
DevSecOps Engineer
Posted Jul 27

Posted Jul 27
This is a fully remote position, open to applicants in Virginia.
• Design, implement, and sustain secure CI/CD pipelines that adhere to the DoD Enterprise DevSecOps Reference Design (DSOP).
• Automate the deployment of secure environments utilizing Terraform, Ansible, or CloudFormation for DoD or FedRAMP-compliant systems.
• Integrate static code analysis (SAST), dynamic testing (DAST), container scanning, and various security toolsets within pipelines to ensure ongoing compliance.
• Implement and manage DoD STIGs, DISA baselines, and RMF controls in Infrastructure as Code (IaC).
• Translate DoD security controls into automated enforcement and validation processes within development pipelines.
• Develop scripts and tools for compliance validation (e.g., OpenSCAP, Chef InSpec, PowerSTIG).
• Assist in the co-development and maintenance of technical documentation for RMF authorization and continuous monitoring processes.
• Implement and manage DevSecOps tools such as GitLab, Jenkins, ArgoCD, Harbor, Nexus, SonarQube, Anchore, and others.
• Automate container security measures and orchestrate deployments using Kubernetes (Big Bang, Iron Bank images, or similar).
• Oversee secret storage, credential rotation, and logging utilizing Vault, DoD-approved KMS, or AWS Secrets Manager.
• Collaborate closely with security, development, and operations teams to ensure alignment with DoD RMF, NIST SP 800-53, and/or FedRAMP.
• Engage with Information System Security Officers (ISSOs), Information Systems Security Managers (ISSMs), and Security Control Assessors in the development of ATO packages.
• Act as a primary internal subject matter expert in federal compliance standards and cybersecurity practices.
• Bachelor’s degree in Computer Science or a related field (or equivalent experience).
• Over 7 years of hands-on experience with DevSecOps in AI/ML or data-intensive systems.
• Familiarity with security hardening for OpenShift or Kubernetes.
• Understanding of Zero Trust Architecture (ZTA) concepts.
• Proven track record in managing and successfully driving ATO processes.
• Expertise in DevSecOps tools, practices, and frameworks.
• Strong grasp of federal security compliance standards (e.g., NIST 800-53, RMF, FedRAMP).
• Practical experience with cloud environments (AWS, Azure, or GCP) and containerization (Docker, Kubernetes).
• Proficient scripting and automation skills (Python, Bash, or similar).
• Excellent leadership, communication, and documentation skills.
• Active security clearance or eligibility to obtain one.
• Medical, Dental, and Vision plans
• Unlimited PTO ⎯ Federal Holiday Paid Leave
• 12 weeks of paid Parental Leave
• Employer paid STD/LTD
• Employer Paid Life Insurance
• 401K plan and Employer Match Professional Development Assistance
• Equity Incentive Plan
DATAGROUP
Ambush
DuoKey
TEKsystems
Get handpicked remote jobs straight to your inbox weekly.