Post a job

Site Reliability Engineer

Remote United States only

BeyondTrust is a place where you can bring your purpose to life through the work that you do, creating a safer world through our cybersecurity SaaS portfolio.

Our culture of flexibility, trust, and continual learning means you will be recognized for your growth, and for the impact you make on our success. You will be surrounded by people who challenge, support, and inspire you to be the best version of yourself.

The Role

BeyondTrust is building a new cross-product Site Reliability Engineering team that stands up and runs the AWS GovCloud environments bringing additional BeyondTrust products into our FedRAMP authorization. The team owns the reliability, change control, and continuous-compliance machinery for those environments so that product feature teams can stay focused on product delivery.

This is an engineering team that owns operations, not an operations team. Its product is automation; operations is the input. Every manual procedure performed twice is a candidate for elimination, and the team’s success is measured by the operational work it has made unnecessary, not the tickets it has closed. Hands-on operational work is capped at roughly half of team capacity; the rest goes to engineering the work away.

Our workloads are not purely cloud-native. The estates include appliance-model and single-tenant VM fleets at scale alongside shared services, so fleet upgrade orchestration, golden images, and staged rollouts are core work, not edge cases.

What You’ll Do

  • Build and operate AWS GovCloud environments: multi-account structure, guardrails, logging and security tooling, IaC-native provisioning (Terraform)
  • Build and run release and update machinery for cloud fleets: mandatory security updates, staged and jittered rollout windows, coordinated installs, and verification that a patch actually landed everywhere it was scoped to
  • Build the continuous-compliance evidence pipeline: collection, normalization, and reporting of FedRAMP 20x Key Security Indicators, where evidence is machine-readable, re-verified every few days, and reported monthly
  • Instrument production: telemetry, SLOs, dashboards, and alerting that the team and product engineering actually own and act on
  • Consolidate CI/CD: shared pipelines for build, signing, artifact management, quality gates, and security scanning instead of per-team reinvention
  • Participate in on-call for the GovCloud estate, with the explicit expectation that recurring incident causes get engineered away

What You’ll Bring

  • Build and operate AWS GovCloud environments: multi-account structure, guardrails, logging and security tooling, IaC-native provisioning (Terraform)
  • Build and run release and update machinery for cloud fleets: mandatory security updates, staged and jittered rollout windows, coordinated installs, and verification that a patch actually landed everywhere it was scoped to
  • Build the continuous-compliance evidence pipeline: collection, normalization, and reporting of FedRAMP 20x Key Security Indicators, where evidence is machine-readable, re-verified every few days, and reported monthly
  • Instrument production: telemetry, SLOs, dashboards, and alerting that the team and product engineering actually own and act on
  • Consolidate CI/CD: shared pipelines for build, signing, artifact management, quality gates, and security scanning instead of per-team reinvention
  • Built or operated inside a FedRAMP Moderate or High boundary (or IL4/IL5, StateRAMP equivalent): continuous monitoring, POA&M lifecycle, patch SLAs, 3PAO engagement
  • AWS GovCloud specifically; multi-account landing zones; FIPS endpoints and crypto modes
  • VM fleet or appliance-model operations at scale, not only Kubernetes
  • Telemetry and data pipeline ownership (OTEL, Grafana-class stacks)
  • Compliance-as-code and evidence automation (OSCAL, machine-readable ConMon, AWS Config rules or OPA at scale)
  • Test and verification engineering: building the harnesses that prove a fleet is in the state the paperwork says it isParticipate in on-call for the GovCloud estate, with the explicit expectation that recurring incident causes get engineered away

Working Details

  • Location: US-based, remote. This role works inside a FedRAMP boundary; standard US-person requirements for federal environments apply.
  • Reports to the SRE Manager, within the VP of Application Engineering’s organization.

Better Together

Diversity. Inclusion. They’re more than just words for us. They are the guiding values of how we build our teams, cultivate leaders, and create a culture where people feel connected.

We take care of our employees so they can take care of our customers. Customers who come from all walks of life just like us. We hire incredible people from diverse backgrounds because when we are different together, we are stronger together.

About Us

BeyondTrust is the global identity security leader protecting Paths to Privilege™. Our identity-centric approach goes beyond securing privileges and access, empowering organizations with the most effective solution to manage the entire identity attack surface and neutralize threats, whether from external attacks or insiders.

BeyondTrust is leading the charge in transforming identity security to prevent breaches and limit the blast radius of attacks, while creating a superior customer experience and operational efficiencies. We are trusted by 20,000 customers, including 75 of the Fortune 100, and our global ecosystem of partners.

Learn more at www.beyondtrust.com. 

#LI-BS1

Source: the employer's careers page. Last checked 2026-10-05. Posted 2026-10-05.

Applications happen on BeyondTrust's own site. View role and apply

Similar jobs

Hiring for a role like this? See how employers fill a role fast.