Federal IT Engineering & Cleared Talent

We deliver
mission-ready systems
& the people who build them.

CDOS Group pairs hands-on federal engineering — DevSecOps, cloud, and secure platforms — with vetted, cleared technical talent. Built by practitioners who ship in DoD and GovCloud environments every day.

28+ yrsfederal IT experience
GovCloudNIPR · SIPR ready
End-to-endbuild · secure · deliver
delivery-pipeline · main
Engineerplatform · cloud · code
✓ ready
Securescan · harden · comply
✓ ready
IntegrateCI/CD · GitOps
✓ ready
Delivercontinuous · to the mission
✓ ready
What we do

Engineering depth across the federal stack.

From platform foundations to the security controls that get you to an ATO — we work in the same trenches your program lives in.

DevSecOps & Platform Engineering

CI/CD pipelines, GitOps delivery, and Kubernetes platforms engineered for speed without sacrificing control.

GitLab CIArgoCDHelmKubernetes

Cloud & Infrastructure

EKS and infrastructure-as-code in AWS GovCloud — resilient, repeatable, and built for the compliance bar.

AWS GovCloudEKSTerraformCrossplane

Identity & Access

PKI/CAC integration, federated SSO, and truststore management aligned to DoD identity requirements.

KeycloakDoD PKIOIDCCAC

Observability & Compliance

Metrics, logs, and vulnerability reporting wired in from day one — visibility that holds up to an audit.

GrafanaTrivyLokiRMF

Systems Integration & Middleware

Stitching legacy and modern systems together — data pipelines, APIs, and middleware that just work.

IntegrationAPIsDataMigration

Cleared Talent Placement

Pre-vetted engineers with active clearances, matched to your program — staff augmentation or full delivery teams.

Public TrustSecretTS/SCI
Two ways to work with us

For the programs that need delivery — and the engineers who deliver it.

For Federal Clients

A subcontracting partner that ships.

Whether you need a delivery team or specialized engineers to fill a gap, CDOS Group plugs into your contract vehicle and gets to work — no ramp-up theater.

  • Subcontracting & teaming for prime contractors
  • Staff augmentation with cleared engineers
  • DevSecOps & cloud modernization delivery
  • Small business — pursuing SBA 8(a) certification
Request capability statement →
For Cleared Talent

Work that matters, with people who get it.

We're engineers placing engineers. That means real technical screening, honest conversations about the role, and advocacy that doesn't stop at the offer letter.

  • Roles across DevSecOps, cloud & platform engineering
  • Active clearance? We'll match you to the mission
  • 1099 / contract & full-time opportunities
  • A recruiter who can actually read your résumé
Submit your résumé →
Open Positions

Cleared technical roles — engineers built for the mission.

We're engineers placing engineers. Every role below is active or opening soon on programs across DoD and federal civilian agencies. Clearance requirements are firm; technical bar is high.

DevSecOps

Senior DevSecOps Engineer

🔒 TS/SCI📍 On-Site / Hybrid · NOVA📄 Contract

Support a DoD program's CI/CD and platform delivery on AWS GovCloud. You'll own pipeline architecture, GitOps workflows, and the toolchain that keeps the mission running — not just maintain it.

Location

On-Site / Hybrid — Northern Virginia (NOVA). SIPR access requires working from a cleared facility. NIPR-only tasks may be performed remotely; on-site presence required for classified network work. Local candidates strongly preferred.

Responsibilities

  • Design, build, and maintain CI/CD pipelines using GitLab CI and ArgoCD across multiple EKS clusters
  • Manage Helm chart development and GitOps delivery patterns via a DSO-HELMS style repository
  • Implement and maintain container security scanning (Trivy, Grype) integrated into the pipeline
  • Collaborate with security teams on vulnerability reporting, remediation, and ATO evidence collection
  • Maintain Kubernetes platform health, upgrades, and cluster configurations on AWS GovCloud (us-gov-west-1)
  • Support observability stack (Grafana, Mimir, Loki, Alloy) — dashboards, alerts, and log pipelines
  • Participate in incident response and on-call rotation

Requirements

  • Active TS/SCI clearance — required, non-negotiable
  • 5+ years of hands-on DevSecOps / platform engineering experience
  • Production experience with Kubernetes (EKS preferred) and Helm
  • Proficiency in GitLab CI/CD, ArgoCD, and GitOps delivery patterns
  • AWS GovCloud experience — IAM, EKS, ECR, Secrets Manager, IRSA
  • Scripting in Bash and/or Python; comfortable in a Linux terminal environment
  • Understanding of DoD security controls, RMF, and STIGs

