DevSecOps Engineer
Quick Summary
Embed cybersecurity engineering into Agile software development and modernization activities. Integrate security requirements and controls throughout the SDLC and CI/CD pipelines.
Embed cybersecurity engineering into Agile software development and modernization activities. Integrate security requirements and controls throughout the SDLC and CI/CD pipelines.
The DevSecOps Engineer provides security engineering expertise to Mission Partners, system owners, ISSMs/ISSOs, architects, and software development teams throughout the SDLC. The position integrates cybersecurity requirements and controls directly into Agile development and CI/CD processes, enabling development teams to identify and address security issues earlier in the lifecycle and securely move applications and capabilities from concept through production.
Responsibilities
~1 min read- →Embed cybersecurity engineering into Agile software development and modernization activities.
- →Integrate security requirements and controls throughout the SDLC and CI/CD pipelines.
- →Apply DevSecOps and shift-left security principles to identify and remediate vulnerabilities earlier in development.
- →Implement and support automated security testing within CI/CD workflows.
- →Participate with development teams in requirements discussions, design activities, sprint planning, and other lifecycle events.
- →Translate RMF, NIST SP 800-53, DoD cybersecurity policy, STIGs, SRGs, and related security requirements into actionable development and engineering tasks.
- →Collaborate with developers, architects, system owners, ISSMs, and ISSOs to develop achievable technical security controls before formal assessment.
- →Provide threat-informed security engineering guidance for legacy, modernized, and cloud-native applications.
- →Support secure development involving APIs, microservices, containerized workloads, and other modern application architectures as applicable.
- →Help development teams remediate security vulnerabilities while preserving mission functionality and delivery objectives.
- →Provide engineering recommendations for technical controls such as authentication, encryption, network segmentation, and application security.
- →Communicate security findings, technical risks, recommended remediation, and implementation approaches to technical and Government stakeholders.
- →Manage security-engineering activities across multiple concurrent projects and development sprints.
Requirements
~2 min read- Bachelor’s degree and 10+ years of related experience.
- DoD 8140 Work Role 652 – Security Architect Certification requirement (must have at least one of the following): Security X/CASP+CE, CCSP, Cloud+, CISSP, CSSLP, CISM, CISSP-ISSAP, CISSP-ISSIP, CSSLP, and GSEC.
- Must have and maintain a current DoD Top Secret clearance.
- Must reside within a commutable distance of Fort Meade, MD or Chambersburg, PA in order to work a hybrid onsite schedule (4 days onsite weekly).
- Demonstrated experience integrating cybersecurity into Agile SDLC environments.
- Demonstrated hands-on experience with CI/CD pipelines.
- Practical experience implementing DevSecOps and shift-left security practices.
- Experience using automated security testing tools within software development processes.
- Knowledge of RMF, NIST SP 800-37, and NIST SP 800-53.
- Knowledge and practical application of DoD STIGs and SRGs.
- Ability to convert security/compliance requirements into specific technical development tasks and controls.
- Understanding of modern application architectures and cloud-native development.
- Ability to collaborate effectively with cybersecurity, engineering, architecture, and software-development teams.
- Strong written and verbal communication skills.
- Ability to manage multiple development efforts and sprints in a high-tempo environment.
The projected salary range for this position is $130,000+ annually. Final compensation will be determined based on factors including years of relevant experience, active security clearance level, certifications, technical skillset, contract requirements, and overall qualifications.
What We Offer
~1 min readLocation & Eligibility
Listing Details
- Posted
- August 28, 2026
- First seen
- August 28, 2026
- Last seen
- August 29, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 60%
- Scored at
- August 28, 2026
Signal breakdown
Please let Agecareers know you found this job on Jobera.
3 other jobs at Agecareers
View all →Explore open roles at Agecareers.
Similar DevSecOps Engineer jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.