Site Reliability Engineer
United States · Remote
- Posted 4d ago
- From BeyondTrust’s careers page
- Location
- United States
- Work mode
- Remote
- Department
- Engineering
Opens the listing on job-boards.greenhouse.io
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.
About the role
The Role
BeyondTrust is building a new cross-product Site Reliability Engineering team that stands up and runs the AWS GovCloud environments bringing additional BeyondTrust products into our FedRAMP authorization. The team owns the reliability, change control, and continuous-compliance machinery for those environments so that product feature teams can stay focused on product delivery.
This is an engineering team that owns operations, not an operations team. Its product is automation; operations is the input. Every manual procedure performed twice is a candidate for elimination, and the team’s success is measured by the operational work it has made unnecessary, not the tickets it has closed. Hands-on operational work is capped at roughly half of team capacity; the rest goes to engineering the work away.
Our workloads are not purely cloud-native. The estates include appliance-model and single-tenant VM fleets at scale alongside shared services, so fleet upgrade orchestration, golden images, and staged rollouts are core work, not edge cases.
What You’ll Do
- Build and operate AWS GovCloud environments: multi-account structure, guardrails, logging and security tooling, IaC-native provisioning (Terraform)
- Build and run release and update machinery for cloud fleets: mandatory security updates, staged and jittered rollout windows, coordinated installs, and verification that a patch actually landed everywhere it was scoped to
- Build the continuous-compliance evidence pipeline: collection, normalization, and reporting of FedRAMP 20x Key Security Indicators, where evidence is machine-readable, re-verified every few days, and reported monthly
- Instrument production: telemetry, SLOs, dashboards, and alerting that the team and product engineering actually own and act on
- Consolidate CI/CD: shared pipelines for build, signing, artifact management, quality gates, and security scanning instead of per-team reinvention
- Participate in on-call for the GovCloud estate, with the explicit expectation that recurring incident causes get engineered away
What You’ll Bring
- Build and operate AWS GovCloud environments: multi-account structure, guardrails, logging and security tooling, IaC-native provisioning (Terraform)
- Build and run release and update machinery for cloud fleets: mandatory security updates, staged and jittered rollout windows, coordinated installs, and verification that a patch actually landed everywhere it was scoped to
- Build the continuous-compliance evidence pipeline: collection, normalization, and reporting of FedRAMP 20x Key Security Indicators, where evidence is machine-readable, re-verified every few days, and reported monthly
- Instrument production: telemetry, SLOs, dashboards, and alerting that the team and product engineering actually own and act on
- Consolidate CI/CD: shared pipelines for build, signing, artifact management, quality gates, and security scanning instead of per-team reinvention
- Built or operated inside a FedRAMP Moderate or High boundary (or IL4/IL5, StateRAMP equivalent): continuous monitoring, POA&M lifecycle, patch SLAs, 3PAO engagement
- AWS GovCloud specifically; multi-account landing zones; FIPS endpoints and crypto modes
- VM fleet or appliance-model operations at scale, not only Kubernetes
- Telemetry and data pipeline ownership (OTEL, Grafana-class stacks)
- Compliance-as-code and evidence automation (OSCAL, machine-readable ConMon, AWS Config rules or OPA at scale)
- Test and verification engineering: building the harnesses that prove a fleet is in the state the paperwork says it is
Working Details
- Location: US-based, remote. This role works inside a FedRAMP boundary; standard US-person requirements for federal environments apply.
- Reports to the SRE Manager, within the VP of Application Engineering’s organization.
Skills they ask for
Pick one to see other roles that ask for it.
About BeyondTrust
Identity and access securityBeyondTrust provides identity and access security products for protecting human, machine, and AI identities.
See all 17 roles at BeyondTrustMore roles at BeyondTrust
See all 17- Business Development RepresentativeBoston · HybridSales · HybridBoston, United States10h
- Manager, FP&A - R&DUnited States · RemoteFinance and Accounting · RemoteUnited States1d
- Business Development RepresentativeBoston · Entry Level · HybridBusiness Development · Entry Level · HybridBoston, United States2d
- Sr Site Reliability EngineerUnited States · Senior · RemoteEngineering · Senior · RemoteUnited States2d
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.