
DevSecOps Project Lead – Sr DevSecOps Engineer
Posted Aug 2

Posted Aug 2
This is a fully remote position, open to applicants in United States.
• In the role of DevSecOps Lead, you will design and manage the delivery platform for a new AI-driven initiative within a government cloud setting: this includes the CI/CD pipeline, the underlying infrastructure, the integrated security measures, and the artifacts generated by the pipeline to facilitate authorization.
• This position is a leadership role that remains hands-on. You will make architectural decisions and also implement them directly.
• Security is embedded from the outset rather than being an afterthought: the pipeline implements hardened baselines, conducts scans, and generates control evidence with every commit.
• As the program progresses, you will lead a small team of platform, cloud, and cyber engineers, serving as the engineering liaison to the customer's security and accreditation personnel.
• We require someone who can start immediately. An initial deliverable necessitates establishing a functional platform in the government environment by a specific date, with cloud accounts, network access, credentials, and authorized service and image lists aligning with the government's timeline rather than our own.
• Over 8 years of experience in DevOps and DevSecOps engineering, including at least one production pipeline managed end-to-end at scale.
• A minimum of 3 years of experience in DoW or federal cloud environments at IL-4 or IL-5, or in an equivalent authorized setting. Preference will be given to candidates with AWS GovCloud experience.
• Hands-on leadership is essential. You will make architectural decisions and execute them; this role does not involve mere coordination or oversight.
• Deep knowledge of cloud and infrastructure: proficiency with containers and orchestration (Docker, Kubernetes or similar), infrastructure as code (Terraform, CloudFormation, or similar), and CI/CD tools on at least one major cloud platform, including the use of hardened base images and image promotion.
• Experience with observability practices: you will instrument your builds and utilize metrics and logs to foster improvements, rather than waiting for incident reports.
• Security integrated into delivery: you will consider security scanning, compliance validation, and evidence generation as standard stages within the pipeline.
• Direct experience in supporting an ATO, cATO, or similar authorization, including the creation of artifacts that assessors will accept.
• A proven history of establishing systems under tight deadlines in scenarios where access, approvals, and accounts were beyond your control. You have successfully delivered a first deployment into a government environment by a set date, with an understanding of the necessary preparatory actions.
• Prepared from day one. The initial deliverable is due early, so we need someone who arrives with a proven pipeline pattern ready to adapt, rather than starting from scratch.
• A strong sense of ownership: you complete tasks, communicate status and risks clearly, and do not require micromanagement.
• US Citizenship is mandatory.
• An active US Secret clearance is required. The role takes place in a controlled government cloud environment and necessitates a favorable investigation and CAC eligibility from the outset.
• Willingness to travel up to 25% to customer locations, DEFCON AI HQ, and vendor facilities as necessary.
• A fully remote, results-driven work environment.
• Competitive salary, bonus, and equity package.
• Comprehensive health insurance, including medical, dental, and vision coverage for you and your family, fully paid by the employer.
• Unlimited PTO, subject to manager approval.
• A flexible work environment allowing you to manage your workday efficiently.
• 14 weeks of fully-paid parental leave.
DATAGROUP
Ambush
DuoKey
TEKsystems
Get handpicked remote jobs straight to your inbox weekly.