Network/Cloud Engineer

CACI International Inc.Washington, District of Columbia, MarylandOn-siteFull-timeStaff, 8–12 yearsListed 59 minutes ago

Apply now

About this role

Job Title: Network/Cloud Engineer

Job Category: Information Technology

Time Type: Full time

Minimum Clearance Required to Start: None

Employee Type: Regular

Percentage of Travel Required: Up to 10%

Type of Travel: Local

* * *

The Opportunity:

In emergency management, technology agility can mean the difference between rapid response and delayed relief. As a Network/Cloud & DevSecOps Engineer on our FEMA ITSA 3.0 program, you will evaluate the cloud architectures, automation maturity, and security controls that enable FEMA systems to deliver mission capabilities with speed, resilience, and compliance. Your assessments will identify the technical enablers—CI/CD automation, infrastructure-as-code, API gateways, service mesh architectures, and modern security patterns—that can accelerate FEMA's modernization journey while strengthening security posture.

You'll dive into cloud hosting platforms, DevSecOps pipelines, and security control implementations to assess maturity, identify gaps, and recommend practical paths forward. Your expertise will inform strategic decisions on cloud migration, automation investment, security architecture enhancement, and DevSecOps transformation—ensuring FEMA can leverage modern engineering practices to deliver capabilities faster, more securely, and with greater reliability. This role offers a unique opportunity to assess and influence the engineering foundations of one of the federal government's most critical missions, where your cloud and DevSecOps expertise will shape how FEMA builds, secures, and operates technology that serves communities in crisis.

Responsibilities:

Cloud Architecture & Platform Assessment:

- Evaluate cloud hosting architectures across AWS, Azure, and hybrid environments including compute, storage, networking, and managed services utilization
- Assess cloud-native design patterns, serverless adoption, containerization maturity, and platform-as-a-service (PaaS) opportunities
- Review multi-region and multi-availability zone strategies for high availability and disaster recovery
- Evaluate environment design across development, test, staging, and production including environment parity and configuration drift
- Identify cloud cost optimization opportunities including rightsizing, reserved capacity, and architectural efficiency
- Assess alignment with FedRAMP requirements, cloud security best practices, and DHS cloud policies

CI/CD Pipeline & DevSecOps Maturity Evaluation:

- Review Continuous Integration/Continuous Deployment (CI/CD) pipelines including build automation, testing frameworks, and deployment orchestration
- Assess artifact management practices, container registries, and software composition analysis
- Evaluate deployment strategies including blue-green deployments, canary releases, rolling updates, and rollback procedures
- Review test automation coverage including unit testing, integration testing, security testing (SAST/DAST), and performance testing
- Assess DevSecOps maturity including security integration within development workflows, shift-left security practices, and automated compliance validation
- Identify pipeline bottlenecks, manual handoffs, and opportunities to accelerate delivery velocity while maintaining security and quality

Infrastructure-as-Code & Configuration Management:

- Evaluate Infrastructure-as-Code (IaC) adoption using tools such as Terraform, CloudFormation, ARM templates, or similar platforms
- Assess configuration management practices, version control discipline, and code review processes for infrastructure
- Review environment provisioning automation, infrastructure testing, and policy-as-code implementation
- Evaluate immutable infrastructure patterns, container orchestration (Kubernetes, ECS, AKS), and declarative configuration approaches
- Identify opportunities to reduce configuration drift, improve environment consistency, and enhance infrastructure reliability through automation

Cybersecurity Controls & Authorization Posture:

- Assess Identity and Access Management (IAM) patterns, role-based access control (RBAC), and least-privilege implementation
- Evaluate Multi-Factor Authentication (MFA) enforcement, privileged access management (PAM), and secrets management practices
- Review Security Information and Event Management (SIEM) integration, centralized logging coverage, and log retention compliance
- Assess alerting mechanisms, threat detection capabilities, and Security Orchestration, Automation and Response (SOAR) maturity
- Evaluate incident response preparedness, playbook documentation, and security operations center (SOC) integration
- Review vulnerability management practices including scanning frequency, remediation workflows, and patch management automation
- Assess compliance with NIST SP 800-53 security controls, Risk Management Framework (RMF) requirements, and continuous monitoring practices

