DevSecOps Engineer - Expert
Summary
Dark Wolf Solutions is hiring an Expert DevSecOps Engineer in Chantilly/Herndon, VA to architect, scale, and secure CI/CD pipelines and infrastructure supporting defense and intelligence community missions. Day-to-day work centers on Jenkins/GitLab CI/CD, Kubernetes with service meshes, policy-as-code, secrets management, and observability stacks like Prometheus and Grafana.
Dark Wolf constructs and deploys data management and analytics solutions for the defense and intelligence communities. We’re proud to boast a world-class engineering team that thrives on rolling up their sleeves to solve your mission’s biggest challenges.
Dark Wolf is seeking an Expert DevSecOps Engineer to serve as a technical anchor, architecting, maintaining, and scaling the Continuous Integration/Continuous Deployment (CI/CD) tools, pipelines, and infrastructure used across the development lifecycle. In this role, you will lead the integration of security and operational resilience, ensuring total observability, automated compliance, and software assurance across complex systems.
We are seeking a seasoned leader and problem solver with a proven ability to deliver superior results while guiding high-performing engineering teams in fast-paced environments.
Key Responsibilities
- CI/CD Platform Leadership: Maintain, optimize, and scale production-grade CI/CD pipelines utilizing platforms such as Jenkins, GitLab CI/CD, and custom workflow engines.
- Automated Security Engineering: Ensure the seamless integration of automated security controls and scanning processes throughout the pipeline, including static code analysis (SAST), dynamic code analysis (DAST), dependency auditing, and vulnerability scanning.
- Testing Architecture: Implement and maintain robust automated testing frameworks across unit testing, integration testing, and User Acceptance Testing (UAT).
- Vulnerability & Risk Remediation: Collaborate directly with software development and security teams to proactively identify, prioritize, and remediate security vulnerabilities and architectural weaknesses in deployed software products.
- Regulatory Compliance & Security Governance: Implement and enforce compliance with relevant federal, DoD, and organizational security regulations and standards.
- Platform & Infrastructure Strategy: Establish enterprise Infrastructure-as-Code (IaC) module standards, direct multi-environment deployment frameworks, and lead response strategies for enterprise-level vulnerabilities.
Qualifications:
- Clearance: Must be a US Citizen holding an active TS/SCI security clearance with an active Full-Scope Polygraph.
- Education: Bachelor's degree in Computer Science, Information Systems, Engineering, or a related technical field.
- Professional Experience: 10+ years of progressive engineering experience, including deep expertise in CI/CD concepts, methodologies, and enterprise automated pipeline construction.
Core Technical Skills Required for Expert Level: (Advanced competencies expected for a 10+ year Expert practitioner)
- Enterprise Container Orchestration & Security: Deep experience managing enterprise Kubernetes clusters, authoring NetworkPolicies, implementing Service Meshes (e.g., Istio, Linkerd), and enforcing runtime security (e.g., Falco).
- Policy-as-Code & Guardrails: Experience implementing Policy-as-Code architectures using tools like Open Policy Agent (OPA/Gatekeeper) or Kyverno to automate compliance enforcement before runtime.
- Secrets Management Architecture: Hands-on design and implementation of automated secret lifecycle solutions (e.g., HashiCorp Vault) integrating dynamically into pipelines and runtime platforms.
- Distributed Observability: Proven capability building centralized telemetry stacks leveraging OpenTelemetry, Prometheus, Grafana, and ELK/OpenSearch.
Desired Qualifications:
- Programming & Scripting: High proficiency in languages such as Python, Go, Bash, or C/C++.
- Containerization: Comprehensive experience with containerized software engineering practices and runtimes (Docker, Podman, OCI specs).
- Agile Engineering: Proven experience working within and leading Agile/Scrum software development teams.
- Multi-Cloud Expertise: Architecture experience across major cloud platforms, including AWS, Azure, or GCP.
- Security Tooling Ecosystem: Hands-on experience integrating modern security scanners (e.g., SonarQube, Snyk, Trivy, OWASP ZAP, Fortify).
Industry Certifications:
- Certified Kubernetes Administrator (CKA) / Certified Kubernetes Security Specialist (CKS)
- AWS Certified DevOps Engineer – Professional
- CompTIA Security+, CISSP, or GIAC DevSecOps Automation (GCSA)
Position Clearance Requirement:
US Citizenship with an active TS/SCI security clearance with Full-Scope Polygraph
Location: Chantilly/Herndon, VA.
Target Salary Range: $160,000.00 – $210,000.00 (Commensurate with specialized expertise and technical skillset).
Equal Opportunity Employer:
We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire.
We are strictly looking for direct, full-time W2 employees. We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this role.
Skills
- Agile
- Analytics
- Automation
- AWS
- Azure
- Bash
- CI/CD
- Cissp
- Cloud
- Containerization
- C++
- DAST
- DevOps
- DevSecOps
- Docker
- ELK
- GCP
- GitLab
- Grafana
- Infrastructure as Code
- Istio
- Jenkins
- Kubernetes
- Observability
- OpenSearch
- OpenTelemetry
- OWASP
- Podman
- Prometheus
- Python
- Regulatory Compliance
- SAST
- Scrum
- Secrets Management
- SonarQube
- Test Automation
- TypeScript
- Unit Testing
- Vault
- Vulnerability Scanning
As published by greenhouse · 10 questions
Basics
First Name, Last Name, Email, Phone, Resume/CV, Location
Short answers (3)
- LinkedIn Profile optional
- Website optional
- Where did you hear about us? optional
Pick from a list (7)
- Are you legally authorized to work in the United States without sponsorship?
- Do you currently hold an active United States security clearance?
- What is the highest level of security clearance you currently hold?
- Voluntary Self-Identification: For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file. As set forth in Dark Wolf Solutions’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law. Gender:
- Voluntary Self-Identification For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file. As set forth in Dark Wolf Solutions’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law. Are you Hispanic/Latino?
- If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows: A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability. A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service. An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense. An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985. Veteran Status:
- Form CC-305 OMB Control Number 1250-0005 Expires 05/31/2023 Voluntary Self-Identification of Disability Why are you being asked to complete this form? We are a federal contractor or subcontractor required by law to provide equal employment opportunity to qualified people with disabilities. We are also required to measure our progress toward having at least 7% of our workforce be individuals with disabilities. To do this, we must ask applicants and employees if they have a disability or have ever had a disability. Because a person may become disabled at any time, we ask all of our employees to update their information at least every five years. Identifying yourself as an individual with a disability is voluntary, and we hope that you will choose to do so. Your answer will be maintained confidentially and not be seen by selecting officials or anyone else involved in making personnel decisions. Completing the form will not negatively impact you in any way, regardless of whether you have self-identified in the past. For more information about this form or the equal employment obligations of federal contractors under Section 503 of the Rehabilitation Act, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp. How do you know if you have a disability? You are considered to have a disability if you have a physical or mental impairment or medical condition that substantially limits a major life activity, or if you have a history or record of such an impairment or medical condition. Disabilities include, but are not limited to: Autism; Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, or HIV/AIDS; Blind or low vision; Cancer; Cardiovascular or heart disease; Celiac disease; Cerebral palsy; Deaf or hard of hearing; Depression or anxiety; Diabetes; Epilepsy; Gastrointestinal disorders, for example, Crohn's Disease, or irritable bowel syndrome; Intellectual disability; Missing limbs or partially missing limbs; Nervous system condition for example, migraine headaches, Parkinson’s disease, or Multiple sclerosis (MS); Psychiatric condition, for example, bipolar disorder, schizophrenia, PTSD, or major depression. Disability Status: