DevSecOps Engineer
Core
Embed security into every layer of software development and infrastructure delivery lifecycle for defense products serving warfighters and border protection teams.
Role type
DevSecOps Engineer
Builds
Secure CI/CD pipelines, automated compliance controls, hardened cloud/on-premise environments, and container security posture.
Domain
Defense technology, Cloud Security, DevSecOps
Deliverable
production ML models | infrastructure
Required skills
CI/CD pipeline security, automated compliance and vulnerability checks, container security hardening, infrastructure-as-code security, policy-as-code enforcement, security toolchain integration, threat modeling, secrets management, cloud security architecture, security automation scripting
Preferred skills
Shift-left security initiative leadership, secure coding practices championing, RMF/ATO support automation, security telemetry monitoring, new DevSecOps tooling evaluation
Technologies
GitHub Actions, GitLab CI, Jenkins, Terraform, CloudFormation, Ansible, Docker, Kubernetes, AWS GovCloud, Azure Government, SAST/DAST/SCA tools (SonarQube, Checkmarx, Snyk, OWASP ZAP, Black Duck), OPA, Conftest, Secrets Manager
Responsibilities
Design and maintain secure CI/CD pipelines with integrated automated security scanning; Automate security and compliance controls including STIG/SRG validation and policy-as-code; Collaborate with engineers to triage vulnerabilities and champion secure coding; Build and manage container security posture including image hardening and Kubernetes configurations; Design and maintain infrastructure-as-code with integrated security controls; Support RMF/ATO activities by automating evidence collection and compliance reporting; Monitor security tooling telemetry and produce trend reports; Coordinate with ISSM/ISSO teams to align practices with authorization boundary requirements; Evaluate and introduce new DevSecOps tooling and operationalize security automation.
Seniority
Mid-Senior, hands-on IC