Modern Architecture Enablers & Integration Patterns:

- Recommend adoption of API gateways for centralized API management, traffic control, and security policy enforcement
- Evaluate service mesh opportunities (Istio, Linkerd, AWS App Mesh) to improve microservices observability, security, and resilience
- Assess automation platforms and orchestration tools that can improve operational efficiency and reduce manual toil
- Identify opportunities to leverage managed services, serverless computing, and event-driven architectures
- Recommend container orchestration, service discovery, and distributed tracing implementations
- Advise on interoperability improvements through standardized APIs, event streaming, and asynchronous messaging patterns

Qualifications:

Required:

- Bachelor's degree and 15+ years of infrastructure, cloud, and security engineering experience across hybrid cloud and on-premises environments
- Hands-on experience architecting and implementing solutions on AWS and/or Azure including core services (compute, storage, networking, databases, security)
- Demonstrated expertise designing and implementing CI/CD pipelines, DevSecOps workflows, and automated deployment strategies
- Proficiency with Infrastructure-as-Code tools (Terraform, CloudFormation, ARM templates, Ansible, or similar)
- Deep understanding of security control implementation across cloud and hybrid environments
- Experience assessing technical maturity, identifying gaps, and recommending practical modernization strategies
- Strong analytical skills with the ability to evaluate complex technical environments and distill findings into actionable recommendations
- Ability to obtain DHS Entry on Duty (EOD) clearance

Desired:

- FedRAMP authorization experience including security assessment, continuous monitoring, and compliance documentation
- Familiarity with NIST Risk Management Framework (RMF), Authority to Operate (ATO) processes, and federal security control baselines
- Knowledge of DHS cloud policies, Trusted Internet Connection (TIC) 3.0 requirements, and DHS Enterprise Architecture standards
- Experience implementing zero-trust architecture principles including software-defined perimeter, micro-segmentation, and identity-centric security
- Hands-on experience with container orchestration platforms (Kubernetes, Docker, ECS, AKS)
- Background with service mesh architectures (Istio, Linkerd, Consul) and API gateway platforms (Kong, Apigee, AWS API Gateway)
- Proficiency with observability and monitoring tools (Prometheus, Grafana, Datadog, Splunk, ELK stack)
- Experience with security automation tools including SAST/DAST scanners, dependency scanning, and compliance-as-code platforms
- Cloud certifications: AWS Solutions Architect, AWS DevOps Engineer, Azure Solutions Architect, Azure DevOps Engineer, or equivalent
- Security certifications: CISSP, CCSP, or cloud security specialty certifications
- DevOps/DevSecOps certifications or demonstrable expertise
- Experience supporting federal IT modernization programs or cloud migration initiatives
- Background in Site Reliability Engineering (SRE) practices and chaos engineering principles

-

What You Can Expect:

A culture of integrity.

At CACI, we place character and innovation at the center of everything we do. As a valued team member, you’ll be part of a high-performing group dedicated to our customer’s missions and driven by a higher purpose – to ensure the safety of our nation.

An environment of trust.

CACI values the unique contributions that every employee brings to our company and our customers - every day. You’ll have the autonomy to take the time you need through a unique flexible time off benefit and have access to robust learning resources to make your ambitions a reality.

A focus on continuous growth.

Together, we will advance our nation's most critical missions, build on our lengthy track record of business success, and find opportunities to break new ground — in your career and in our legacy.

Pay Range :

There are a host of factors that can influence final salary including, but not limited to, geographic location, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, education, and certifications. Our employees value the flexibility at CACI that allows them to balance quality work and their personal lives. We offer competitive compensation, benefits and learning and development opportunities. Our broad and competitive mix of benefits options is designed to support and protect employees and their families. At CACI, you will receive comprehensive benefits such as; healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits.

Since this position can be worked in more than one location, the range shown is the national average for the position.

The proposed salary range for this position is:
$105,100-$231,100

CACI is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, age, national origin, disability, status as a protected veteran, or any other protected characteristic.