRAMP Vulnerability Management from intake through validated remediation and closure.

Triage and prioritize host, OS-package, container, base-image, and application-dependency findings using exploitability, asset criticality, and remediation timelines.

Identify the real source of vulnerable software and determine whether the right action is a dependency update, image rebuild, promotion, host change, deviation, false-positive correction, or ticket cleanup.

Implement or coordinate fixes through Ansible, GitLab CI, package managers, container builds, Artifactory, and Federal promotion-train workflows and validated promoted artifacts.

Validate fixes using effective package versions, build artifacts, image manifests, deployed-host evidence, and scanner rescans before resolving vulnerability tickets.

Maintain Jira evidence, ownership, due-date escalation, exception rationale, backlog metrics, runbooks, automation, and knowledge transfer.

Success will mean reducing the overdue backlog, improving ownership and evidence quality, delivering repeatable automation and runbooks, and transferring a sustainable process to the CSI team for future use.

Minimum Qualifications

  • 5+ years of experience in Site Reliability Engineering, DevOps, Infrastructure Engineering, or a related role supporting cloud-based production environments.
  • Practical vulnerability-management experience; familiarity with Qualys, JFrog Xray, SCA/SBOM, or equivalent tooling; as well as knowledge of dependency-management for Ruby/Bundler, Python/pip, and Go modules. Experience with direct versus transitive dependencies, version constraints, lockfiles, go.mod/go.sum, and verifying the effective version shipped in a built artifact.
  • Experience developing and maintaining infrastructure automation using Ansible.
  • Experience administering and troubleshooting Linux-based systems and distributed infrastructure environments.
  • Experience designing, implementing, and maintaining CI/CD pipelines, including GitLab CI.
  • Experience supporting large-scale infrastructure environments consisting of hundreds or thousands of systems.
  • Available to be online from 9am-4pm PST.

Preferred Qualifications

  • Familiarity with AWS or other public cloud platforms and hybrid infrastructure environments.
  • Knowledge of monitoring, observability, and reliability engineering practices and tooling.
  • Familiarity with Kubernetes concepts and containerized application platforms.
  • Experience employing AI-assisted development tools to improve software development, automation, operational analysis, and engineering productivity.
  • Experience managing fleet wide software deployments
  • Experience providing incident support and triage.
Rate:
Not specified
Location:
United Kingdom
IR35 Status:
Outside
Remote Status:
Remote
Industry:
IT
Seniority Level:
Senior

Take-Home Pay

Not Available

Visit calculators for additional details

Share job