
Senior Engineer
Posted Sep 15

Posted Sep 15
This is a fully remote position, open to applicants in Texas.
• Assist a DoW program by integrating Information Assurance, cybersecurity, and security engineering requirements into DevSecOps pipelines, tools, configurations, and software delivery processes.
• Collaborate with the Pipeline Architect, Software Engineering Subject Matter Experts (SMEs), infrastructure/platform engineers, and government stakeholders to ensure compliance with DoD cybersecurity standards.
• Convert DoD cybersecurity, RMF, and DevSecOps requirements into practical technical specifications.
• Design, implement, configure, and sustain automated security controls within CI/CD pipelines.
• Incorporate and manage SAST, DAST, SCA, container scanning, secrets detection, dependency scanning, and vulnerability management tools.
• Set up and enforce security gates and thresholds in GitLab CI/CD pipelines.
• Facilitate secure software supply chain methodologies, including artifact integrity, SBOM generation, vulnerability scanning, signing, provenance, and attestations.
• Integrate security tools such as Fortify, SonarQube, Trivy, Twistlock/Prisma Cloud, NeuVector, and Cosign/Sigstore into automated workflows.
• Assess Kubernetes, container, GitLab Runner, infrastructure-as-code, and pipeline configurations for security flaws and weaknesses.
• Assist in vulnerability triage and remediation efforts alongside software and platform engineering teams.
• Develop and sustain security-as-code and policy-as-code methodologies.
• Ensure compliance with the DoD DevSecOps Reference Design, NIST RMF, NIST 800-53 controls, and relevant DoD cybersecurity mandates.
• Automate the collection of security evidence for authorization and ongoing monitoring.
• Collaborate with platform and application teams on the UP continuous Authority to Operate and CD/CI processes.
• Identify cybersecurity risks and propose technical mitigations.
• Create security documentation, implementation guidance, configuration standards, and engineering best practices.
• Engage in architecture reviews, technical discussions, troubleshooting sessions, and security evaluations.
• This position is based in the U.S.; U.S. citizenship is required for employment, and all work must be performed within the continental U.S.
• A minimum of 3 years of experience in Cybersecurity Engineering, DevSecOps, Platform Engineering, Cloud Security, Application Security, or a related technical field.
• Practical experience in implementing security capabilities within CI/CD pipelines, preferably using GitLab CI/CD.
• Familiarity with application or container security technologies such as Fortify, SonarQube, Trivy, Twistlock/Prisma Cloud, NeuVector, or similar tools.
• Experience with containerized environments and understanding of Kubernetes security concepts.
• Proven experience in identifying, assessing, and remediating vulnerabilities in software, containers, infrastructure, or configurations.
• Working knowledge of DoD RMF, NIST SP 800-53, and DoD cybersecurity/Information Assurance requirements.
• Grasp of DevSecOps principles and the integration of security controls throughout the software development lifecycle.
• Experience with Git and infrastructure/configuration-as-code technologies such as Terraform, Ansible, Helm, or equivalent tools.
• Understanding of software supply chain security concepts, including SBOMs, artifact signing, provenance, vulnerability scanning, and attestations.
• Ability to translate cybersecurity requirements into effective technical controls and communicate clearly with cybersecurity and engineering stakeholders.
• An active Secret Clearance is required to start.
• Preferable experience with GitLab, GitLab Runners, Argo CD, Kubernetes, Helm, SOPS, AWS/GovCloud, Platform One, DoD software factories, and DoD cATO environments.
• A DoD 8140/8570-compliant cybersecurity certification such as Security+, CySA+, CASP+/SecurityX, CISSP, or equivalent is preferred.
• Certifications in Kubernetes, cloud security, or AWS are desirable.
• Highly competitive salary
• Comprehensive healthcare, dental, and vision coverage
• 401(k) plan with company matching
• Flexible PTO policy + 11 paid holidays
• Education and training benefits
• Generous referral bonuses
• And more!
Tether.to
CI&T
CVS Health
BÆRSkin Tactical Supply Co. (divbrands)
Get handpicked remote jobs straight to your inbox weekly.