
DevSecOps Developer – RMF
Posted Sep 14

Posted Sep 14
This is a fully remote position, open to applicants in Virginia.
• Design, implement, manage, and troubleshoot secure cloud infrastructure and applications across development, testing, and production environments.
• Oversee Docker and Kubernetes environments, including tasks such as deployments, networking, configuration, storage, scaling, and upgrades.
• Create and maintain CI/CD pipelines that automate application builds, testing, security scanning, and deployment processes.
• Utilize Infrastructure as Code through Terraform, CloudFormation, Ansible, or similar technologies.
• Manage Linux systems and resolve issues across applications, containers, networks, operating systems, and cloud services.
• Establish monitoring, logging, alerting, backup, recovery, and operational automation capabilities.
• Enforce security baselines, DISA STIGs, patching requirements, least-privilege access, and secure configuration practices.
• Identify, prioritize, address, and document vulnerabilities and security findings.
• Assist with DoD RMF and ATO activities by creating and maintaining SSPs, POA&Ms, architecture diagrams, inventories, data flows, PPSM documentation, and remediation evidence.
• Collaborate with ISSOs, ISSMs, engineers, developers, and assessors to document NIST SP 800-53 control implementations and ensure accurate authorization packages are maintained.
• Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field.
• Four or more years of experience in DevOps, DevSecOps, cloud engineering, systems engineering, or a related discipline.
• Practical experience with Linux, Docker, Kubernetes, Git, and AWS, Microsoft Azure, or another major cloud platform.
• Proven experience in developing CI/CD pipelines.
• Experience in implementing Infrastructure as Code using Terraform, CloudFormation, or similar tools.
• Understanding of cloud networking, identity and access management, secrets management, encryption, monitoring, vulnerability management, patching, and system hardening.
• Familiarity with DoD RMF, the ATO lifecycle, NIST SP 800-53, DISA STIGs, security-control documentation, and POA&Ms.
• Strong troubleshooting, technical writing, communication, and teamwork skills.
• Experience supporting DoD or other federal information systems, including eMASS and RMF/ATO documentation.
• Familiarity with AWS GovCloud and Kubernetes platforms such as EKS, AKS, Rancher/RKE2, or Red Hat OpenShift.
• Experience with security and compliance tools such as Fortify, SonarQube, Snyk, Trivy, Nessus, ACAS, AWS Inspector, or SCAP.
• Security+, CISSP, SecurityX, AWS, Azure, CKA, CKS, or another relevant certification.
• Must be a U.S. citizen.
• Must be eligible to obtain and maintain the required U.S. Government security clearance and/or suitability determination.
• Must meet applicable DoD 8140 cybersecurity workforce qualification requirements.
• Comprehensive medical, dental, & vision insurance starting the first of the month after joining.
• 401(k) Plan with employer contributions that are immediately vested; no matching required.
• Generous Paid Time Off (PTO) policy.
• One additional day of paid wellness leave per calendar year.
• Ten federal holidays observed.
• Pet Insurance.
• Tuition reimbursement.
• Internal training programs.
• Company-sponsored industry certifications.
• Dynamic and collaborative work environment.
• Team building activities.
• Community volunteering.
• Quarterly HQ days.
• Wellness events.
• Happy hours.
• Family fun events.
FourEnergy GmbH
ICF
Mastercam
C&S Informática
Get handpicked remote jobs straight to your inbox weekly.