Nice to Have

  • Experience with Istio service mesh and Kong gateway
  • Familiarity with Keycloak, DoD PKI/CAC, and federated identity
  • AWS certifications (SAA, DVA, or Security Specialty)
  • Experience on NIPR/SIPR environments
Cloud · Platform

Cloud Platform Engineer (Kubernetes / EKS)

🔒 Secret📍 Remote / Hybrid · NOVA📄 Contract

Own the Kubernetes and AWS infrastructure layer for a federal program. You'll manage cluster lifecycle, cloud networking, and infrastructure-as-code on AWS GovCloud — with a security posture that has to hold up to an audit.

Location

Remote / Hybrid — Northern Virginia (NOVA). Majority of work is remote on NIPR infrastructure. Periodic on-site visits to the NOVA area may be required for program reviews, clearance-related activities, or SIPR work. Local or relocatable candidates preferred.

Responsibilities

  • Manage EKS cluster provisioning, upgrades, and lifecycle (Bottlerocket FIPS nodes preferred)
  • Build and maintain infrastructure-as-code using Terraform and/or Crossplane
  • Design and manage AWS networking: VPCs, security groups, NACLs, VPC endpoints
  • Implement IRSA, pod identity, and least-privilege IAM patterns
  • Maintain ECR image lifecycle policies and image mirroring pipelines
  • Support Node-level hardening (FIPS, STIGs, Bottlerocket OS)
  • Contribute to infrastructure documentation and runbooks

Requirements

  • Active Secret clearance (TS preferred)
  • 4+ years of cloud infrastructure / platform engineering experience
  • Deep AWS experience — EKS, EC2, VPC, IAM, ECR, Secrets Manager
  • Terraform proficiency — modules, state management, remote backends
  • Kubernetes administration including upgrades, add-ons, and autoscaling
  • AWS GovCloud familiarity — partition differences, compliance considerations

Nice to Have

  • Crossplane experience
  • Bottlerocket or FIPS-compliant AMI management
  • Experience with CoreDNS tuning and NodeLocal DNSCache
  • AWS Solutions Architect certification
Identity · IAM

Identity & Access Management (IAM) Engineer

🔒 Secret📍 On-Site / Hybrid · NOVA📄 Contract

Own identity and access for a federal platform — DoD PKI/CAC authentication, federated SSO, and truststore management. You understand the JKS/PKCS12 world and can navigate DoD CA cert changes without breaking production.

Location

On-Site / Hybrid — Northern Virginia (NOVA). CAC/PKI integration and SIPR identity management require on-site access to classified systems at a cleared facility. NIPR configuration work may be performed remotely.

Responsibilities

  • Configure and maintain Keycloak for DoD CAC/PIV authentication using OIDC and SAML
  • Manage DoD CA truststore updates across Keycloak, Java-based services, and application containers
  • Implement and troubleshoot federated SSO across NIPR environments
  • Manage PKI certificates and secret rotation using AWS Secrets Manager and External Secrets Operator
  • Coordinate with security teams on identity-related ATO controls and audit evidence
  • Document IAM architecture, certificate management procedures, and runbooks

Requirements

  • Active Secret clearance (TS preferred)
  • 3+ years of IAM / identity engineering experience in a federal environment
  • Keycloak or comparable IdP experience (Okta, PingFederate)
  • DoD PKI, CAC/PIV authentication, and certificate chain management
  • OIDC, SAML 2.0, and OAuth 2.0 — implementation level, not just theory
  • AWS Secrets Manager, Kubernetes secrets, and External Secrets Operator
  • Familiarity with Java keystores (JKS, PKCS12) and CA cert management

Nice to Have

  • Experience with SIPR identity management and cross-domain considerations
  • DoD 8570 / 8140 IAM certification (CAP, CISSP, CISM)
  • Keycloak extension development or theme customization
Security · RMF

Information System Security Officer (ISSO)

🔒 Secret📍 Hybrid / NOVA📄 Contract

Support ATO and continuous monitoring for a DoD platform on AWS GovCloud. You'll own the RMF package, manage POA&Ms, and work directly with the platform engineering team to translate compliance requirements into real controls.

