DevSecOps Engineer

Hybrid in Tysons, VA, US • Posted 12 hours ago • Updated 12 hours ago
Full Time
No Travel Required
Hybrid
Depends on Experience
Fitment

Dice Job Match Score™

👤 Reviewing your profile...

Job Details

Skills

  • DevSecOps
  • GitLab
  • Ansible
  • DoD
  • DevOps
  • Docker
  • Amazon Web Services
  • Splunk

Summary

2. DevSecOps Engineer — Key Personnel

Labor Category:  DevSecOps Engineer

Clearance:  U.S. Citizen with active SECRET clearance (required).

Position Summary

Design, automate, and secure the CI/CD pipelines, cloud infrastructure, and RMF compliance for a FedRAMP High / DoD Impact Level 5 (IL5) data and analytics platform. Embeds security automation across the DevOps lifecycle under an ''Automation-First'' mandate.

A. Minimum Qualifications (resume must demonstrate)

       Five (5) years in DevSecOps: designing, implementing, and maintaining CI/CD pipelines and automating deployment (Jenkins, GitLab CI/CD, Ansible).

       Five (5) years supporting the RMF process for DoD/federal systems: applying DISA STIGs, vulnerability assessments, and patching/remediation.

       Five (5) years automating cloud infrastructure/platform provisioning (AWS, Azure) using Infrastructure as Code (Terraform, CloudFormation).

       Experience integrating security automation, vulnerability scanning (Nessus, OpenSCAP), and monitoring/logging (Splunk, ELK) into the DevOps lifecycle.

       Verifiable experience with containerization/orchestration (Docker, Kubernetes) in a microservices architecture.

       Verifiable experience integrating automated security testing (SAST and DAST) directly into the CI/CD pipeline.

B. On-Contract Responsibilities (from PWS Task Areas)

       Automate infrastructure and workflows using IaC (Terraform, Ansible); build and manage CI/CD pipelines for secure deployment; develop streaming data pipelines (Apache Kafka, AWS Kinesis) for real-time processing.

       Deliver all activities and evidence to achieve and maintain a full Authority to Operate (ATO) under RMF — System Security Plan, Security Assessment Report, POA&M — and support control assessments and continuous monitoring.

       Implement Compliance-as-Code: automate DISA STIG application/verification across all infrastructure layers; auto-generate RMF artifacts (PPSM, topology diagrams) from IaC repos so eMASS reflects the true environment; integrate zero-touch automated vulnerability scanning into CI/CD.

       Operate within a FedRAMP High / DoD IL5 cloud (AWS GovCloud, Azure Government), ensuring all AI/ML processing stays inside the accredited boundary (no CUI to public commercial AI endpoints).

       Use IaC to dynamically provision/de-provision GPU-accelerated compute clusters to control costs, supporting the MLOps lifecycle.

       Perform continuous security compliance for baseline components — software patching and STIG/vulnerability remediation — with zero degradation to legacy capabilities during modernization.

 

 

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10491343
  • Position Id: 9049600
  • Posted 12 hours ago
Contact the job poster
UB

Uma Bhattacharya

Recruiter @ Satsyil Corporation
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Sterling, Virginia

Today

Full-time

Washington, District of Columbia

Today

Full-time

USD 98,000.00 - 163,000.00 per year

Washington, District of Columbia

Today

Full-time

Washington, District of Columbia

Today

Full-time

USD 100,000.00 per year

Search all similar jobs