About the role
What will you do at Lumbee Tribe Holdings, Inc.?
Position Title
Automation / Cloud Services Engineer
Position Classification:
Exempt
Position Type:
This is a full-time position scheduled to work standard business hours from 8:00 a.m. to 5:00 p.m. Occasional work outside standard hours may be required to support scheduled maintenance windows, deployments, test events, or critical incident response.
Work Location
Marine Corps Tactical Systems Support Activity (MCTSSA), 31 Area, Marine Corps Base Camp Pendleton, CA
Position Description
The Automation / Cloud Services Engineer supports the Marine Corps Tactical Systems Support Activity (MCTSSA) Infrastructure and Information Services Division (I2SD) by designing, deploying, and maintaining secure private, hybrid, and multi-cloud infrastructure that hosts critical Command, Control, Communications, Computers, Cyber, and Intelligence (C5I) applications for engineering, test, and experimentation.
The individual is responsible for installing, configuring, patching, and administering the VMware Cloud Foundation (VCF) private cloud (vSphere, vSAN, NSX, and Aria Suite) in a Department of War (DoW) IL5-compliant environment, enforcing NSX micro-segmentation to realize Zero Trust objectives, and maintaining continuous compliance with DISA STIGs.
The engineer architects and implements resilient hybrid-cloud and container-orchestration frameworks (such as Kubernetes, Tanzu, and OpenShift) spanning on-premises private clouds and DoW-approved public clouds (AWS, Azure, and GCP), and provisions multi-tenant virtual machines, containerized workloads, and serverless architectures across development, test, and production enclaves in accordance with DoW Secure Cloud Computing guidelines.
The individual builds and maintains an Infrastructure-as-Code (IaC) and configuration management framework using Ansible, Terraform, and CI/CD pipelines to automate provisioning, configuration compliance, and application deployment, committing all source code daily to the Government Git/GitLab repository.
The engineer provides continuous monitoring, governance, and cost optimization of hybrid-cloud infrastructure to sustain greater than 99.9% availability, and produces version-controlled documentation, blueprints, and README files that allow the Government to rebuild any environment from bare metal to operational status.
The role also supports assigned test events, contributes to System Security Plans (SSPs) and related cybersecurity documentation, and provides technical representation at working groups and meetings as required.
Essential Position Functions:
* Five years of hands-on experience designing, deploying, and administering enterprise virtualization and cloud infrastructure, preferably within DoD/DoW environments.
* Hands-on experience installing, configuring, patching, and administering VMware Cloud Foundation (VCF) components, including vSphere, vSAN, NSX, and Aria Suite, and implementing NSX micro-segmentation policies.
* Experience architecting, deploying, and securing container-orchestration platforms such as Kubernetes, VMware Tanzu, or Red Hat OpenShift, including hardening containers to the DoW Container Hardening Guide.
* Experience designing and operating secure, multi-tenant hybrid and multi-cloud architectures in at least one DoW-approved public cloud (AWS, Azure, or GCP), including cloud-native and on-premises service meshes for secure service-to-service communication.
* Proficiency developing, testing, and maintaining declarative automation code (Ansible playbooks, Terraform configurations) for network devices (Arista and Cisco switches), virtual hosts, and operating systems.
* Experience building and maintaining CI/CD pipelines and source control workflows using Git/GitLab to automate testing and deployment.
* Administrator-level knowledge of Windows Server, Red Hat Enterprise Linux, and VMware ESXi, including patching, DISA STIG hardening, and integration with enterprise storage, backup systems, and Active Directory/LDAP services.
* Working knowledge of Zero Trust Architecture principles (NIST SP 800-207) and DoW IL5/IL6 cloud security requirements.
* Experience using cloud monitoring suites to track resource utilization, scale instances to handle traffic spikes, cost-optimize resources, and maintain high availability (greater than 99.9%).
* Proficiency in scripting languages such as Python, PowerShell, and Bash to automate repetitive tasks.
* Familiarity with the Risk Management Framework (RMF) and developing System Security Plans (SSPs) and related cybersecurity documentation.
* Strong written and verbal communication skills, including the ability to produce clear, version-controlled technical documentation, system blueprints, and operational guides, and to explain complex technical topics to non-technical audiences.
* Possess a DoD 8140-compliant certification appropriate for privileged system access (e.g., CompTIA Security+ CE or higher) upon onboarding.
