Role Focus & Technical Matrix:
Zero Trust & Identity: Monitoring Zscaler connectors, HashiCorp & Vault basic secret updates.
Infrastructure as Code: Running pre-written Terraform plans, Git PR workflows, fundamental CloudFormation playbooks.
Security & Compliance: FedRAMP baselines, sorting Wiz/Qualys vulnerability alerts, basic CrowdStrike endpoint checks
Observability & Ops: Grafana dashboard upkeep, CloudWatch metrics, ServiceNow ticketing, shadow on-call protocols
Zero Trust & Identity Operations
● Assist in monitoring Zero Trust Network Access tools (Zscaler ZPA / PRA), verifying
application connectors and remote access pathways remain operational.
● Support secrets management workflows within HashiCorp Vault, including basic
credential generation, entry updates, and confirming automated rotations execute without
● Review basic IAM permissions and cloud role policies to ensure alignment with least-
privilege models under senior engineering review.
Infrastructure & Automation Support
● Run, test, and troubleshoot pre-defined Terraform modules across development and
staging environments in AWS, Azure, or GCP.
● Identify and log configuration drift or environment resource issues, assisting senior
engineers with standard infrastructure patching and remediation tasks.
● Review cloud security groups, public endpoint configurations, and basic network routes to cross-check them against compliance baselines.
CI/CD & Pipeline Maintenance
● Monitor and triage failing CI/CD pipeline runs within GitHub Actions, GitLab CI, or Azure
DevOps, escalating systemic errors to the team.
● Review automated security scan readouts (SAST, SCA, and container scans) embedded
● Assist in updating, building, and running security base-image layers for containers
(Docker) destined for managed Kubernetes clusters (EKS, AKS, GKE).
Compliance Monitoring & Change Administration
● Assist compliance with the programmatic gathering of audit evidence for ongoing
FedRAMP Continuous Monitoring (ConMon) cycles, specifically targeting CM-2, CM-6,
AU-2, and SC-12 controls.
● Assist with Plan of Action and Milestones (POA&M) ticket creation, tracking remediation
deadlines across the platform.
● Draft and submit technical change requests within ServiceNow, ensuring correct structural documentation for review by the Change Advisory Board (CAB).
Observability & Incident Support
● Maintain and adjust basic Grafana and CloudWatch dashboards, ensuring alert
notifications are mapped accurately to operational notification streams.
● Monitor standard system health indicators, performing low-severity alert triaging to
prevent production fatigue.
● Maintain open telemetry operations for ongoing application monitoring
● Participate in a shadow on-call rotation capacity (PagerDuty) alongside senior engineers
to develop live diagnostic and real-time incident resolution skills.