Overview
Skills
Job Details
Job Title: OpenShift Platform Engineer FIPS-Compliant Environment
Location: Remote
Job Summary:
We are seeking an experienced OpenShift Platform Engineer to design, deploy, and manage a RH OpenShift Container Platform 4 (OCP 4) environment that meets Federal Information Processing Standards (FIPS 140-2/140-3) compliance requirements. The ideal candidate will have a strong background in container orchestration, Linux system administration, and security hardening for federal or regulated environments.
Key Responsibilities:
Deploy, configure, and maintain RH OpenShift 4.x clusters in compliance with FIPS mode requirements.
Ensure all cluster components (RHCOS nodes, CoreOS images, container runtimes, and OpenShift services) are FIPS-validated or FIPS-compliant.
Implement secure configuration baselines aligned with NIST and DoD security guidelines.
Integrate FIPS-compliant cryptographic modules and validate configurations across the platform.
Collaborate with security, compliance, and DevOps teams to maintain continuous compliance and audit readiness.
Automate deployment and validation using Ansible, Helm, and CI/CD pipelines.
Troubleshoot cluster performance, networking, and security-related issues in a FIPS-enabled environment.
Maintain documentation and configuration records for FIPS and OCP compliance reporting.
Required Qualifications:
3 5 years of hands-on experience with RH OpenShift 4.x or Kubernetes in enterprise or federal environments.
Proven experience deploying and managing FIPS 140-2/140-3 compliant systems.
Strong knowledge of RHEL/RHCOS, Linux security, and container runtime security.
Familiarity with DoD STIGs, NIST 800-53, and DISA compliance frameworks.
Scripting and automation skills (e.g., Ansible, Bash, Python).
Experience with RH Advanced Cluster Management (ACM) and OpenShift GitOps (ArgoCD) is a plus.
Active Security Clearance or ability to obtain one preferred.
Preferred Certifications:
RH Certified Specialist in OpenShift Administration (EX280)
RH Certified Engineer (RHCE)
Security+ or CISSP