Spatial Front, Inc. (SFI) is seeking an AI Platform Engineer (OCI Security) to support our growing modernization team. SFI was recently awarded the 2025 USA Today National Top Places to Work award and the 2025 Washington Post Top Workplaces. The ideal candidate will perform hands-on engineering to deploy, adapt, secure, and operate containerized artificial intelligence applications within Oracle Cloud Infrastructure (OCI) supporting PeopleSoft HCM and related enterprise systems.
This role requires a combination of cloud infrastructure, application security, container, networking, identity and access management, and software engineering skills. The candidate will work closely with AI developers, integration engineers, cybersecurity personnel, DevSecOps engineers, DBAs, and infrastructure teams to ensure AI applications can operate securely within hardened Federal and DoD cloud environments. This includes modifying application configuration, deployment patterns, authentication and authorization approaches, integrations, and supporting infrastructure as needed to meet security and operational requirements. As a valued member of the SFI team, you will help establish secure and scalable AI capabilities for mission-critical Federal Government systems.
Location
Crystal City, VA - On-Site/Hybrid
Responsibilities
- Design, deploy, configure, secure, and maintain AI application environments within Oracle Cloud Infrastructure (OCI).
- Adapt existing containerized applications and supporting services for deployment within secured and hardened OCI environments.
- Design and implement secure OCI networking including Virtual Cloud Networks (VCNs), private subnets, routing, Network Security Groups (NSGs), private endpoints, DNS, and connectivity to enterprise services and data sources.
- Implement and maintain identity, authentication, and authorization capabilities using OCI IAM and approved enterprise identity-management technologies.
- Work with application developers to modify authentication, authorization, session management, service identities, and application configuration as required to meet Federal and DoD security requirements.
- Design secure service-to-service communication between web applications, AI services, large language models, APIs, databases, integration services, and other enterprise resources.
- Deploy and support containerized applications using Docker, Kubernetes/Oracle Kubernetes Engine (OKE), OCI Container Registry (OCIR), or comparable container technologies.
- Configure and secure AI application access to approved LLM services, APIs, enterprise applications, databases, and other supporting services.
- Implement secure patterns for AI tool and data integrations, including controlled access to enterprise services and Model Context Protocol (MCP)-based connections where applicable.
- Apply least-privilege access, network segmentation, encryption, secrets management, certificate management, and other security controls across AI application environments.
- Configure and manage OCI Vault, keys, certificates, secrets, service credentials, and other sensitive application configuration.
- Develop and maintain Infrastructure as Code (IaC) using Terraform or comparable technologies to create repeatable, controlled, and auditable cloud environments.
- Integrate platform deployment with source control, CI/CD pipelines, automated builds, security scanning, artifact management, configuration management, and release processes.
- Configure application and infrastructure logging, monitoring, audit trails, metrics, alerts, and operational dashboards.
- Partner with cybersecurity teams to implement security controls, hardening requirements, vulnerability remediation, access restrictions, audit requirements, and other compliance measures.
- Troubleshoot issues across application configuration, OCI networking, IAM, containers, certificates, APIs, service connectivity, authentication, authorization, and cloud infrastructure.
- Participate in application and architecture reviews to identify security, deployment, networking, authentication, and integration changes needed for successful cloud implementation.
- Develop reusable platform standards, security patterns, Terraform modules, deployment templates, technical documentation, and operational procedures.
- Participate in Agile/SAFe activities including PI Planning, backlog refinement, technical reviews, demonstrations, testing, release readiness, and production support.
- Other duties as assigned.
- Must be a U.S. Citizen with an active Secret security clearance required
- Bachelor's degree in Computer Science, Information Systems, Cybersecurity, Engineering, or a related field; equivalent relevant experience may be considered.
- 5+ years of hands-on cloud infrastructure, platform engineering, DevSecOps, cloud security, application infrastructure, or related engineering experience in complex enterprise environments.
- Hands-on experience with Oracle Cloud Infrastructure (OCI), including networking, compute, IAM, storage, security, logging, monitoring, and cloud-native application services.
- Strong knowledge of cloud networking including VCNs/VPCs, subnets, routing, DNS, security groups, firewalls, private endpoints, service connectivity, and hybrid connectivity.
- Strong knowledge of identity and access management, authentication, authorization, least-privilege access, service identities, secrets management, certificates, and encryption.
- Experience deploying and supporting containerized applications using Docker and Kubernetes/OKE or comparable technologies.
- Experience working with web application architectures and understanding how application authentication, authorization, APIs, services, and infrastructure interact.
- Experience modifying application configuration, deployment architecture, or supporting code to meet cloud security, networking, identity, or operational requirements.
- Experience using Terraform or another Infrastructure as Code technology to provision and manage cloud infrastructure.
- Experience with CI/CD, source control, automated builds, vulnerability scanning, logging, monitoring, and modern DevSecOps practices.
- Strong troubleshooting skills across application, cloud, container, networking, IAM, and integration layers.
Desired Skills
- Experience deploying or securing artificial intelligence, generative AI, machine learning, or data-intensive applications in OCI or another enterprise cloud environment.
- Experience with OCI Generative AI, OCI Generative AI Agents, OCI Data Science, or related Oracle AI services.
- Experience with OCI IAM policies, dynamic groups, resource principals, identity domains, OAuth/OIDC, API authentication, and service-to-service authorization.
- Experience with OCI Vault, Certificates, Cloud Guard, Security Zones, Logging, Monitoring, private endpoints, and related OCI security services.
- Experience with Oracle Kubernetes Engine (OKE), OCI Container Registry (OCIR), OCI Functions, and API Gateway.
- Experience integrating containerized applications with large language models, APIs, databases, enterprise services, or AI tool frameworks.
- Familiarity with Model Context Protocol (MCP), AI agent tool integration, or comparable approaches for securely connecting AI applications to enterprise systems and data sources.
- Experience securing web applications that require changes to commercial or enterprise authentication and authorization patterns to operate within hardened environments.
- Knowledge of AI-specific security concerns including prompt injection, excessive permissions, sensitive-data exposure, insecure tool access, and service-to-service authorization.
- Working knowledge of Python, Bash, PowerShell, OCI CLI, OCI SDKs, or comparable scripting and automation technologies.
- Experience working in Agile or SAFe environments and using Azure DevOps (ADO) or a similar lifecycle-management tool.
- Experience supporting secured Federal or DoD enterprise systems is preferred.
- OCI Architect, OCI Security, Kubernetes, Terraform, cloud security, or related certification is a plus.
Additional Information
- Clearance: Must be a U.S. Citizen with an active Secret security clearance.
- Work Environment: Onsite/Hybrid as required by the contract.
- This is a full-time, W2 position.
- No agencies, third parties, or Corp-to-Corp submissions.
- Spatial Front Inc. is an Equal Opportunity Employer — all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status.
- SFI participates in E-Verify.