DevSecOps / Cloud Engineer
RemoteUnited States
Job Summary
Build and maintain CI/CD pipelines within the CWBI GitHub Enterprise environment while automating DoD STIG compliance checks and vulnerability scanning across the development pipeline. Support legacy application migration to the USACE CWBI Cloud using hardened images and architect solutions leveraging SaaS, PaaS, and microservices. Manage vulnerability remediation timelines for Critical, High, Moderate, and Low severity issues, and coordinate identity provider implementations including Login.gov and OpenID. Ensure all AI/ML development occurs within the RMF-authorized AWS GovCloud environment while documenting models and datasets in the Civil Works Data Catalog. Participate in two-week Agile sprint cycles for release planning and demonstrations.
Required Qualifications
- U.S. Citizenship
- Minimum active Tier 1 (or higher) federal background investigation, favorably adjudicated, prior to start
- Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience)
- Minimum 5-7 years of experience in DevSecOps, cloud engineering, or information security
- Experience with modern DevSecOps pipelines and tools, including code repositories like GitHub
- Experience with cloud architecture, migration, and modernization, preferably within AWS GovCloud
- Demonstrated experience implementing secure coding principles and DoD STIGs across a CI/CD pipeline
- Knowledge of implementing and documenting AI/ML solutions in accordance with DoD governance principles
- Active Tier 1+ background investigation prior to start
- CompTIA Security+ or DoD 8140-approved equivalent required within six (6) months of contract start
Desired Qualifications
- Ability to obtain a CAC if required by duties
- Experience with microservices architecture and hardened/Iron Bank container images
- Federal government or DoD cloud/cybersecurity program background
- AWS certification (e.g., Solutions Architect, Security Specialty)
- Familiarity with data cataloging standards (Dublin Core, OpenAPI)
- (ISC)2 CISSP or EC-Council Certified DevSecOps Engineer (ECDE) desired for senior/lead roles
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.