
Cybersecurity Engineer – DevSecOps
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in District of Columbia, +2 more states.
• Assist with cybersecurity, software assurance, and security engineering initiatives within a DoD/DoN context.
• Embed cybersecurity practices throughout the software development and delivery lifecycle.
• Execute vulnerability assessments for code and containers utilizing DoD scanning tools, DISA STIGs, SRGs, and software assurance instruments.
• Establish and evaluate security configurations for operating systems.
• Conduct cybersecurity evaluations, security audits, and risk assessments.
• Utilize SAST and DAST testing methodologies across the software development lifecycle.
• Analyze and enforce cybersecurity policies and security controls within CI/CD pipelines.
• Act as a GitLab security reviewer and approver for merge requests.
• Inspect GitLab SAST, dependency, secret detection, and container scanning results; coordinate remediation and monitor findings until resolution.
• Assess GitLab security policies, pipeline controls, and protected branch settings.
• Offer cybersecurity oversight for containerized workloads utilizing NeuVector.
• Partner with application and platform teams to investigate findings, refine policies, and document remediation or accepted risks.
• Ensure that security requirements in system acquisition and program documentation address cybersecurity mandates.
• Provide cybersecurity advice and develop mitigation strategies for DoD information systems.
• Prepare RMF artifacts and Memoranda of Agreement with system owners.
• Identify and assess Common Criteria and NIAP-certified technologies.
• Review cybersecurity products and technologies for compliance with DoD/DoN standards.
• Collaborate with engineering, development, platform, and program teams.
• Assist in business development through technical interviews, documentation, proposal writing, and proposal color reviews.
• Active Secret clearance.
• Bachelor's degree with 8 years of relevant experience, or a high school diploma/equivalent with 13 years of relevant experience.
• Familiarity with the DoD Risk Management Framework (RMF) and knowledge of DoDI 8510.01.
• IAM Level II certification in accordance with DoD 8570.01-M, such as CISSP, GSLC, or CISM.
• Knowledge of DoD cybersecurity requirements, including DISA STIGs and SRGs.
• Proficiency with SAST and DAST software security testing methodologies.
• Experience supporting cybersecurity initiatives in CI/CD or DevSecOps frameworks.
• Experience with GitLab security tools and processes, including reviewing security scan results and facilitating vulnerability remediation.
• Residing in or near a major U.S. Navy installation.
• Willingness to engage in extended periods of sitting and working on a computer.
• Capability to lift weights up to 10–15 pounds at once.
• Comprehensive health and wellness programs.
• Opportunities for professional development and training.
• Flexible work arrangements.
• Competitive salary and performance-based bonuses.
Horizon3.ai
CLOUD MANTA GmbH
Stefanini LATAM
Akamai Technologies
Get handpicked remote jobs straight to your inbox weekly.