Systems Engineer (DevSecOps)


This is a foundational hire with room to grow. You will be responsible for the operational layer of a fast moving, high-impact research and technology environment. You'll start as the senior engineer who runs and hardens the platform, reporting to the CTO for our client, a growing advisor firm, with the runway to develop further. You will work closely with our Software Engineers to maintain, harden, and evolve a modern stack: macOS/iOS user endpoints, Linux servers, AWS infrastructure, Cloudflare for edge services and ZTNA, and a sophisticated data analytics environment including a multi-DB lakehouse. You will operate and continuously improve all aspects of DevSecOps - including CI/CD, secrets management, IdAM, and security posture overall.
This is not a ticket-queue role. You will architect as well as administer, automate as well as operate, and maintain an optimal estate as our team and systems scale - minimising click-ops.

You will not be walking into a confused mess. We already operate a sophisticated and well-designed (but part-built) environment, with clarity on where we are going. E.g. at present deployments are health-gated with automatic rollback, CI runs on short-lived redentials rather than long-lived cloud keys, dependency and image updates arrive as automated, review-gated pull requests, and backups sit in deletion-locked vaults with cross-region copies. Your job will be to help us go further. Resilience - backup, DR, recovery, and the observability and incident response around them - is yours to own, and to keep proven by drill rather than assumed.

Required Skills


- Five years of professional experience in building and running production systems. Ideally a tertiary qualification, but we value demonstrated skill more.
- Linux-first (RHEL/Debian/Ubuntu), macOS and iOS end-user devices, AWS, cloud-native - workloads run predominantly as containers and IaC, not hand-tended servers; this includes isolated, segmented environments.
- Cloudflare: DNS, CDN, and Zero Trust (Access, Tunnels, WARP) end to end. AWS, multi-account: ECS/EC2, IAM, S3, networking, and governance - IaC via Terraform, Terraform-first.
- Identity & endpoints: Entra ID, Intune - run well, evolved with judgment; note this is not a Windows-centric role.
- Databases: Aurora (OLTP), Iceberg/S3 tables, with numerous other analytical and graph databases
and caches.
- CI/CD: GitHub Enterprise, Actions with security embedded in the pipeline.
- AI-native engineering: you use AI tools fluently and are comfortable operating alongside AI agents in the delivery loop

**ABOUT YOU**

You are a systems engineer first, an operator always. You have deep, evidenced experience running Linux and macOS environments in production - shown in the things you've actually built and shipped, and that you can walk us through in depth (a public GitHub or similar is welcome). You build the platform, you don't just tend it. You think in infrastructure-as-code and automation by default - Terraform, containers, CI/CD pipelines - and you treat click-ops as debt. You've designed and shipped systems that deploy, scale, and recover without someone standing over them. Every manual task is a candidate for elimination. You automate what you administer. You script fluently in shell (bash/zsh) and Python. You believe the best systems run themselves, and you build toward that. Security is woven through the work, not a layer someone else owns. DevSecOps is how you build, not a separate discipline: Zero Trust access (Cloudflare Access/Tunnels/WARP), least privilege IAM, federated identity (Entra/SSO/SCIM), secrets management and rotation, guardrails as code, and pipeline security in GitHub Actions - ephemeral credentials, secret-scanning, artefact integrity. You've done serious work across several of these surfaces and want to own the rest. You own resilience, and you prove it. Backup, disaster recovery, observability, and incident response are yours - kept honest by drill, not assumption. You instrument what you run, you know before your users do, and you've been the person in the incident, not just downstream of it. You understand the full stack beneath the application. Networking, DNS, TLS, databases - transactional and analytical. You might not be a DBA, but you speak SQL well enough to diagnose, optimise, and not break things. You work with AI, not around it. You use AI tooling - e.g. Claude Code - to go faster and build better, and you can contribute to the infrastructure that supports AI workloads.

Apply Now

Return to Search Results

Have a Question?

Location

Hybrid/Washington, DC

Openings

1

Anticipated Start Date

Monday, September 14, 2026

Job Type

Contract

Anticipated Duration

Direct Placement

Date Posted

Monday, August 10, 2026

Know someone who would be a good fit? We pay for referrals!

Share this job:



Call 800-ELITE-50
Reference #12649

Elite Technical Services, Inc. participates in the E-Verify program to confirm the employment eligibility of all persons hired. This means that we will provide the Social Security Administration (SSA) and, if necessary, the Department of Homeland Security (DHS), with information from each new employee's Form I-9 to confirm work authorization. Elite Technical Services, Inc. will not use E-Verify to pre-screen job applicants.

Elite Technical Services, Inc. is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law.