
DevSecOps Engineer – RMF
Posted Sep 14

Posted Sep 14
This is a fully remote position, open to applicants in Virginia.
• Design, implement, maintain, and troubleshoot secure cloud infrastructures and applications across development, testing, and production environments.
• Manage Docker and Kubernetes environments, encompassing deployments, networking, configuration, storage, scaling, and upgrades.
• Create and sustain CI/CD pipelines for application builds, testing, security scanning, and deployment.
• Execute Infrastructure as Code using Terraform, CloudFormation, Ansible, or similar technologies.
• Oversee Linux systems and resolve issues related to applications, containers, networks, operating systems, and cloud services.
• Establish monitoring, logging, alerting, backup, recovery, and operational automation capabilities.
• Implement security baselines, DISA STIGs, patching requirements, least-privilege access, and secure configuration practices.
• Identify, prioritize, correct, and document vulnerabilities and security findings.
• Assist with DoD RMF and ATO activities by developing and maintaining SSPs, POA&Ms, architecture diagrams, inventories, data flows, PPSM documentation, and remediation evidence.
• Collaborate with ISSOs, ISSMs, engineers, developers, and assessors to document NIST SP 800-53 control implementations and uphold accurate authorization packages.
• Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field.
• A minimum of four years of experience in DevOps, DevSecOps, cloud engineering, systems engineering, or a related discipline.
• Practical experience with Linux, Docker, Kubernetes, Git, and AWS, Microsoft Azure, or another major cloud platform.
• Experience in developing CI/CD pipelines.
• Experience in implementing Infrastructure as Code using Terraform, CloudFormation, or similar tools.
• Understanding of cloud networking, identity and access management, secrets management, encryption, monitoring, vulnerability management, patching, and system hardening.
• Familiarity with DoD RMF, the ATO lifecycle, NIST SP 800-53, DISA STIGs, security-control documentation, and POA&Ms.
• Strong skills in troubleshooting, technical writing, communication, and collaboration.
• Must be a U.S. citizen.
• Must be eligible to obtain and maintain the required U.S. Government security clearance and/or suitability determination.
• Must meet the applicable DoD 8140 cybersecurity workforce qualification requirements.
• Comprehensive medical, dental, and vision insurance starting the first of the month following your start date.
• 401(k) plan with immediate vesting of employer contributions; no matching required.
• Generous Paid Time Off (PTO).
• One additional day of paid wellness leave each calendar year.
• Ten federal holidays.
• Pet insurance.
• Tuition reimbursement.
• Internal training programs.
• Company-sponsored industry certifications.
• Team building activities.
• Community volunteering.
• Quarterly HQ days.
• Wellness events.
• Happy hours.
• Family fun events.
• Dynamic and collaborative work environment.
FourEnergy GmbH
ICF
Mastercam
C&S Informática
Get handpicked remote jobs straight to your inbox weekly.