Location

Hybrid — Northern Virginia (NOVA). ATO briefings, SIPR system reviews, and eMASS work require periodic on-site access at a cleared facility. Documentation, continuous monitoring, and coordination tasks can be performed remotely.

Responsibilities

  • Own and maintain the system security plan (SSP) and ATO package for a cloud-native DoD platform
  • Manage POA&Ms, security control assessments, and continuous monitoring activities
  • Coordinate with engineering teams to implement and validate NIST SP 800-53 controls
  • Conduct vulnerability scanning (Tenable/Nessus, Trivy) and track remediation
  • Support STIG compliance reviews for containers, OS, and application layers
  • Prepare and present security status briefs to the ISSM and AO
  • Maintain artifacts in eMASS or equivalent GRC tool

Requirements

  • Active Secret clearance
  • 3+ years as an ISSO or in an RMF support role on a federal system
  • Working knowledge of NIST SP 800-53, NIST SP 800-37, and the RMF process
  • eMASS experience — creating, maintaining, and submitting ATO packages
  • DoD 8570 / 8140 IAT Level II or higher (Security+, CySA+, CISSP)
  • Familiarity with cloud security in AWS — understanding of shared responsibility model

Nice to Have

  • AWS Security Specialty certification
  • Experience with container security and Kubernetes STIG implementation
  • FedRAMP familiarity and cloud ATO experience
  • CISSP or CISM certification
Integration · Middleware

Systems Integration Engineer

🔒 Secret📍 Remote / Hybrid · NOVA📄 Contract

Connect legacy and modern federal systems — APIs, data pipelines, and middleware that move data reliably between systems that weren't designed to talk to each other. You solve the hard integration problems that don't show up in documentation.

Location

Remote / Hybrid — Northern Virginia (NOVA). Most integration and middleware work is performed remotely on NIPR systems. On-site presence at a NOVA cleared facility may be required for SIPR pipeline work or production support.

Responsibilities

  • Design and implement system integrations between legacy and cloud-native federal applications
  • Build and maintain REST and SOAP API integrations, message queues, and event-driven pipelines
  • Support CDC (Change Data Capture) pipelines using Kafka, Debezium, or similar
  • Manage middleware platforms (Pentaho, MuleSoft, or comparable) in containerized environments
  • Troubleshoot data pipeline failures, connector issues, and database connectivity in production
  • Document integration architecture, data flows, and operational runbooks

Requirements

  • Active Secret clearance
  • 4+ years of systems integration or middleware engineering experience
  • REST and SOAP API design and implementation
  • Experience with message brokers — Kafka, RabbitMQ, or ActiveMQ
  • SQL and database connectivity — Oracle, PostgreSQL, or similar
  • Containerized middleware deployment — Docker and Kubernetes
  • Comfort working across teams and in systems where documentation is sparse

Nice to Have

  • Debezium CDC connector experience
  • Kafka Streams or ksqlDB
  • Pentaho Carte / Data Integration experience
  • ClickHouse or other OLAP database experience

Don't see your role? We're always looking for cleared engineers with federal IT depth.

Submit your résumé →
Who we are

CDOS Group is built on a simple idea: the best people to deliver federal systems are the ones who've spent careers building them.

We're a minority-owned small business operating as CDOS Group — the commercial brand of YZA LLC. Our roots run through roughly 28 years of federal IT: systems integration, software and cloud engineering, DevSecOps, and middleware across NIPR and SIPR environments.

That practitioner background shapes how we work — incremental, secure, and accountable to the mission. We don't resell buzzwords; we deliver systems, and we place the talent who can keep delivering them.

Legal EntityYZA LLC (dba CDOS Group)
State of FormationVirginia
UEI[ add UEI ]
CAGE Code[ add CAGE ]
Primary NAICS541512 + add
Business SizeSmall Business
OwnershipMinority-Owned Small Business
8(a) StatusIn pursuit
Get in touch

Let's talk delivery.

Requesting a capability statement, exploring a teaming arrangement, or sending us your résumé — we read every message and reply quickly.

Emailinfo@cdosgroup.com
Mailing address215 N Payne Street, Alexandria, VA 22314
Phone(703) 721-7924
C:\>
C:\>
C:\>
C:\>
C:\>

Opens your email client with the message pre-filled. Connect a form backend later to capture submissions directly.