
DevSecOps Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Design, develop, maintain, and enhance DevSecOps processes along with CI/CD pipelines.
• Incorporate security measures and checkpoints within development and deployment workflows.
• Automate security evaluations, compliance tasks, and vulnerability remediation throughout the Software Development Life Cycle (SDLC).
• Create deployment scripts, workflows, configuration management solutions, and automation scripts.
• Provide support for cloud-native DevSecOps solutions while ensuring the security of containerized applications and workloads.
• Integrate cybersecurity tools and technologies into CI/CD pipelines and DevOps processes.
• Conduct and assist with security evaluations, vulnerability management, and responses to cybersecurity incidents.
• Oversee Git-based source code repositories, including branching, merging, change tracking, and controlled releases.
• Establish version-controlled, traceable, and reproducible processes for software and infrastructure delivery.
• Maintain automated traceability of requirements from cybersecurity controls through Authority to Operate (ATO).
• Collaborate with cybersecurity engineers, architects, developers, cloud engineers, administrators, government stakeholders, and other technical personnel.
• Assess designs for security vulnerabilities, control deficiencies, attack vectors, and configuration weaknesses.
• Implement secure configuration baselines and automate configuration and deployment procedures.
• Support software supply chain security, including SBOM generation or validation, malware assessments, code signing, and integrity checks.
• Create and present custom code, scripts, APIs, schemas, metadata, deployment artifacts, and technical documentation.
• Engage in design reviews, security assessments, modernization efforts, pilots, testing, and engineering working groups.
• Document DevSecOps architectures, pipelines, workflows, controls, procedures, configurations, deployments, and integrations.
• Generate technical documentation for audits and compliance activities and assist in addressing any identified issues.
• Align efforts with VA, government architecture, federal cybersecurity standards, DevOps, DevSecOps, cloud-native requirements, and Lean-Agile principles.
• May entail up to two onsite travel visits annually.
• At least 10 years of experience in DevSecOps, with a minimum of 5 years focused on Cybersecurity and Cloud Security in a large government agency comparable to GSA, IRS, DoD, or VA.
• Proficiency in DevSecOps or related domains, such as CI/CD pipelines, containerization, and cloud-native environments.
• Strong knowledge of software development along with familiarity with development methodologies, code repositories (e.g., Git), and version control systems.
• Expertise in cybersecurity roles, including conducting security assessments, vulnerability management, and incident response.
• Skilled in integrating security tools into DevOps pipelines and automating security testing and compliance processes.
• Bachelor’s degree in a relevant or related field (preferred/desired).
• Preferred/desired certifications include CASP+ (SecurityX), CCISO, CISA, CISM, CISSP, CISSP-ISSAP, CISSP-ISSEP, GCED, GCIH, GSLC, CCNP Security.
• Selected candidates will undergo a security investigation and may need to fulfill eligibility criteria for access to classified information.
• Medical insurance
• Dental insurance
• Vision insurance
• Voluntary Life Insurance
• 401(k)
• Basic Life A&D
• Short-term disability (STD)
• Long-term disability (LTD)
• Paid time off (PTO)
• Telehealth
• Paid holidays
• Flexible Spending Account (FSA)
• Health Savings Account (HSA)
• Employee Assistance Program (EAP)
• Traveling Assistance
Tether.to
CoorsTek, Inc.
Sigma Software Group
Tether.to
Get handpicked remote jobs straight to your inbox weekly.