DevSecOps Engineer
Summary
| Title: | DevSecOps Engineer |
|---|---|
| ID: | 10349 |
| Department: | Information Technology |
| Location : | Crystal City VA |
Description
Clearance: Need Active Secret or above
Seeking a DevSecOps Engineer to integrate security into the software development and delivery lifecycle. This role will design, implement, and operate secure CI/CD pipelines, cloud infrastructure, automation, and security controls that enable development teams to deliver reliable software quickly and safely. The ideal candidate combines hands-on engineering expertise with a strong understanding of application security, cloud security, infrastructure as code, and modern software delivery practices. This role partners closely with software engineers, platform teams, architects, cybersecurity teams, and compliance stakeholders.
Key Responsibilities
- Design, implement, and maintain secure CI/CD pipelines across development, test, and production environments.
- Embed automated security testing into the software development lifecycle, including static application security testing, dynamic testing, software composition analysis, container scanning, and secrets detection.
- Develop and manage infrastructure as code using tools such as Terraform, CloudFormation, or Ansible.
- Implement security controls across cloud platforms, containers, Kubernetes, APIs, and enterprise applications.
- Establish and enforce policy-as-code, secure configuration standards, and deployment guardrails.
- Integrate vulnerability management findings into engineering workflows and support timely remediation.
- Partner with development teams to identify security risks, perform threat modeling, and improve secure coding practices.
- Automate security, compliance, and operational processes to improve consistency and reduce manual effort.
- Monitor pipeline, infrastructure, and application security events; support investigation and remediation of security incidents.
- Maintain technical documentation, runbooks, architecture diagrams, and control evidence.
- Contribute to security architecture reviews, technology evaluations, and continuous improvement initiatives.
- Support compliance with applicable organizational policies, contractual requirements, and regulatory frameworks

