- Anavationllc
- San Antonio, TX
- Full-Time
- <48 Hours
Software Engineer - Kubernetes.
Before you go
Before you leave us, sign up for our email alerts
We don't do job spam, just the best digital jobs delivered straight to your inbox.
Software Engineer - Kubernetes: our view in 3 lines...
- The Role:This role is for a senior software engineer focused on securing Kubernetes and OpenShift platforms for government mission applications.
- The Person:The person will design, build, and run Kubernetes and OpenShift clusters, implement security controls, validate compliance evidence, manage vulnerabilities, and maintain documentation for ATO, cATO, and audit readiness.
- Requirements:The ideal candidate has Kubernetes, Istio, GitOps, custom Kubernetes Operators, custom Helm charts, custom Admission Controllers, custom CRDs and Controllers, Ansible, Terraform, Docker, Linux, and a TS/SCI clearance.
About the role
Description of Task to be Performed:
AnaVation is seeking a Software Engineer - Kubernetes to support one of our cybersecurity programs in our San Antonio office. In this position, the right candidate will support engineering, hardening and continuously validating the security of Kubernetes and OpenShift platforms that host Government mission applications across value streams. The role designs, builds, and runs resilient, secure architectures using service-meshand loosely coupled design, and sustains Interim Authority to Test (IATT), Authority to Operate (ATO), and Continuous Authority to Operate (cATO) readiness aligned with the Government’s Cyber Assessment Roadmap.
Position Responsibilities: This position sets the technical standard for securing container orchestration platforms and hardened workloads while keeping control evidence continuously validated and audit-ready.
Responsibilities include:
- Design, build, and run Kubernetes/OpenShift clusters and manage providers (Amazon EKS/Fargate, Azure KS, Google KE) or self-managed clusters.
- Design network connectivity and provisioning strategy, and assess/design RBAC to keep the cloud foundation strong and compliant.
- Maintain, configure, and monitor containers using Infrastructure as Code (Terraform, Helm) across development, test, and live environments.
- Implement and validate security controls, security-relevant changes (SRCs), and Security Impact Assessments (SIAs) supporting IATT, ATO, and cATO readiness.
- Perform full-stack Kubernetes (K8s) risk assessments and apply STIGs, CIS Benchmarks, and Iron Bank hardened images.
- Advance control inheritance and automation aligned with the Government’s Cyber Assessment Roadmap.
- Support container vulnerability management against CVEs and open-source threat reporting, coordinating remediation with Value Stream engineering.
- Collaborate with ISSEs, ISSMs, DevSecOps engineers, COT, CPT, and Government stakeholders across Value Stream sprint cadences.
- Create and maintain documentation for implementations and supporting Bodies of Evidence (BOE).
- Support Zero Trust enforcement and cloud-native security best practices across mission environments.
- Maintain and validate A&A control evidence in eMASS (control implementation, SIAs, SRCs, POA&Ms) supporting continuous monitoring and cATO readiness.
- Generous cost sharing for medical insurance for the employee and dependents
- 100% company paid dental insurance for employees and dependents
- 100% company paid long-term and short-term disability insurance
- 100% company paid vision insurance for employees and dependents
- 401k plan with generous match and 100% immediate vesting
- Competitive Pay
- Generous paid leave and holiday package
- Tuition and training reimbursement
- Life and AD&D Insurance
