DevSecOps Engineer - 4173703
$140,000–$155,000 year
On-siteWashington, District of Columbia, United States or Washington, United States
Job Summary
Design, implement, and maintain CI/CD pipelines in AWS environments using GitLab, Terraform, and CloudFormation. Manage and deploy containerized applications with Kubernetes and Docker while configuring security baselines and policies. Integrate SAST and DAST tools like Sonarqube and Invicti into the DevSecOps lifecycle to analyze code and container images. Collaborate with development teams to resolve vulnerabilities reported by Tenable and track resolution progress. Automate deployment and configuration management across development, test, and production environments using Ansible. Implement monitoring and logging solutions such as Splunk or ELK Stack to ensure system uptime and application health. Support platform operations including updates, patching, and maintenance for underlying AWS cloud infrastructure. Review and suggest improvements to cloud architecture to aid in scaling. This full-time remote role requires U.S. citizenship and a government background investigation, with occasional on-site presence in the Washington, D.C. area.
Required Qualifications
- U.S. citizenship
- submit to a government background investigation and be favorably adjudicated before their first day
- live within commuting distance of Washington, D.C.
- Five (5) plus years of experience in DevSecOps engineering
- at least 3+ years managing and maintaining AWS ecosystems
- Expertise in managing and deploying containerized applications using Kubernetes and Docker
- Proficiency with AWS cloud security, including configuring baselines and security policies to create a Zero Trust Architecture for tools such as encrypted S3 buckets, IAM role, and service/network logging
- Proficiency in designing, implementing, and maintaining CI/CD pipelines using tools such as GitLab
- utilizing tools, such as Terraform or Cloud Formation, to implement an Infrastructure as Code methodology
- Hands-on experience with security scanning and analysis tools, including SAST/DAST (e.g., Sonarqube, Invicti) and vulnerability management (e.g., Tenable)
- Ability to work in an agile or iterative development environment
- Experience authoring and debugging Dockerfiles for web applications, preferably for Docker images using Java or Angular
- Experience standing up and managing an AWS/Gitlab architecture, preferably in a non-DOD federal government space
Desired Qualifications
- DevSecOps relevant certifications in Cloud platforms (AWS preferred)
- Experience ensuring application security for Java Spring Boot API containers
- Practice working with regulatory, legal, or government data sets
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.