Senior Engineer

atRaftRemoteUS flagTexasFull-timeFull-stack EngineerSenior$140k – $160k/year

Posted Sep 15

This is a fully remote position, open to applicants in Texas.

📋 Description

• Assist a DoW program by integrating Information Assurance, cybersecurity, and security engineering requirements into DevSecOps pipelines, tools, configurations, and software delivery processes.

• Collaborate with the Pipeline Architect, Software Engineering Subject Matter Experts (SMEs), infrastructure/platform engineers, and government stakeholders to ensure compliance with DoD cybersecurity standards.

• Convert DoD cybersecurity, RMF, and DevSecOps requirements into practical technical specifications.

• Design, implement, configure, and sustain automated security controls within CI/CD pipelines.

• Incorporate and manage SAST, DAST, SCA, container scanning, secrets detection, dependency scanning, and vulnerability management tools.

• Set up and enforce security gates and thresholds in GitLab CI/CD pipelines.

• Facilitate secure software supply chain methodologies, including artifact integrity, SBOM generation, vulnerability scanning, signing, provenance, and attestations.

• Integrate security tools such as Fortify, SonarQube, Trivy, Twistlock/Prisma Cloud, NeuVector, and Cosign/Sigstore into automated workflows.

• Assess Kubernetes, container, GitLab Runner, infrastructure-as-code, and pipeline configurations for security flaws and weaknesses.

• Assist in vulnerability triage and remediation efforts alongside software and platform engineering teams.

• Develop and sustain security-as-code and policy-as-code methodologies.

• Ensure compliance with the DoD DevSecOps Reference Design, NIST RMF, NIST 800-53 controls, and relevant DoD cybersecurity mandates.

• Automate the collection of security evidence for authorization and ongoing monitoring.

• Collaborate with platform and application teams on the UP continuous Authority to Operate and CD/CI processes.

• Identify cybersecurity risks and propose technical mitigations.

• Create security documentation, implementation guidance, configuration standards, and engineering best practices.

• Engage in architecture reviews, technical discussions, troubleshooting sessions, and security evaluations.


⛳️ Requirements

• This position is based in the U.S.; U.S. citizenship is required for employment, and all work must be performed within the continental U.S.

• A minimum of 3 years of experience in Cybersecurity Engineering, DevSecOps, Platform Engineering, Cloud Security, Application Security, or a related technical field.

• Practical experience in implementing security capabilities within CI/CD pipelines, preferably using GitLab CI/CD.

• Familiarity with application or container security technologies such as Fortify, SonarQube, Trivy, Twistlock/Prisma Cloud, NeuVector, or similar tools.

• Experience with containerized environments and understanding of Kubernetes security concepts.

• Proven experience in identifying, assessing, and remediating vulnerabilities in software, containers, infrastructure, or configurations.

• Working knowledge of DoD RMF, NIST SP 800-53, and DoD cybersecurity/Information Assurance requirements.

• Grasp of DevSecOps principles and the integration of security controls throughout the software development lifecycle.

• Experience with Git and infrastructure/configuration-as-code technologies such as Terraform, Ansible, Helm, or equivalent tools.

• Understanding of software supply chain security concepts, including SBOMs, artifact signing, provenance, vulnerability scanning, and attestations.

• Ability to translate cybersecurity requirements into effective technical controls and communicate clearly with cybersecurity and engineering stakeholders.

• An active Secret Clearance is required to start.

• Preferable experience with GitLab, GitLab Runners, Argo CD, Kubernetes, Helm, SOPS, AWS/GovCloud, Platform One, DoD software factories, and DoD cATO environments.

• A DoD 8140/8570-compliant cybersecurity certification such as Security+, CySA+, CASP+/SecurityX, CISSP, or equivalent is preferred.

• Certifications in Kubernetes, cloud security, or AWS are desirable.


🏝️ Benefits

• Highly competitive salary

• Comprehensive healthcare, dental, and vision coverage

• 401(k) plan with company matching

• Flexible PTO policy + 11 paid holidays

• Education and training benefits

• Generous referral bonuses

• And more!

People also viewed

Tether.to17 hours ago

Frontend Software Engineer

PK flagPakistan OnlyFull-timeFull-stack Engineer
ApplyView job
CI&T17 hours ago

AI Full-Stack Developer, Java/Angular

BR flagBrazil OnlyFull-timeFull-stack Engineer
ApplyView job
CVS Health17 hours ago

Senior Software Development Engineer

US flagTexas OnlyFull-timeFull-stack Engineer$92.7k – $185.4k/year
ApplyView job
BÆRSkin Tactical Supply Co. (divbrands)17 hours ago

Senior Product Engineer

EuropeFull-timeFull-stack Engineer
ApplyView job
i22 Digital Agency17 hours ago

Senior Software Engineer – Frontend, Backend, Full-Stack

DE flagGermany OnlyFull-timeFull-stack Engineer
ApplyView job
Tether.to17 hours ago

Frontend Software Engineer

IN flagIndia OnlyFull-timeFull-stack Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers