DevSecOps Engineer
Core
Design, implement, and automate secure CI/CD pipelines and DevSecOps processes for the VA Cybersecurity Operations Systems Engineering (COSE) program to integrate security throughout the software development lifecycle.
Role type
DevSecOps Engineer (IC)
Builds
Automated, secure software delivery pipelines and hardened cloud-native infrastructure for the US Department of Veterans Affairs
Domain
Government / Cybersecurity / Cloud Engineering
Deliverable
production ML models | product features | infrastructure
Required skills
CI/CD pipeline design, security automation, containerization, cloud-native architecture, vulnerability management, configuration management, source code version control, security assessment, incident response support, secure software development practices, supply chain security, SBOM management
Preferred skills
Infrastructure automation, API integration, workflow orchestration, security tool integration
Technologies
Git, CI/CD tools, container orchestration platforms, cloud platforms, configuration management frameworks, security scanning tools
Responsibilities
Design and optimize DevSecOps processes and CI/CD pipelines; Integrate security controls and gates into development and deployment pipelines; Automate security testing and compliance activities throughout the SDLC; Develop and maintain automated deployment scripts and configuration management solutions; Support secure implementation of containerized applications in cloud environments; Perform security assessments and vulnerability management for applications and infrastructure; Collaborate with cybersecurity engineers to translate requirements into automated technical controls; Review application designs to identify security risks and configuration weaknesses; Implement secure configuration baselines and automated controls; Support software supply-chain security and SBOM generation.
Seniority
Mid-level Engineer (Engineer, 3), hands-on IC