Senior Platform Engineer-TS Required
SIXGEN · Sterling, VA · 1 mo ago
HybridFull-time
About the role
The position involves building, securing, and scaling virtualization, network, and endpoint infrastructure for a sensitive, high-assurance environment. The ideal candidate will have 5+ years of experience in platform, infrastructure, systems, or DevOps engineering.
Responsibilities
- Design, build, and administer a highly available Type-1 hypervisor cluster as the backbone for internal services and workloads.
- Automate provisioning of isolated workload VMs with controlled, auditable access to shared storage.
- Tune and troubleshoot the virtualization layer for concurrent workloads and capacity; manage cluster health against a documented sizing model.
- Audit and secure network architecture with layered firewall enforcement and a default-deny posture.
- Build and operate self-hosted remote access (modern VPN with strong MFA) and internal connectivity, keeping control planes private and not internet-exposed.
- Own internal DNS, PKI/mTLS, and time synchronization; enforce encrypted, controlled name resolution.
- Build and maintain hardened endpoints and hosts to recognized baselines (CIS Benchmarks / DISA STIG).
- Provision the environment as code (infrastructure-as-code plus configuration management) with encrypted state and runtime secret injection.
- Maintain a staging path to validate changes before production, plus staged patch management and tested backup/restore.
- Build the observability stack (metrics, health, alerting), isolated from workloads so it cannot be reached or tampered with from them.
- Deploy network and flow monitoring at key boundaries, with alerting on anomalies and integrity issues.
- Implement isolation and response controls, and generate the audit evidence that supports common security frameworks (SOC 2, ISO 27001, NIST CSF, NIST SP 800-115).
Qualifications
- Deep hands-on expertise with a Type-1 hypervisor (Proxmox VE, KVM/QEMU, VMware ESXi, or equivalent), including clustering, shared storage, templating, and GPU passthrough.
- Strong network engineering and security skills: segmentation, stateful firewalls, zero-trust / least-privilege design, VPNs, DNS, PKI/mTLS, and TCP/IP fundamentals.
- Demonstrated endpoint and OS hardening across Linux and Windows to CIS/STIG baselines: full-disk encryption, measured boot, host firewalls, and attack-surface reduction.
- Fluency in infrastructure-as-code and automation (e.g., Terraform, Ansible, Packer) plus Python and Bash, with a track record of shipping and maintaining working tooling and pipelines.
- Working knowledge of secrets management, containerization, Git and CI/CD, and an observability/SIEM stack.
- Proven ability to stand up infrastructure from bare metal to operational, document it in runbooks, and operate it under security- and audit-sensitive conditions.
Preferred Qualifications
- TS/SCI with CI polygraph; background supporting national security, intelligence community, or federal missions.
- Experience building or operating secure, isolated, or highly segmented infrastructure for sensitive or security-critical environments.
- Multi-cloud experience (AWS, GCP, Azure) with self-hosted networking.
- Experience building SIEM/audit pipelines with tamper-evident logging and detection engineering.
- Relevant certifications (e.g., RHCE, CKA, Security+, CISSP) and familiarity with SOC 2, ISO/IEC 27001, NIST CSF, or NIST SP 800-115.
- Experience standing up a new capability, unit, or program from zero — including standards authorship, staging environments, and identity-lifecycle (onboarding/offboarding) design.