
DevOps Engineer, Secret Clearance
Posted Jul 17

Posted Jul 17
This is a fully remote position, open to applicants in United States.
• Implement and uphold security measures throughout the development pipeline, ensuring that security is integrated into every stage of the software development lifecycle.
• Collaborate with Information System Security Officers (ISSOs) to evaluate Security Technical Implementation Guides (STIGs) and assist with Authority to Operate (ATO) processes, ensuring adherence to security standards and regulatory requirements.
• Design, implement, and manage secure CI/CD pipelines incorporating automated security testing, vulnerability assessments, and compliance checks within deployment workflows.
• Actively engage in Scrum ceremonies, including sprint planning, daily stand-ups, sprint reviews, and retrospectives, while offering security insights and effort estimates for security-related tasks.
• Conduct regular security evaluations, vulnerability scans, and penetration testing, coordinating remediation efforts with development teams.
• Develop and maintain secure infrastructure configurations using Infrastructure as Code principles, with automated enforcement of security policies.
• Implement and oversee security monitoring tools, logging systems, and incident response procedures to identify and respond to security threats in real time.
• Perform security risk assessments, threat modeling, and security architecture reviews to pinpoint and mitigate potential vulnerabilities.
• Create security documentation, procedures, and training materials while ensuring compliance artifacts are available for audit purposes.
• 4 years of experience and a Bachelor’s degree, or 8 years of experience.
• DoD Secret clearance or equivalent IAT Level II certification required (e.g., Security+ CE, CCNA-Security, GSEC, GICSP, SSCP, CySA+, or other DoD 8570.01-M / DoD 8140 approved certifications at IAT Level II).
• AWS - Experience specifically with AWS CDK and processes is preferred.
• Strong expertise in DevSecOps practices, security automation, and secure software development within enterprise settings.
• Comprehensive understanding of Scrum principles and Agile development practices, including the integration of security requirements into sprint planning and user story development.
• Extensive knowledge of STIGs, NIST frameworks, ATO processes, and federal security compliance requirements, with experience collaborating alongside ISSOs and security teams.
• Proficiency with CI/CD tools, preferably GitLab CI, as well as containerization technologies like Docker and Kubernetes, and automation platforms such as Terraform, Ansible, and CloudFormation.
• Experience with cloud security platforms and cloud-native security tools, with AWS Security Hub preferred.
• Proficiency in scripting languages, with JavaScript preferred, as well as Bash and PowerShell, with experience in security testing frameworks and static/dynamic analysis tools.
• Experience with vulnerability scanners (Nessus, OpenVAS), SAST/DAST tools, container security scanning solutions, and security orchestration platforms.
• Excellent communication skills, with the ability to collaborate effectively across cross-functional Scrum teams, security officers, compliance teams, and stakeholders in fast-paced development environments.
Quantiphi
NIR-YU
Bet On Talent
Zignaly
Get handpicked remote jobs straight to your inbox weekly.