As a Sr. DevSecOps Engineer I, you’ll play a critical role in designing, implementing, and maintaining secure and efficient software development and deployment pipelines. You will collaborate with cross-functional teams to integrate security practices seamlessly into the development and operations lifecycle, ensuring the delivery of high-quality, secure, and reliable software solutions. This role requires an on-site presence in Reston, VA.
What you’ll do:
- Collaborate with customers and internal teams to design and implement technical solutions across multiple classification environments, working independently or collaboratively to address complex requirements.
- Develop CI/CD pipelines from scratch in GitLab and Jenkins with integrated security scanning and STIG compliance validation, providing expert guidance on pipeline troubleshooting and DevSecOps best practices.
- Create and maintain Infrastructure as Code (IaC) templates, primarily using CloudFormation, to architect highly available, resilient, and secure DevSecOps tool infrastructure across AWS environments (GovCloud, C2S, TC2S) while ensuring STIG compliance.
- Lead advanced troubleshooting by analyzing system and application logs via Linux command-line tools, conducting root cause analysis, and developing mitigation strategies for service degradation.
- Provide expert guidance to development teams on secure coding practices, STIG compliance, and vulnerability remediation in support of ATO efforts, while mentoring junior engineers through code reviews, IaC best practices, and technical documentation.
What you’ll need to succeed:
- Active TS/SCI with CI Poly security clearance.
- Certification to satisfy DoD 8140/8570 (e.g., Security+, or equivalent).
- 5+ years as a DevSecOps Engineer, DevOps Engineer, or similar.
- Strong hands-on Linux experience.
- Experience with designing, deploying, and managing production-grade Kubernetes (K8s) or OpenShift clusters via automation with Ansible and Terraform and/or CloudFormation in on-prem and cloud environments.
- Experience with CI/CD pipelines (e.g. GitLab, or equivalent) and containerization.
- Experience with Helm chart development and STIGs (preferred).
Nice to Have's:
Experience with:
- Jenkins
- Artifactory / Nexus
- SonarQube
- Selenium
- Security tooling:
- Fortify, Acunetix, Prisma Cloud
- PKI / certificate lifecycle management
- Cloud experience (AWS, Azure, GCP)
- NIST SP 800-53 Security Controls
The salary range for this position is determined based on qualifications, skills, and relevant experience. The final salary offered will be determined based on several factors including:
- The candidate's professional background and relevant work experience
- The specific responsibilities of the role and organizational needs
- Internal equity and alignment with current team compensation