DevSecOps Engineer
Quick Summary
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a DevSecOps Engineer based in the United States.
This role supports a mission-critical federal DevSecOps program focused on modernizing supply chain and logistics solutions. You’ll embed security directly into CI/CD pipelines, ensuring that applications are protected throughout the software development lifecycle. The position combines hands-on pipeline engineering, cloud security, vulnerability management, and compliance automation. You’ll collaborate closely with Agile delivery teams, developers, security leaders, and federal stakeholders to turn security requirements into practical controls. Your work will help maintain secure, compliant systems and support continuous authorization in complex cloud environments. You’ll also contribute to secure coding practices, incident response, reusable security solutions, and the ongoing evolution of DevSecOps capabilities.
- Embed Guardrails-as-Code and automated security controls across CI/CD pipelines, including SAST, DAST, SBOM generation, vulnerability scanning, and policy gates.
- Manage secrets, cryptographic code signing, artifact integrity, hardened container images, and automated configuration drift detection.
- Triage, track, and remediate security vulnerabilities within defined deadlines, ensuring critical and high-risk findings are addressed before production.
- Automate security evidence collection to support Continuous Assessment and Authorization (ATO), NIST RMF activities, and VA/FedRAMP compliance.
- Implement Zero Trust principles, identity and access controls, logging, encryption, network segmentation, and cloud security measures across AWS, Azure, and VA Enterprise Cloud environments.
- Mentor development teams on secure coding and security design practices, including the review and validation of AI-generated code and test scripts.
- Support security incident response through component isolation, forensic activities, rapid reporting, and after-hours escalation rotations.
- Contribute to DevSecOps strategies for proposals, security performance metrics, technical interviews, reusable pipeline security templates, cybersecurity communities, and corporate quality initiatives.
Requirements
~2 min read- 7+ years of experience in IT security or DevSecOps, including at least 4 years integrating continuous security controls into CI/CD pipelines within federal Agile/SAFe environments.
- 3+ years of hands-on experience with pipeline security automation, including SAST/DAST, container scanning, secrets management, and SBOM generation using standards such as SPDX or CycloneDX.
- Strong experience automating infrastructure hardening and configuration compliance with tools such as Ansible and Terraform against DISA STIG and CIS benchmarks.
- Proven knowledge of NIST Risk Management Framework (RMF), Authority to Operate (ATO) processes, POA&Ms, and automated continuous control evidence collection.
- Extensive experience securing AWS, Azure, and VA Enterprise Cloud environments, including IAM, encryption, network segmentation, and related cloud security controls.
- Strong vulnerability management experience, with the ability to partner directly with development teams to investigate, prioritize, and resolve findings.
- Experience with security monitoring and logging platforms such as Splunk, as well as identity and access technologies including HashiCorp Vault, mutual TLS, ICAM, and PIV.
- Ability to support secure development across Java, .NET, Python, and legacy MUMPS environments, with experience embedding automated Section 508 accessibility testing into pipelines.
- Experience with VA supply chain systems, HL7/FHIR healthcare APIs, one-hour incident response requirements, or AI-generated code validation is highly preferred.
- Bachelor's degree in Cybersecurity, Computer Science, Computer Engineering, Information Systems, or a related field; a master's degree is preferred.
- Required certification: ISC2 CISSP or Security+. Additional preferred certifications include AWS Solutions Architect Associate, AWS Developer Associate, Azure Solutions Architect, Azure Developer Associate, Red Hat Certified Specialist in Ansible Automation, or Red Hat Certified Architect.
- Ability to obtain a Tier 2 / Moderate Risk Background Investigation and VA PIV credential.
What We Offer
~2 min readLocation & Eligibility
Listing Details
- Posted
- October 2, 2026
- First seen
- October 2, 2026
- Last seen
- October 2, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 68%
- Scored at
- October 2, 2026
Signal breakdown
Similar DevSecOps Engineer jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.