* Possess one of the following certifications upon onboarding:
* VMware Certified Professional – VMware Cloud Foundation Administrator (VCP-VCF Admin)
* AWS Certified Solutions Architect – Associate
* Microsoft Certified: Azure Administrator Associate
* Certified Kubernetes Administrator (CKA)
* Red Hat Certified Engineer (RHCE)
* Obtain one of the following certifications within 9 months of onboarding:
* HashiCorp Certified: Terraform Associate
* Certified Kubernetes Security Specialist (CKS)
* AWS Certified Solutions Architect – Professional
* Microsoft Certified: Azure Solutions Architect Expert
Competencies for the role
The Automation / Cloud Services Engineer demonstrates advanced expertise in private, hybrid, and multi-cloud architecture, virtualization, and container orchestration within secure DoW environments. This role requires an automation-first mindset, with the ability to translate manual processes into repeatable Infrastructure-as-Code and CI/CD workflows that reduce provisioning time and eliminate configuration drift.
The individual applies Zero Trust and DISA STIG requirements to every layer of the environment, troubleshoots complex issues methodically, and documents work so thoroughly that the Government can reconstruct any environment independently.
Physical Requirements for the role
This position is primarily sedentary and requires the ability to work at a computer for extended periods, including viewing monitors, using keyboards, and operating standard office equipment. The role requires occasional standing and walking in server rooms and data center environments, and occasional lifting of IT equipment up to 25 pounds.
Reports To
Assigned Program Manager
Supervisory responsibilities
None
Work Environment: The work environment for this position is primarily a professional office, laboratory, and data center setting at a secure government facility with standard business conditions. The role involves regular use of computers and related technology, access to classified and unclassified enclaves, and frequent collaboration with government, military, and contractor technical and non-technical team members.
Work is generally performed during normal business hours with minimal physical risk, and the environment requires adherence to established cybersecurity, safety, and organizational policies, including MCTSSA standard operating procedures.
Security Clearance Requirements
Secret. Candidates must possess an active SECRET clearance and maintain it throughout employment. This position may be designated IT-I or IT-II, which requires a favorably adjudicated Tier 5 or Tier 3 investigation, respectively.
Travel Requirements
Travel is anticipated to be up to 10% within the Continental United States (CONUS) to support test events, deployments, and other mission requirements. Occasional travel outside the Continental United States (OCONUS) may be required. All travel must be preapproved in writing by the Contracting Officer's Representative (COR).
Compensation
Salary will be determined based on the individual's education and experience level.
Lumbee Holdings is an Equal Opportunity Employer. We do not discriminate in employment based on race, color, religion, sex (including pregnancy, sexual orientation, or gender identity), national origin, age, disability, protected veteran status, or any other status protected by applicable federal, state, or local law.
Lumbee Holdings reserves the right to share applications and related candidate information with its subsidiaries, affiliates, teaming partners, subcontractors, and prime contractors for purposes of evaluating candidates for this and other current or future openings.
Note: This summary is not intended to be a complete description of all benefits. Employees will receive detailed information about benefit plan terms, conditions, and eligibility during onboarding. These statements are intended to describe the general nature and level of work involved for this job.
It is not an exhaustive list of all responsibilities, duties, and skills required of this job.
Which skills does this role require?
Make your next move
Build a shortlist and prepare
Identify the requirements you can demonstrate, then choose examples from your work to discuss with the hiring team.
- Build a focused shortlist before you applyCompare role requirements with your experience and give each application a clear reason.
- Practice explaining your experience in an interviewRehearse your answers before meeting the hiring team.
Other roles to compare
Review the responsibilities and requirements before adding an opening to your shortlist.
AI Evaluations Engineer, US Decision Intelligence
Apple · Cupertino, California, United States
AI Outcome Customer Engineer, Forward Deployed Engineering
Google · Atlanta, Georgia, United States
Orchestration Workload Engineer - ACE - AI Factory
Roche · Kaiseraugst, Aargau, Switzerland
AI Risk Engineer
Bright Vision Technologies · Columbus, Ohio, United States
Research Engineer, Responsible Frontier AI Research, DeepMind
Google · New York, New York, United States
Senior Principal Engineer, Enterprise Networking Architecture, Automation and AI
Equinix · Toronto, Ontario, Canada
Role information can change. Confirm current details on the original application page.
