Everforth ECS is seeking an Infrastructure Engineer (AWS / Terraform / EKS) to work in a hybrid capacity in our Fairfax, VA office.
Â
Everforth ECS is seeking a Senior Infrastructure Engineer (AWS / Terraform / EKS) to join a team responsible for managing and maintaining multiple network enclaves to support the DoD community. This role focuses on designing, building, and operating secure, repeatable AWS environments within a FedRAMP and ATO-governed context. The engineer will work in an environment where all deployments are infrastructure-as-code, peer-reviewed, and fully auditable. The successful candidate will combine hands-on AWS engineering depth with a strong sense of operational discipline, automation, and compliance awareness. This is not just EKS/Terraform build work; it is operational ownership across commercial and GovCloud AWS accounts for connectivity, routing, DNS, F5/load balancing, EKS, Terraform, security remediation, migrations, and stakeholder coordination.
Â
We are seeking dynamic, energetic, and engaging team members who love challenges! The ideal candidate will be able to align to the following duties:
Â
- Troubleshoot and support enterprise load-balancing and ingress patterns, including F5 or equivalent technologies, DNS, TLS/certificate paths, routing, and endpoint reachability.
- Coordinate directly with application teams, Security, stakeholders, network owners, and program leadership to resolve connectivity, access, migraiton, and production readiness
- Design, build, and maintain Infrastructure-as-Code using Terraform (modules, S3/DynamoDB remote state, OPA/tfsec policy integration).
- Provision, upgrade, and manage EKS clusters, including namespaces, Helm-based add-ons (cert-manager, ESO, Confluent Operator), and IAM roles for service accounts.
- Design, configure, and troubleshoot AWS VPC networking, including routing, TGWs, DNS, DHCP, endpoints, NACLs, and security groups.
- Implement and secure microservices on EKS with proper connectivity to AWS services (S3, ECR, Secrets Manager, IAM).
- Automate infrastructure deployments using GitHub Actions (or self-hosted runners), cross-account IAM role assumptions, and CI/CD policy gates.
- Collaborate with security and applications teams to enforce least-privilege IAM, automate compliance evidence collection, and support RMF/ATO documentation.
- Diagnose and resolve complex issues spanning containers, Kubernetes networking, and AWS layers (VPC – Zscaler - C-TIPS - SaaS endpoints).
- Support observability, logging, and monitoring through integration with Elastic, ScienceLogic, or AppDynamics to meet SLA and audit requirements.
- Mentor and guide junior engineers through knowledge sharing, paired engineering, and process standardization.
- Evaluate and improve infrastructure design for policy compliance, resiliency, and performance tuning.
- Develop and maintain SOPs and playbooks that align with program governance.
- Support legacy-to-CAWS migration activities, including RabbitMQ/app-server connectivity, environment cutover support, dependency discovery, and validation of network paths across lower and production environments.
- Quickly build working knowledge of inherited environments, document tribal knowledge, create diagrams/runbooks, and transfer operational context to primary and backup owners.
- Operate within a formal change-control, evidence, and audit expectations, including CR support, implementation evidence, rollback planning, and post-change validation.
- Other duties, as assigned.
Note: Salary is commensurate with skillset, qualifications, experience, and educational background.
Â
Salary Range: $140,000-180,000
General Description of BenefitsÂ
- U.S. Citizen.
- Active DoD Secret clearance.
- Bachelor's degree or 6 years of relevant experience or high school diploma with 9+ years of relevant experience.
- Candidate is required to work in a hybrid capacity, with up to 3 business days per week onsite at Everforth ECS Corporate Offices
- Required certifications
- Active DoD 8140 IAT Level II Security+ (or higher).
- CLF-C02 AWS Certified Cloud Practitioner.
- SAA-C03 AWS Certified Solutions Architect – Associate.
- Experience required:
- 6+ years designing, implementing, securing, and maintaining AWS Cloud infrastructure (CAWS, GovCloud, or equivalent).
- 5 + years troubleshooting hybrid/cloud network connectivity, including VPC routing, TGW, DNS, DHCP, TLS/certificates, security groups, NACLs, endpoints, and load balancers.
- 5+ years of of Terraform (advanced modules, state management, policy enforcement).
- 5+ years' of Kubernetes networking, ingress, CoreDNS, service exposure, node/security group behavior, and connectivity between EKS workloads and AWS/external services.
- 5+ years of infrastructure experience related to network security.
- Strong networking foundation: TCP/IP, DNS, DHCP, TLS, routing, subnetting, NACLs, and endpoint connectivity.
- Proficient scripting/automation using Python or Bash, YAML/JSON templating, and Git-based workflows.
- Experience in security compliance environments (FedRAMP, FISMA, NIST 800-53) and supporting ATO documentation.
- Demonstrated ability to collaborate cross-functionally with Security, DevSecOps, and CI/CD teams to maintain compliant, auditable infrastructure.
- Strong problem-solving and decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate solution.
- Highly developed interpersonal and oral/written communication skills, with the ability to effectively and professionally interact with a diverse set of stakeholders (from peers to end-users to executive management).
Â
Learn more about this Employer on their Career Site
