DevSecOps Engineer - Government
Core
Own secure code integration across the software delivery lifecycle, ensuring software is securely built, tested, packaged, and deployed into Government and customer environments including classified and air-gapped systems.
Role type
Senior DevSecOps Engineer (Government/Defense)
Builds
Secure CI/CD pipelines, reusable pipeline templates, hardened build environments, and automated security controls in AWS GovCloud.
Domain
Defense & Government contracting, Cloud Security, DevSecOps
Deliverable
production ML models | infrastructure
Required skills
CI/CD pipeline ownership, SAST/DAST/SCA/secrets/container scanning integration, policy-as-code (OPA/Rego, cfn-guard, Cedar), AWS GovCloud services (Config, Security Hub, IAM, KMS, CloudTrail, EventBridge), infrastructure-as-code (Terraform, Ansible, CDK, CloudFormation), Python/Bash/Go scripting, container orchestration (Docker, Kubernetes), NIST 800-53/800-171/DISA STIGs/CMMC Level 2 compliance, audit evidence production, threat modeling, secure software supply chain (SBOM, artifact signing).
Preferred skills
CISSP/CSSLP/CKS/AWS Security Specialty certifications, DoD software factory experience (Platform One, Iron Bank, Big Bang), hardware-isolated runtimes (Kata Containers, gVisor), classified/air-gapped environment deployment, SLSA/SSDF/CycloneDX/SPDX frameworks, FedRAMP/DoD Impact Level 4/5 authorization, AI/ML workload security.
Responsibilities
Define and enforce promotion gates and severity thresholds for security findings; troubleshoot findings and pair with developers on remediation; automate system hardening and compliance evidence collection; implement preventive and detective controls in AWS GovCloud; support software promotion into classified and air-gapped environments; lead threat modeling and security design reviews; map technical controls to NIST/DISA/CMMC requirements; establish secure development guidance and repeatable engineering patterns.
Seniority
Senior, hands-on IC