DevSecOps Engineer
Core
Senior DevSecOps Engineer leading integration of security practices into development and operations to support federal compliance and DoD Authorization to Operate (ATO) processes.
Role type
Senior hands-on IC DevSecOps Engineer
Builds
Secure CI/CD pipelines, DoD-compliant cloud infrastructure, and automated compliance validation tools
Domain
US Government / Defense (DoD) / Cloud Security
Deliverable
production ML models | infrastructure
Required skills
DoD DevSecOps Reference Architecture, secure CI/CD implementation, Defense cloud environments (AWS GovCloud, Azure Government), RMF compliance, Infrastructure as Code (Terraform, Ansible, CloudFormation), SAST/DAST integration, container security, Kubernetes security hardening, Zero Trust Architecture, ATO process management, Python/Bash scripting
Preferred skills
OpenShift, NIST SP 800-53, FedRAMP, government contracting experience, CKA, AWS Certified Security, HashiCorp Terraform Associate
Technologies
Terraform, Ansible, CloudFormation, GitLab, Jenkins, ArgoCD, Harbor, Nexus, SonarQube, Anchore, Kubernetes, Vault, OpenSCAP, Chef InSpec, PowerSTIG, Docker
Responsibilities
Design and maintain secure CI/CD pipelines aligned with DoD Enterprise DevSecOps Reference Design; Implement and manage DoD STIGs, DISA baselines, and RMF controls in IaC; Automate container security and orchestrate deployments; Manage secret storage, credential rotation, and logging; Collaborate with ISSOs and ISSMs for ATO package development.
Seniority
Senior, hands-on IC