
DevSecOps Engineer
Posted Aug 11

Posted Aug 11
This is a fully remote position, open to applicants in United States.
• Analyze the complete communication workflow involving Salesforce, S-Docs, AWS, and VA Notify.
• Review S-Docs HTML/PDF template creation, data dependencies, automation triggers, and governance controls.
• Assess AWS Lambda processing capabilities, queuing strategies, dead-letter queues, and monitoring functionalities.
• Confirm scalability, security controls, auditability, observability, and alignment with federal compliance standards.
• Document observations, architectural choices, risks, issues, data flows, sequences, design factors, and decision logs.
• Develop and enhance Salesforce data models, integration components, error-handling mechanisms, and orchestration.
• Implement API Gateway endpoints, Lambda functions, SQS/DLQ queuing, logging and monitoring pipelines, and Salesforce delivery-result services.
• Automate configuration management, secrets management, and access controls in accordance with federal security baselines and least-privilege principles.
• Embed SAST, DAST, and SCA security scanning within CI/CD pipelines.
• Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or a related field, or equivalent professional experience.
• Experience in DevOps/DevSecOps or software integration engineering roles.
• Proficient in Salesforce development with Apex, Flow/Process Builder, Lightning Web Components, and REST/SOAP or Bulk API integration patterns.
• Familiarity with Salesforce document generation/templating tools such as S-Docs or Conga, including HTML/PDF template design, data dependencies, and automation triggers.
• Experience in building serverless AWS integrations using API Gateway, Lambda, SQS/DLQ patterns, and CloudWatch for monitoring and alerting.
• Proven experience in designing or supporting high-volume, fault-tolerant integration pipelines, focusing on throughput, API limits, and latency.
• Practical knowledge of integrating SAST, DAST, and SCA into build and release pipelines.
• Understanding of NIST SP 800-53, RMF, FISMA, and federal Assessment & Authorization/ATO processes.
• Experience with automated testing, including high-volume/load testing of 50,000+ transactions and regression test automation.
• Proficient in deploying through CI/CD pipelines across development, QA, UAT, and production environments, using tools such as GitLab CI, Jenkins, or Azure DevOps.
• Scripting and automation skills in Python, Bash, and/or PowerShell.
• Excellent written communication abilities and capacity to create solution documentation for both technical and government audiences.
• U.S. citizenship required, with eligibility to obtain and maintain a Public Trust clearance/favorable suitability determination.
• Preferred: Experience with VA Notify or similar notification-as-a-service.
• Preferred: Familiarity with VA program experience and VA Handbook/Directive 6500, VA TRM, and VA ProPath SDLC.
• Preferred: Salesforce and/or AWS certifications.
• Preferred: Knowledge of federal GRC/ATO tools such as eMASS or Xacta.
• Preferred: Experience with SIEM and log management tools such as Splunk or ELK Stack.
• Preferred: Understanding of Section 508 accessibility standards and testing tools.
• Preferred: Proficiency in Docker, Kubernetes/OpenShift, and Infrastructure as Code tools like Terraform, Ansible, or CloudFormation.
• Preferred: Agile/Scrum experience on federal contracts.
• Competitive compensation and benefits package.
• Support for professional development, including reimbursement for certifications and training.
• Chance to contribute to a mission that positively impacts Veterans and their families.
• Collaborative, security-focused engineering culture with an emphasis on automation and modern tools.
DATAGROUP
Ambush
DuoKey
TEKsystems
Get handpicked remote jobs straight to your inbox weekly.