Overview
Remote
HybridIts a hybrid position and not 100% remote. Travel to DC on a need basis.
Depends on Experience
Accepts corp to corp applications
Contract - Independent
Contract - W2
Contract - 12 Month(s)
10% Travel
Skills
DevSecOps Engineer
AWS Code Pipeline
Code Build
and Code Deploy
IAM
EC2
Lambda
S3
CloudFormation
Python
Job Details
Role: Senior DevSecOps Engineer
Location: Washington, DC - It's a hybrid position and not 100% remote. Travel to DC on a need basis.
Job Overview
We are seeking a highly skilled DevSecOps Engineer to lead the integration of security into our cloud-native development and operations workflows. This role requires deep expertise in AWS tooling, infrastructure automation, and secure CI/CD practices. The ideal candidate will have hands-on experience with AWS Code Pipeline, Code Build, Code Deploy (including blue/green deployments), Bitbucket, Python CDK, and Terraform.
Key Responsibilities
- Design and implement secure CI/CD pipelines using AWS Code Pipeline, Code Build, and Code Deploy.
- Configure and manage blue/green deployments for zero-downtime releases.
- Automate infrastructure provisioning using Terraform and AWS CDK (Python).
- Integrate security scanning tools (SAST, DAST, SCA) into build and deployment workflows.
- Collaborate with development and operations teams to enforce secure coding and deployment standards.
- Monitor and respond to vulnerabilities across applications and infrastructure.
- Ensure compliance with security policies and cloud governance frameworks.
- Maintain documentation for security processes, configurations, and deployment strategies.
Required Skills:
- Strong hands-on experience with AWS services, including:
- Code Pipeline, Code Build, Code Deploy
- IAM, EC2, Lambda, S3, CloudFormation
- Proficiency in Python, especially for infrastructure automation using AWS CDK.
- Experience with Terraform for infrastructure-as-code.
- Familiarity with Bitbucket for source control and pipeline management.
- Knowledge of containerization and orchestration (Docker, Kubernetes).
- Experience with security tools (e.g. Checkmarx, SonarQube).
- Understanding of security frameworks (e.g., OWASP, NIST, CIS).
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.