<div class="content-intro"><p>Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. Black Duck, a recognized pioneer in application security, provides SAST, SCA, and DAST solutions that enable teams to quickly find and fix vulnerabilities and defects in proprietary code, open source components, and application behavior. With a combination of industry-leading tools, services, and expertise, only Black Duck helps organizations maximize security and quality in DevSecOps and throughout the software development life cycle.</p></div><p><strong><span data-contrast="none">Lead DevOps Engineer</span></strong><span data-ccp-props="{}"> <strong>(FedRamp - Design & Build)</strong></span></p>
<p><strong><span data-contrast="auto">Who we are: </span></strong><span data-ccp-props="{"335559738":240,"335559739":240}"> </span></p>
<p><span data-contrast="auto">Black Duck is the market leader in application security testing, helping organizations worldwide build secure, high-quality software. We are building FedRAMP-authorized cloud environments to serve federal agencies, integrating security seamlessly into DevOps while establishing rigorous compliance with government security frameworks. </span><span data-ccp-props="{"335559738":240,"335559739":240}"> </span></p>
<p><strong><span data-contrast="auto">What you'll do (responsibilities): </span></strong><span data-ccp-props="{"335559738":240,"335559739":240}"> </span></p>
<p><span data-contrast="auto">As a Senior Staff Engineer in the FedRAMP DevOps Platform Team, you will define and drive the technical vision for our FedRAMP-authorized cloud platform, enabling Black Duck's expansion into the federal market. You will architect compliance-first infrastructure serving 500+ engineers while maintaining government security standards and accelerating our path to ATO.</span><span data-ccp-props="{"335559738":240,"335559739":240}"> </span></p>
<ul>
<li><span data-contrast="auto">Define and architect the end-to-end FedRAMP-compliant cloud platform strategy, leveraging accelerators to achieve initial ATO within 12-18 months while establishing foundation for continuous authorization and multi-year scalability.</span><span data-ccp-props="{"335559738":240,"335559739":240}"> </span></li>
<li><span data-contrast="auto">Lead initial FedRAMP authorization from architecture through ATO: drive SSP authoring, NIST 800-53 control implementations, 3PAO coordination, and readiness assessment while establishing repeatable processes that reduce future authorization cycles by 40%.</span><span data-ccp-props="{"335559738":240,"335559739":240}"> </span></li>
<li><span data-contrast="auto">Architect secure, scalable platform infrastructure including CI/CD pipelines, Kubernetes environments, developer portal (Backstage), observability systems, and compliance automation that enables developer velocity while maintaining continuous compliance posture.</span><span data-ccp-props="{"335559738":240,"335559739":240}"> </span></li>
<li><span data-contrast="auto">Establish security and compliance architecture patterns across encryption, network segmentation, secrets management, supply chain security, and incident response that become organizational standards and reduce security review cycles.</span><span data-ccp-props="{"335559738":240,"335559739":240}"> </span></li>
<li><span data-contrast="auto">Drive technical decisions and technology selection for government cloud platforms, compliance tooling, and security controls; influence product roadmap to balance federal requirements with commercial product needs.</span></li>
<li><span data-contrast="auto">Mentor and raise the technical bar across engineering teams through architecture reviews, design discussions, and establishing FedRAMP best practices; build organizational competency in compliance-aware development.</span></li>
<li><span data-contrast="auto">Partner with security, product, and business leadership to translate federal customer requirements into technical architecture, manage compliance risk, and deliver measurable improvements in security posture and operational efficiency. </span></li>
</ul>
<p><strong><span data-contrast="auto">What you'll need:</span></strong><span data-ccp-props="{"335559738":240,"335559739":240}"> </span></p>
<p><strong><span data-contrast="auto">BASIC QUALIFICATIONS:</span></strong><span data-ccp-props="{"335559738":240,"335559739":240}"> </span></p>
<ul>
<li><span data-contrast="auto">U.S. citizenship required (FedRAMP and government customer requirements).</span><span data-ccp-props="{"335559738":240,"335559739":240}"> </span></li>
<li><span data-contrast="auto">BS in Computer Science or related field, or equivalent experience.</span></li>
<li><span data-contrast="auto">10+ years in SRE, DevOps, or Platform Engineering with demonstrated technical leadership across teams.</span><span data-ccp-props="{"335559738":240,"335559739":240}"> </span></li>
<li><span data-contrast="auto">Proven experience designing and achieving FedRAMP ATO (High or Moderate), including SSP authoring, NIST 800-53 control implementation, architecture documentation, and 3PAO coordination.</span></li>
<li><span data-contrast="auto">Expert-level architecture experience on government cloud platforms (AWS GovCloud, Azure Government, or GCP for Government) with deep understanding of compliance requirements, networking, and security boundaries.</span><span data-ccp-props="{"335559738":240,"335559739":240}"> </span></li>
<li><span data-contrast="auto">Expertise in modern platform technologies: Kubernetes security, infrastructure-as-code (Terraform), GitOps (ArgoCD/Flux), CI/CD security, observability systems, and secrets management.</span><span data-ccp-props="{"335559738":240,"335559739":240}"> </span></li>
<li><span data-contrast="auto">Strong programming skills (Go, Python, or Node.js) and demonstrated ability to drive complex technical initiatives from architecture through production. </span><span data-ccp-props="{"335559738":240,"335559739":240}"> </span></li>
</ul>
<p><strong><span data-contrast="auto">PREFERRED QUALIFICATIONS:</span><span data-ccp-props="{"335559738":240,"335559739":240}"> </span></strong></p>
<ul>
<li><span data-contrast="auto">Experience leading multiple FedRAMP authorizations from architecture through ATO with track record of reducing time-to-authorization and establishing repeatable processes.</span><span data-ccp-props="{"335559738":240,"335559739":240}"> </span></li>
<li><span data-contrast="auto">Experience with FedRAMP accelerators (Stack Armor, Coalfire) and demonstrated ability to adapt frameworks while maintaining architectural integrity.</span><span data-ccp-props="{"335559738":240,"335559739":240}"> </span></li>
<li><span data-contrast="auto">Professional certifications: CISSP, AWS/Azure/GCP Security Specialty, CKS, GIAC, or equivalent.</span><span data-ccp-props="{"335559738":240,"335559739":240}"> </span></li>
<li><span data-contrast="auto">Experience with DoD environments (IL4/IL5), CMMC, compliance-as-code practices (OSCAL), and automated compliance documentation.</span><span data-ccp-props="{"335559738":240,"335559739":240}"> </span></li>
<li><span data-contrast="auto">Advanced degree in Computer Science or related field, or equivalent experience architecting secure, compliant platforms at scale.</span></li>
</ul><div class="content-pay-transparency"><div class="pay-input"><div class="title">Pay Range</div><div class="pay-range"><span>$164,500</span><span class="divider">—</span><span>$246,800 USD</span></div></div></div><div class="content-conclusion"><p>Black Duck considers all applicants for employment without regard to race, color, religion, sex, gender preference, national origin, age, disability, or status as a Covered Veteran in accordance with federal law. In addition, Black Duck complies with applicable state and local laws prohibiting discrimination in employment in every jurisdiction in which it maintains facilities. Black Duck also provides reasonable accommodation to individuals with a disability in accordance with applicable laws.</p></div>