
DevSecOps Project Lead, Senior
Posted Aug 2

Posted Aug 2
This is a fully remote position, open to applicants in United States.
• In the role of DevSecOps Lead, you will be responsible for constructing and managing the delivery platform for a new AI-driven initiative within a government cloud setting: the CI/CD pipeline, the infrastructure it operates on, the integrated security measures, and the artifacts generated by the pipeline to facilitate authorization.
• This is a leadership position that requires hands-on involvement. You will make architectural decisions and also implement them.
• Take ownership of the initial platform deployment into the government IL-5 environment, which constitutes the program's first contract deliverable and is scheduled for an early launch.
• Develop and validate the pipeline and infrastructure as code in our own cloud first, utilizing portable templates, ensuring that deployment into the government environment is a straightforward port rather than a complex build.
• Manage the CI/CD pipeline from inception to completion: including building, testing, conducting static and dynamic security analyses, software composition analysis, container and infrastructure-as-code scanning, SBOM generation, and overseeing the gated promotion to production.
• A minimum of 8 years of experience in DevOps and DevSecOps engineering, with at least one production pipeline managed end to end at scale.
• At least 3 years of experience in DoW or federal cloud environments at IL-4 or IL-5, or a similar authorized setting. Preference for AWS GovCloud experience.
• Must be hands-on while leading. You will make architectural decisions and execute them; this position is not focused on coordination or oversight.
• Depth in cloud and infrastructure: familiarity with containers and orchestration (Docker, Kubernetes or equivalent), infrastructure as code (Terraform, CloudFormation, or similar), and CI/CD tools on at least one major cloud, including hardened base images and image promotion.
• Experience in observability practices: you will instrument your builds and leverage metrics and logs to drive enhancements, instead of waiting for incident reports.
• Integrating security into the delivery process: you will incorporate security scanning, compliance validation, and evidence generation as standard stages within the pipeline.
• Direct experience in supporting an ATO, cATO, or equivalent authorization, including providing the artifacts that an assessor will accept.
• Proven history of establishing a system under tight deadlines in environments where access, approvals, and accounts were beyond your control. You have successfully delivered a first deployment into a government setting by a specific date, understanding what needs to be arranged in advance to facilitate this.
• Prepared to contribute on day one. Since the first deliverable is early, we seek someone who arrives with a proven pipeline pattern ready to adapt, rather than needing to develop an approach from scratch.
• A proactive owner: you drive tasks to completion, communicate status and risks clearly, and do not require detailed management.
• US Citizenship is required.
• An active US Secret clearance is necessary. The work will take place in a controlled government cloud environment and demands a favorable investigation and CAC eligibility from the outset.
• Willingness to travel up to 25% to customer locations, DEFCON AI HQ, and vendor facilities as necessary.
• A fully remote, results-oriented work environment.
• Competitive salary along with bonus and equity options.
• Comprehensive health insurance paid 100% by the employer, covering medical, dental, and vision for you and your family.
• Unlimited PTO, subject to manager’s approval.
• A flexible work environment that allows you to manage your own workday.
• 14 weeks of fully-paid parental leave.
DATAGROUP
Ambush
DuoKey
TEKsystems
Get handpicked remote jobs straight to your inbox weekly.