DevSecOps Engineer
DevSecOps Engineer
Responsibilities and Duties:
Design, implement, and maintain secure DevSecOps pipelines that integrate security throughout the Software Development Lifecycle (SDLC).
Lead the implementation of security controls and automation solutions supporting Digital Solution Development, Automation, and Infrastructure Support initiatives.
Develop and maintain Continuous Integration/Continuous Delivery (CI/CD) pipelines to support rapid and secure software delivery.
Integrate automated security testing tools, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), and container security scanning.
Collaborate with application developers, architects, cybersecurity personnel, and infrastructure teams to embed security requirements into system designs and development processes.
Establish and enforce secure coding practices, vulnerability management procedures, and DevSecOps best practices.
Support cloud security architecture and automation efforts across cloud-hosted and hybrid environments.
Design and implement Infrastructure as Code (IaC) solutions using modern automation tools and frameworks.
Conduct security assessments, code reviews, architecture reviews, and risk analyses for applications and infrastructure platforms.
Monitor, analyze, and remediate security vulnerabilities identified through automated scanning and assessment tools.
Develop and maintain security baselines, secure configuration standards, and deployment templates.
Support containerization and orchestration technologies, including security hardening and compliance monitoring activities.
Lead security-related technical projects and provide technical guidance to project teams and stakeholders.
Collaborate with system administrators, network engineers, and developers to ensure secure deployment and operation of enterprise systems.
Support Authority to Operate (ATO), FISMA, NIST, FedRAMP, and other compliance-related activities as applicable.
Develop security automation capabilities to improve detection, response, monitoring, and reporting functions.
Participate in incident response, root cause analysis, and corrective action planning activities.
Mentor junior engineers and provide technical leadership on information security initiatives.
Create and maintain technical documentation, architecture diagrams, operational procedures, and security implementation guides.
Evaluate emerging DevSecOps, cloud, and security technologies and recommend improvements to organizational security posture.
Support enterprise modernization, automation, and digital transformation initiatives by ensuring security is integrated from design through deployment.
Develop security metrics, dashboards, and reports to communicate program health, risk posture, and compliance status to leadership.
Basic Qualifications
Bachelor’s Degree in Computer Science, Information Technology, Cybersecurity, Computer Engineering, or a related field.
Minimum of eight (8) years of progressive experience in information security, cybersecurity engineering, or related disciplines. Minimum of two (2) years of experience providing technical leadership for information security projects.
Experience supporting DoD information systems and Security Technical Implementation Guide (STIG) compliance programs.
Develop and maintain automation scripts and Infrastructure as Code (IaC) templates to enforce STIG-compliant configurations across enterprise environments.
Experience implementing DevSecOps practices within Agile, DevSecOps, or CI/CD environments.
Experience with security automation tools, vulnerability management platforms, and secure software development methodologies.
Knowledge of secure coding standards, application security principles, and security testing methodologies.
Experience with CI/CD platforms such as Azure DevOps, Jenkins, GitLab, GitHub Actions, or similar technologies.
Experience supporting cloud environments, including Microsoft Azure, AWS, or Google Cloud Platform (GCP).
Familiarity with Infrastructure as Code (IaC) technologies such as Terraform, Ansible, CloudFormation, or ARM Templates.
Knowledge of containerization and orchestration technologies such as Docker, Kubernetes, and OpenShift.
Strong understanding of NIST Cybersecurity Framework, NIST 800-53, RMF, FISMA, and related federal security standards.
Experience identifying, assessing, and mitigating application and infrastructure security risks.
Strong analytical, troubleshooting, and problem-solving skills.
Excellent written, verbal, and presentation communication skills.
Ability to work effectively across multidisciplinary technical and business teams.
U.S. Citizen, and ability to get the clearance.
Preferred Qualifications
Experience supporting Department of Homeland Security (DHS) and/or Cybersecurity and Infrastructure Security Agency (CISA) programs.
Experience designing and implementing Zero Trust architectures and modern cloud security solutions.
Knowledge of Infrastructure Automation, Platform Engineering, and Site Reliability Engineering (SRE) practices.
Experience supporting FedRAMP, Continuous Diagnostics and Mitigation (CDM), or enterprise cybersecurity programs.
Hands-on experience with SIEM, SOAR, and security monitoring technologies.
Relevant certifications such as CISSP, CCSP, AWS Security Specialty, Azure Security Engineer Associate, GIAC certifications, Certified DevSecOps Professional, Security+, or equivalent.
Experience supporting enterprise modernization, application transformation, and infrastructure automation programs.