Skip to main content
Weightless
CR
Engineering

DevOps Engineer (Infrastructure and Security Focus)

Castle Rock Associates

Full-Time
Mid-Level
$90k – $105k/yr
Remote, US
Posted 2d ago

Skills & tools

Node.jsPythonJavaScriptJavaPostgreSQLAWSDockerTerraformRESTGit

Job Description

**Important: This position is open only to candidates who currently reside in one of the following US locations. You will NOT be considered if you live outside these locations:** ***Oregon, Washington, California, Arizona, Minnesota, Michigan, Louisiana, Texas, or Washington, D.C.*** **Also, you must be authorized to work in the US without employer sponsorship now or in the future. We are unable to provide visa sponsorship for this role.** \-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\- **About Castle Rock Associates** Castle Rock is an industry leader in developing and operating software for transportation agencies across North America and Europe. Our software supports mission\-critical functions for our clients and the public, improving safety, trust, and mobility on roads and highways. We've been in this industry for over 40 years, but we've remained a small (\~30 people), focused, and highly productive team with a suite of successful products that we continue to grow and develop in close partnership with our clients. At the heart of our business is our 24/7/365 DevOps support team, which deploys, maintains, and monitors our systems in the Amazon Web Services (AWS) cloud. We're now investing heavily in security and compliance, working toward GovRAMP authorization, and modernizing infrastructure that has grown organically over many years. **The Opportunity** We're hiring a hands\-on DevOps Engineer to help us get our systems audit\-ready for GovRAMP and rebuild pieces of our AWS environment to meet modern security and compliance standards. This is a high\-impact, high\-autonomy role: you'll be architecting new infrastructure, hardening and rebuilding legacy systems, mapping our environment to NIST 800\-53 / GovRAMP control families, and moving fast using modern AI\-assisted development tools. This role reports directly to our CTO and will work as part of our DevOps team to support the current systems while applying security enhancements. If you love untangling legacy AWS environments, designing infrastructure the right way the first time, and want to apply serious security rigor without getting buried in bureaucracy, this role is built for you. **Why This Role Is Great for You** * You get to build, not just maintain – you'll architect new infrastructure and rebuild legacy systems rather than only keeping the lights on. * Your compliance and security expertise matters – your knowledge directly shapes how we design and document our systems. * You'll work at the speed AI tools now enable – we want someone who builds fast using modern AI coding and infrastructure tools. * High visibility, high trust – you'll work directly with the CTO and Leadership team on one of the company's top priorities this year and beyond. * You'll see your impact immediately – on a small team, your architecture and security decisions directly determine whether we pass our audits and how resilient our systems are. **What You'll Do** * Design, build, and rebuild AWS infrastructure to meet security best practices and GovRAMP/NIST 800\-53 control requirements. * Lead infrastructure\-as\-code efforts (Terraform, CloudFormation, or similar) to make environments repeatable, auditable, and version\-controlled. * Partner with the CTO to map technical controls to NIST 800\-53 / GovRAMP control families and produce supporting evidence and documentation. * Assess existing systems for architectural, security, and compliance gaps, and design remediation plans and rebuilds where needed. * Deploy and maintain services across Java, Node.js, and other platforms in AWS. * Design and implement system monitoring, logging, and alerting (e.g., CloudWatch, SIEM tooling) to support security operations and audit evidence. * Harden identity and access management, network segmentation, and encryption (at rest and in transit) across environments. * Use AI\-assisted development and infrastructure tools (e.g., Claude Code, Cursor) to accelerate delivery, while applying sound judgment to review, secure, and validate AI\-generated code and configurations. We are a human\-led, AI\-powered company, and accountability always rests with our people. * Build and maintain CI/CD pipelines that bake in security and compliance checks. * Participate in an on\-call rotation to support 24/7 system reliability. * Contribute to incident response, business continuity, and disaster recovery planning and testing. **What We're Looking For** **Must\-Have Skills** * 2\+ years of experience designing, building, and troubleshooting distributed