About the role
What will you do at Clarity?
Clarity Innovations is a trusted national security partner, dedicated to safeguarding our nation’s interests and delivering innovative solutions that empower the Intelligence Community (IC) and Department of Defense (DoD) to transform data into actionable intelligence, ensuring mission success in an evolving world.
Our mission-first software and data engineering platform modernizes data operations, utilizing advanced workflows, CI/CD, and secure DevSecOps practices. We focus on challenges in Information Warfare, Cyber Operations, Operational Security, and Data Structuring, enabling end-to-end solutions that drive operational impact.
We are committed to delivering cutting-edge tools and capabilities that address the most complex national security challenges, empowering our partners to stay ahead of emerging threats and ensuring the success of their critical missions. At Clarity, we are people-focused and set on being a destination employer for top talent, offering an environment where innovation thrives, careers grow, and individuals are valued.
Join us as we continue to lead innovation and tackle the most pressing challenges in national security.
Position Summary
The position is part of a team of software and platform engineers building a unified, multi-tenant control plane driven by Kubernetes, Crossplane, and Cluster API (CAPI), that abstracts infrastructure differences across AWS, Azure, on-premises, and air-gapped environments.
As a Senior Principal Platform Engineer, you will act as the critical technical bridge between compliance strategy and system execution. You will collaborate closely with the Information System Security Officer (ISSO) to ingest traditional security policy, governance frameworks (e.g., NIST SP 800-37/53, DoDI 8510.01), and control requirements, translating them into actionable solutions, code, automated pipelines, and continuous platform guardrails in concert with the engineering team.
Utilizing Go, Python, and cloud-native security tools, you will implement technical security controls, ranging from admission control and secrets management to zero-trust networking, ensuring the underlying infrastructure and control plane remain in an automated, continuously authorized state.
The ideal candidate is a seasoned platform engineer with deep cybersecurity domain knowledge who excels at automating compliance, streamlining secure software supply chains, and turning complex regulatory expectations into developer-friendly platform abstractions.
Key Responsibilities
- Policy-as-Code & Control Enforcement: Translate NIST 800-53 controls and ISSO policy into automated admission policies, cross-cloud guardrails, and real-time compliance checks using Policy-as-Code frameworks.
- Automated Evidence & ConMon: Build pipelines and telemetry dashboards to collect compliance evidence automatically and stream real-time reporting to tools like eMASS/XACTA to support the Authorization to Operate (ATO) lifecycle.
- Secure Supply Chain: Implement end-to-end supply chain controls within CI/CD pipelines, including automated SBOM generation, artifact signing, vulnerability scanning, and provenance tracking.
- Zero-Trust Infrastructure: Package and configure core security capabilities across IAM, secrets management, service mesh, and network segmentation to ensure robust zero-trust architecture.
- Cross-Team Alignment: Partner with software and platform engineers to turn security requirements into actionable backlog items and guide teams on implementing technical controls.
Qualifications
- Platform Security & Infrastructure: 5+ years of hands-on platform engineering experience, with deep technical expertise in cloud infrastructure and zero-trust architectures.
- Compliance Frameworks: Direct experience working with NIST SP 800-53, RMF (NIST SP 800-37), or FedRAMP, with a proven ability to translate control statements into software configurations.
- Software Automation & CI/CD: Proficiency in Go or Python, along with CI/CD pipeline automation (e.g., GitLab CI) and GitOps workflows.
- Supply Chain Security: Hands-on experience with vulnerability scanning, image signing, dependency management, and SBOM validation across cloud and air-gapped systems.
- Security Tooling: Experience with enterprise IAM, secrets management platforms (e.g., HashiCorp Vault), and automated policy engines.
- Active DoD Top Secret Clearance.
Preferred Qualifications
- Active security or cloud certifications (e.g., CISSP, CCSP).
- Experience automating Continuous ATO (cATO) in air-gapped or heavily regulated environments.
- Salary Range: $150,000 - $330,000
- We are an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.
Which skills does this role require?
Make your next move
Build a shortlist and prepare
Identify the requirements you can demonstrate, then choose examples from your work to discuss with the hiring team.
- Build a focused shortlist before you applyCompare role requirements with your experience and give each application a clear reason.
- Backend engineering jobsCompare current openings and review what to look for in this role.
- Platform engineering jobsCompare current openings and review what to look for in this role.
- Practice explaining your experience in an interviewRehearse your answers before meeting the hiring team.
Other roles to compare
Review the responsibilities and requirements before adding an opening to your shortlist.
Back End Data Architect and Engineer, Senior
Booz Allen Hamilton · Annapolis Junction, Maryland, United States
Senior AI Platform Engineer (Data and Analytics Cloud Engineer)
Truist · Atlanta, Virginia, United States
Cloud Database Platform Engineer
Echelon Services, LLC · Clayton, Ohio, United States
Multi-Cloud Engineer SME (Azure/Identity) - Ft Belvoir, VA
JCS Solutions LLC · Fort Belvoir, Virginia, United States
Security Engineer - Infrastructure Security
Figure · San Jose, California, United States
Early Career - Cloud Engineer, Cloud Operations
Rivian · Atlanta, Georgia, United States
Role information can change. Confirm current details on the original application page.
