Steve Clark

Principal DevSecOps Engineer & Infrastructure Security Architect

๐Ÿ“ Sarasota, FL

DevSecOps Subject Matter Expert with 25+ years in IT infrastructure, cloud security, and platform engineering. Deep expertise designing and operating secure, hardened cloud platforms across AWS GovCloud, Azure Public/Government, and GCP. Proven record leading large-scale datacenter-to-cloud migrations, achieving sustained SOC 2 and PCI compliance, and implementing zero-trust security architectures in highly regulated federal and enterprise environments. Known for operationalizing DISA STIG compliance pipelines, driving DevSecOps cultural adoption, and delivering mission-critical platforms with 99.99%+ availability.

Experience

Senior DevSecOps Engineer

Jan 2024 โ€“ Present
SAP ยท Remote
  • Architect and manage production of 600+ unique DISA-hardened golden images monthly across 7 cloud platforms โ€” AWS, Azure Public, Azure Government, GCP, OpenStack, and additional sovereign cloud environments.
  • Own the end-to-end golden image pipeline from security requirements through automated build, compliance validation, and release using HashiCorp Packer and Concourse CI.
  • Enforce DISA STIGs, CIS benchmarks, and internal SAP security controls through automated compliance pipelines.
  • Replaced legacy bash-based hardening workflows with Ansible, improving consistency and auditability across all 7 cloud platforms.
  • Lead and mentor a team of 8 engineers responsible for image lifecycle, vulnerability remediation, and secure release management.
  • Supported development of a FIPS-hardened SAP BTP Cloud Foundry stemcell built for sovereign cloud deployments.

Owner

2017 โ€“ Present
Clark IT Consulting

Independent consultancy run alongside full-time engineering roles, helping Operations and Engineering teams โ€” largely in the federal government space โ€” adopt automation and CI/CD pipelines for infrastructure and application releases.

Director of Operations

Oct 2018 โ€“ Sep 2023
Airside Mobile ยท Remote
  • Architected and operated a multi-account AWS GovCloud environment supporting Mobile Passport and Airside Digital Identity, maintaining 99.99% uptime across SLA-bound production systems.
  • Led the full migration of the Mobile Passport platform from a traditional datacenter to AWS GovCloud.
  • Designed and deployed a Docker-based platform on HashiCorp Nomad, Consul, and Vault for zero-trust secrets management across multiple environments.
  • Standardized infrastructure provisioning via Terraform and built CI/CD pipelines on Jenkins and CircleCI.
  • Achieved and sustained multiyear SOC 2 compliance and kept AWS Security Hub scores above 90%.

Principal DevOps Engineer

Jul 2016 โ€“ Oct 2018
TSA Secure Flight โ€” DHS ยท Annapolis Junction, MD
  • Championed and drove DHS approval and adoption of HashiCorp Vault, Terraform, and Packer in a highly regulated, air-gapped federal environment โ€” the agency's first DevOps implementation.
  • Implemented full Chef infrastructure in an air-gapped network, enforcing standardized OS security baselines across AIX and Red Hat.
  • Developed Terraform plans for IBM PowerVC and VMware vSphere for consistent, auditable infrastructure.

Sr. Systems Administrator / Staff Systems Administrator

Sep 2011 โ€“ Jun 2016
Neustar ยท Sterling, VA
  • Migrated 1,000+ critical systems to a private cloud environment using PXE and Kickstart automation.
  • Led the company's first Big Data (Hadoop/HIVE) deployment โ€” 40 nodes, 2 petabytes of storage.
  • Developed and maintained infrastructure Chef cookbooks and introduced continuous deployment via improved Kickstart and Chef bootstrap workflows.
  • Implemented TACACS+ and LDAP access integration on Cisco MDS fiber switches, centralizing authentication across data centers.

Earlier Experience

1997 โ€“ 2011

Network Operations, Storage Engineering, and Telecommunications roles at NeuStar, Inc. (2004โ€“2011). Sr. Technical Support Engineer โ†’ Enterprise Systems Administrator, Electronic Health Information (1997โ€“2001).

Skills

Cloud Platforms

AWS GovCloud & Commercial Azure Public/Gov GCP OpenStack

Security & Compliance

DISA STIGs SOC 2 PCI-DSS CIS Benchmarks Zero-Trust Architecture

Infrastructure as Code

Terraform Packer Ansible Chef

Secrets & Identity

HashiCorp Vault IAM LDAP TACACS+

CI/CD & Pipelines

Concourse CI Jenkins CircleCI GitOps

Containers & Orchestration

Docker HashiCorp Nomad Consul

Operating Systems

RHEL IBM AIX Sun Solaris CentOS OEL

Monitoring & HA

AWS Security Hub DR Planning 99.99% Uptime Design

Certifications

Red Hat Certified Systems Administrator (RHCSA)

Red Hat
2013

ITILยฎ v3 Foundation Certificate

IT Service Management
2013

AWS Cloud Practitioner

Amazon Web Services
2023

AWS Cloud Quest: Cloud Practitioner

Amazon Web Services
2023

AWS Cloud Quest: Solutions Architect

Amazon Web Services
2023

AWS Cloud Quest: Networking

Amazon Web Services
2023

AWS Cloud Quest: Security

Amazon Web Services
2023

HP Virtual Connect / HP SIM & Insight Control

HP
2012

MCSE โ€” Windows 2000

Blue Ridge Community and Technical College

Contact

Reach out at steve@bigsteve.us, connect on LinkedIn, or find my code on GitHub.