software systems and infrastructure in AWS and strong AWS knowledge of EC2, RDS, Route53, Lambda, CloudFormation, S3, IAM, VPC/networking, etc. * Direct experience with NIST 800\-53, FedRAMP, ISO, SOC, or comparable cybersecurity compliance frameworks. * Demonstrated infrastructure architecture experience – able to design new environments from scratch and re\-architect/rebuild legacy ones. * Infrastructure\-as\-code experience (Terraform, CloudFormation, Ansible, or similar). * Strong scripting/programming skills (Python, Bash, JavaScript, or similar) for automation. * Hands\-on experience using AI coding/agentic tools (e.g., Claude Code, GitHub Copilot, Cursor) as part of your regular development workflow, with the judgment to review and secure what they produce. * Experience deploying and supporting Java web applications. * Familiarity with PostgreSQL and database administration fundamentals. * Solid Git experience and CI/CD pipeline design. **Nice\-to\-Have Skills** * Configuration management with source control and automated systems * Containerization and orchestration experience (Docker, ECS). * Experience with vulnerability management and patching tools (e.g., AWS Inspector, Nessus, Qualys). * Experience with logging/SIEM platforms (Splunk, Wazuh, CloudWatch Logs). * Exposure to cost optimization / FinOps practices when re\-architecting cloud environments. **Personal Qualities** * Ownership mindset – comfortable being accountable for architecture decisions end to end. * Security\-first instincts, balanced with practical delivery speed. * Strong written communication – able to document architecture and controls clearly enough for auditors and non\-technical stakeholders alike. * Strong verbal communication – able to clearly articulate complex technical information for technical and non\-technical audiences. * Comfortable with ambiguity – able to walk into a legacy system, figure out what's there, and design a better version. * Dependable and reliable, especially in a support rotation. * Curious and current – actively keeps up with new AI\-assisted engineering tools and knows how to apply them responsibly. **Eligibility Requirements** * You must already be authorized to work in the US, which we are required to confirm with e\-Verify * We are not accepting H1B/H1B transfer applicants at this time. * You must live/reside in one of these states: OR, WA, CA, AZ, MN, MI, LA, TX, DC * You must be willing to undergo a background check **Compensation \& Benefits** Salary range: commensurate with experience and level ($90k\-$105k) * Company\-paid medical, dental, and vision for employees and family members. * 401K with employer match up to 6%. * Life insurance policy. * Short\-term and long\-term disability coverage. * Paid holidays and generous vacation/sick leave. * Flexible work environment. To apply, please submit a resume and cover letter and carefully, thoughtfully answer all of the questions we have posted on the job listing. We're excited to meet you! Job Type: Full\-time Pay: $90,000\.00 \- $105,000\.00 per year Benefits: * 401(k) * 401(k) matching * Dental insurance * Flexible schedule * Health insurance * Life insurance * Paid time off * Parental leave * Vision insurance Application Question(s): * What are your salary expectations for this role? * Write 1 \-2 paragraphs explaining why you are a good fit for this role, emphasizing your experience with deploying and managing AWS infrastructure. * Do you currently live in one of these US locations? Applicants will only be considered if they live in one of these states. * Oregon * Washington * California * Arizona * Minnesota * Michigan * Louisiana * Texas * District of Columbia Experience: * AWS Deployment and System Management: 2 years (Required) Language: * English (Required) Work Location: Remote

Get jobs like this in your inbox

A free weekly email with new remote jobs from the board. Unsubscribe from any email.

Before you apply

Similar Jobs

GitLab Inc

Support Engineer, U.S. Government Support

GitLab Inc
$95k – $161kYesterday
NetApp

Principal Software Engineer, Data Processing OSS

NetApp
$228k – $339kYesterday
NetApp

Sr. Software Engineer, Data Processing OSS

NetApp
$196k – $293kYesterday
CommandLink

Staff Software Engineer, Alerting Platform

CommandLink
$150k – $190kYesterday
General Dynamics Information Technology

Cloud Hosting Engineer

General Dynamics Information Technology
$109k – $147kYesterday
Maximus

IT Senior Architect - DevSecOps

Maximus
$160k – $239kYesterday
Blattner Company

Senior Mechanical Engineer - Gas Power Generation

Blattner Company
$101k – $146kToday
R1 RCM

Senior Manager, Process Engineering

R1 RCM
$100k – $145kYesterday
BV Teck

Advanced Software Engineer

BV Teck
$100k – $150kYesterday
Pax8

Staff Software Engineer - Fintech

Pax8
$225k – $325kYesterday