Search

Infrastructure Engineer (Active TS/SCI Required)

PublishedPublished: 6/14/2022
Technology

Job Description

Job Description

Infrastructure Engineer (Active TS/SCI Required)


Location: Arlington, VA (On-Site)

Type: Full-Time

Compensation: $200,000 - $300,000


AGF Talent is leading the search for a Forward Deployed Infrastructure Engineer on behalf of a fast-growing company building AI platforms for high-consequence government environments.


The Opportunity

This organization is looking for a cleared infrastructure engineer who can make a complex AI platform run reliably anywhere it's deployed, from cloud environments with limited connectivity to fully air-gapped clusters with no internet access at all. If you love solving hard infrastructure problems with no safety net, no internet search to lean on, and no room for guesswork, this is the kind of role that will keep you sharp.


This company builds AI platforms for high-consequence government environments and has grown quickly, winning competitively awarded federal contracts and standing up work in classified networks. The team brings together backgrounds from intelligence, elite engineering, and military service.


What You'll Own

  • The air-gapped deployment pipeline, end to end: getting source code, charts, and configuration into disconnected environments, then building and deploying container images onsite, with no ability to pull anything from the internet
  • Onsite Helm configurations that adapt to each deployment target, whether that means using managed services in an on-prem cloud or swapping in Kubernetes-native alternatives on standalone clusters
  • Stateful infrastructure services, including databases, caching, workflow orchestration, identity, and object storage, running on bare Kubernetes without managed cloud backends
  • Cluster management and delivery tooling, including Kubernetes lifecycle management, GitOps-based deployment, and container registry operations in disconnected environments
  • The secrets lifecycle in classified environments, with all credentials generated fresh onsite and rigorous security practices throughout
  • PKI and certificate management across onsite deployments, including CA hierarchies, certificate issuance and rotation, mTLS between services, and trust chain validation without external certificate authorities
  • Container build pipelines for environments where Docker isn't available, using rootless, hardened tooling
  • Troubleshooting in fully disconnected environments: crashed pods, failed migrations, certificate errors, and storage problems, solved without a debug image or a search engine
  • Performance optimization on constrained hardware, tuning resource utilization, pod scheduling, storage I/O, and network throughput where you can't simply scale up
  • Deployment parity between cloud and onsite environments, plus the onsite monitoring architecture that gives the team visibility into system health and service status
  • Database operations tooling, including migrations, backup and restore, and schema management, built to work reliably without a connection
  • Clear runbooks and troubleshooting guides that onsite operators can follow independently


What You Bring

  • Deep, hands-on experience deploying and operating Kubernetes in constrained or fully disconnected environments
  • U.S. citizenship and an active TS/SCI clearance
  • Strong Helm skills and comfort translating deployments across different infrastructure targets
  • Experience running stateful workloads on bare Kubernetes without managed cloud services
  • Solid understanding of PKI, certificate management, and secrets handling in secure environments
  • Comfort troubleshooting deep infrastructure issues with no external resources to lean on
  • Clear technical writing skills for operational, classified contexts
  • Willingness to work on-site in the National Capital Region


Nice to Have

  • Experience operating Kubernetes across classified environments, including on-prem cloud and standalone or SCIF environments
  • Experience with modern GitOps and container registry tooling in air-gapped or restricted settings
  • Prior work with rootless container build tools in restricted environments
  • Experience deploying identity providers without cloud backends
  • Background in workflow orchestration operations, especially schema bootstrapping without internet access
  • Familiarity with DoD-hardened base images or STIG compliance
  • Experience authoring STIGs, SSPs, or ATO documentation for classified deployments
  • Prior work with cross-domain solutions or data transfer procedures between classification levels


What's In It For You

  • Competitive base salary of $200,000-$300,000 plus bonus
  • Full benefits package
  • Generous paid time off
  • A seat alongside a genuinely exceptional team, with real ownership over outcomes from day one


If you're ready to solve infrastructure problems that actually matter, we'd love to hear from you.

Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...