
DevSecOps – Cloud Engineer
Posted Aug 6

Posted Aug 6
This is a fully remote position, open to applicants in United States.
• Develop and sustain CI/CD pipelines within the specified CWBI GitHub Enterprise environment.
• Automate compliance checks for DoD STIG and conduct ACAS/SCAP vulnerability scans throughout the development pipeline; integrate results into DISA STIG Viewer and eMASS.
• Assist in the remediation of vulnerabilities according to established timelines: Immediate for Critical/High, 60 days for Moderate, and 120 days for Low.
• Transition applications from on-premises hosting to the USACE CWBI Cloud in line with a Cloud-Smart approach.
• Design solutions utilizing the highest possible abstraction of cloud services, including SaaS and PaaS, and microservices when applicable.
• Deploy applications using CWBI PMO-sanctioned hardened images, ideally Iron Bank images.
• Facilitate inventory management, risk-tagging, and documentation of AI/ML systems, models, and datasets within the Civil Works Data Catalog, including model cards and data lineage records.
• Ensure that AI/ML development and training occur within the RMF-authorized AWS GovCloud environment and manage CUI in accordance with established policies.
• Collaborate with the CWBI support team to implement standardized identity providers such as Login.gov, OpenID, and Keycloak.
• Engage in two-week Agile sprint cycles and contribute to release planning and demonstrations.
• U.S. Citizenship is required.
• A minimum of an active Tier 1 (or higher) federal background investigation, favorably adjudicated, prior to commencement.
• Ability to obtain a CAC if required by job responsibilities.
• Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent experience.
• At least 5–7 years of experience in DevSecOps, cloud engineering, or information security.
• Proficiency in modern DevSecOps pipelines and tools, including GitHub repositories.
• Experience with cloud architecture, migration, and modernization, preferably with AWS GovCloud.
• Proven experience in implementing secure coding principles and DoD STIGs throughout a CI/CD pipeline.
• Knowledge of implementing and documenting AI/ML solutions in accordance with DoD governance principles.
• Experience with microservices architecture and hardened/Iron Bank container images is preferred.
• Background in federal government or DoD cloud/cybersecurity programs is preferred.
• AWS certification is preferred, such as Solutions Architect or Security Specialty.
• Familiarity with Dublin Core and OpenAPI data cataloging standards is preferred.
• CompTIA Security+ or a DoD 8140-approved equivalent is required within six months of contract start.
• (ISC)² CISSP or EC-Council Certified DevSecOps Engineer (ECDE) is desired for senior/lead positions.
• Competitive salary and performance-based bonuses.
• Comprehensive health, dental, and vision insurance plans.
• Retirement savings plan with company match.
• Opportunities for professional development and training.
• Flexible work arrangements to promote work-life balance.
SPD Technology
Totara
Vesta Software Group
Elfonze Technologies
Get handpicked remote jobs straight to your inbox weekly.