DevSecOps Engineer
Core
Embed security into every layer of the software development and infrastructure delivery lifecycle, owning CI/CD pipeline security and automating compliance for classified and unclassified environments.
Role type
DevSecOps Engineer
Builds
Secure CI/CD pipelines, automated compliance controls, hardened cloud/on-premise environments, and container security postures.
Domain
Defense technology, Cloud Security, DevSecOps
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
CI/CD pipeline security, container security hardening, infrastructure-as-code, security tooling integration, policy-as-code, scripting/programming, cloud security, vulnerability management
Preferred skills
NIST RMF ATO support, CMMC Level 2/3 practices, GitOps workflows, software supply chain security, classified/air-gapped environment operations
Technologies
GitHub Actions, GitLab CI, Jenkins, Terraform, CloudFormation, Ansible, Docker, Kubernetes, AWS GovCloud, Azure Government, OPA, Conftest, Secrets Manager, SonarQube, Checkmarx, Snyk, OWASP ZAP, Black Duck
Responsibilities
Design and maintain secure CI/CD pipelines with automated security scanning; automate security and compliance controls including STIG/SRG validation and policy-as-code; collaborate with engineers to remediate vulnerabilities and champion secure coding; build and manage container security posture including image hardening and Kubernetes configurations; design and maintain infrastructure-as-code with integrated security controls; support RMF/ATO activities by automating evidence collection and compliance reporting; monitor security tooling telemetry and produce trend reports; coordinate with ISSM/ISSO teams to align practices with authorization boundary requirements; evaluate and introduce new DevSecOps tooling and practices.
Seniority
Mid-Senior, hands-on IC