Point your AI agent at freehire and let it find you a job.

Get the CLI →

Millennium Corporation

NewBe an early applicant

Cybersecurity Engineer – DevSecOps

Posted Updated
Discussion

Overview

Millennium is proud to be part of the Markon enterprise, a network of specialized organizations united in support of critical national security missions. This partnership strengthens our ability to deliver results by expanding our technical depth, operational reach, and access to a broader bench of proven experts, ensuring our customers continue to receive best-in-class cybersecurity support.Since 2004, Millennium has operated at the forefront of cybersecurity. Our elite team of over 300 professionals brings an unmatched record of performance across Red Team Operations, Defensive Cyber Operations, Software Engineering, and Technical Engineering. As home to the largest contingent of contracted Red Team operators supporting the Department of Defense, Millennium delivers unparalleled threat intelligence and battle-tested expertise to both DoD and federal civilian customers.

What We Believe

Millennium is an equal opportunity employer and does not discriminate or allow discrimination on the basis of race, color, religion, gender, age, national origin, citizenship, disability, veteran status or any other classification protected by federal, state, or local law.

Responsibilities

Millennium Corporation is seeking a Cybersecurity Engineer – DevSecOps to support cybersecurity, software assurance, and security engineering activities within a DoD/DoN environment. This position is 100% remote and will focus on integrating cybersecurity throughout the software development and delivery lifecycle, with an emphasis on application security, CI/CD pipeline security, container security, vulnerability management, and DoD cybersecurity compliance.

Candidates located in or near major U.S. Navy installations are preferred, with priority given to candidates in the New Orleans, Orlando, and Washington, DC metropolitan areas. Candidates located near other major Navy facilities may also be considered.

Key Responsibilities

  • Conduct code and container vulnerability assessments using approved DoD vulnerability scanning tools, DISA Security Technical Implementation Guides (STIGs), Security Requirements Guides (SRGs), and other DoD/DoN software assurance tools.
  • Implement and assess operating system security configurations in accordance with applicable DISA STIGs and SRGs.
  • Perform cybersecurity assessments, security audits, and risk analyses to identify vulnerabilities and compliance gaps.
  • Apply security testing methodologies, including Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST), throughout the software development lifecycle.
  • Review and implement cybersecurity policies and security controls within CI/CD pipelines to support secure software delivery and DoD/DoN requirements.
  • Serve as a GitLab security reviewer and approver for merge requests, reviewing security scan results and verifying that identified findings are remediated or appropriately documented through the approved risk-management process prior to release.
  • Review GitLab SAST, dependency, secret detection, and container scanning results; coordinate remediation activities with development teams and track findings through closure.
  • Review changes to GitLab security policies, pipeline controls, and protected branch settings to ensure required security checks and approvals remain properly enforced.
  • Provide cybersecurity oversight for containerized workloads using NeuVector, including review of vulnerability findings, admission control decisions, and runtime security alerts.
  • Collaborate with application and platform teams to investigate NeuVector findings, tune security policies, and document remediation actions or accepted risks.
  • Ensure security-related provisions within system acquisition and program documentation address identified cybersecurity requirements.
  • Provide cybersecurity guidance and assist with developing mitigation strategies for DoD information systems.
  • Prepare Risk Management Framework (RMF) artifacts and Memoranda of Agreement (MoAs) with system owners supporting interface and networking implementations.
  • Identify and evaluate Common Criteria and National Information Assurance Partnership (NIAP) certified technologies when applicable.
  • Evaluate cybersecurity products and technologies used by programs to validate compliance with applicable DoD/DoN requirements.
  • Support cybersecurity activities across the software lifecycle and collaborate with engineering, development, platform, and program teams to address security requirements and risks.

Qualifications

  • Active Secret clearance.
  • Bachelor's degree with 8 years of relevant experience, or a high school diploma/equivalent with 13 years of relevant experience.
  • Experience working within the DoD Risk Management Framework (RMF) and familiarity with DoDI 8510.01.
  • An Information Assurance Manager (IAM) Level II certification in accordance with DoD 8570.01-M, such as:-CISSP-GSLC-CISM
  • Experience with DoD cybersecurity requirements, including DISA STIGs and SRGs.
  • Experience with software security testing methodologies, including SAST and DAST.
  • Experience supporting cybersecurity within CI/CD or DevSecOps environments.
  • Experience with GitLab security tools and processes, including reviewing security scan results and supporting vulnerability remediation.
  • Candidates should be located in or near a major U.S. Navy installation. Preferred locations include New Orleans, LA; Orlando, FL; and the Washington, DC metropolitan area. Candidates near other major Navy facilities may also be considered.

Preferred Qualifications

  • Proficiency with GitLab, NeuVector, and Sonatype.
  • Experience with container security and vulnerability management.
  • Experience supporting cybersecurity within a DoD or Department of the Navy (DoN) environment.
  • Experience with the Navy's Rapid Assess and Incorporate Software Engineering (RAISE) methodology.
  • Experience with the RAISE Platform of Choice (RPOC).
  • Experience evaluating Common Criteria and NIAP-certified technologies.
  • Experience developing or supporting RMF artifacts, security documentation, and cybersecurity mitigation strategies.

Business Development

Assist with Business Development activities as required to support Millennium's strategic business objectives, which may include but not limited to participation in technical interviews, creation of technical documentation, general proposal writing support and proposal color reviews.

Physical Requirements

  • Must be comfortable with prolonged periods of sitting at a desk and working on a computer.
  • Must be able to lift up to 10-15 pounds at a time.

COMPENSATION:

$125,000- $135,000

The salary range provided for this position is intended as a general guideline and does not guarantee a specific salary or compensation amount. Final compensation will be determined based on a variety of factors, including, relevant education, experience, knowledge, skills, and abilities

Skills

Apply

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available