DevSecOps Engineer Role
The work
DevSecOps Engineers make secure delivery repeatable. They design the CI/CD paths, deployment controls, and operational feedback loops that carry software from a change in source code to a running service. In federal environments, that work also includes assembling and maintaining security evidence for an Authority to Operate (ATO), the formal decision to allow a system to operate at an accepted level of risk.
The role works across development, operations, and security. DevSecOps Engineers automate build, test, deployment, configuration, vulnerability management, logging, and recovery practices so teams can release with visible controls and usable evidence. They partner with Cloud Infrastructure Engineers who provide the underlying platform, while they own the delivery path and its security integration.
What you'll build
· CI/CD pipelines that run tests, security checks, approvals, and deployments consistently.
· Infrastructure-as-code modules and deployment patterns that are versioned and reviewable.
· Container build, image-scanning, and release processes for application workloads.
· Observability and vulnerability-management workflows that turn operating signals into action.
· Control evidence and traceability that support authorization, assessment, and continuous monitoring.
Who you are
You treat security, reliability, and delivery speed as one engineering problem. You look for manual deployment steps, unreviewed configuration changes, and missing evidence because each makes a system harder to operate and defend.
You can work across specialties without blurring accountability. You understand enough application engineering, cloud infrastructure, and security practice to create a dependable delivery system, communicate tradeoffs clearly, and help teams use it.
What you bring
· Hands-on experience with source control, automated testing, CI/CD, and deployment automation.
· Infrastructure-as-code experience with tools such as Terraform, Amazon Web Services CloudFormation, or comparable platforms.
· Working knowledge of container security, software supply-chain controls, and vulnerability remediation.
· Experience with logging, monitoring, incident response, and recovery practices.
· Ability to translate National Institute of Standards and Technology (NIST) Special Publication 800-53 control expectations into engineering work and evidence.
About OPEN Data Jobs
OPEN Data Jobs connects AI, data, and software professionals with critical roles, primarily in the federal sector. Registering with ODJ can put your profile in view for multiple positions across several clients.
Register for DevSecOps Engineer Role
Click Apply below to register for DevSecOps Engineer Role.
Requirements
What openings may require
Some openings may ask for experience supporting an ATO or working with the Risk Management Framework, a structured NIST process for managing security risk. Others may focus on a specific cloud, orchestration platform, programming language, or delivery toolchain.
Openings with production accountability may require demonstrated work with on-call operations, incident response, security assessments, or regulated release controls. Requirements should distinguish responsibility for the delivery pipeline from responsibility for the underlying cloud environment or independent security assessment.
Benefits
Compensation, benefits, work location, and employment terms are set for each specific opening and will be stated with that opening
Skills
As published by workable · 12 questions · 7 written answers
Basics
First name, Last name, Email, Headline, Phone, Address, Resume, Cover letter
Pick from a list (4)
- Many of our clients support federal agencies in work that requires U.S. citizenship. Are you a United States citizen?
- Willing to undergo a standard pre-employment background check?
- We ask you to report one standardized admissions or entrance test score, such as the SAT, ACT, GRE, GMAT, or ASVAB. Which test are you reporting?
- If you choose to be considered for a specific opening, can you provide professional references at that time?
Written answers (7)
- In which countries are you currently authorized to work without employer sponsorship? Enter N/A if none.
- List any current U.S. government security clearance you hold, including the level. Enter None if you do not currently hold one.
- Enter your undergraduate major(s) or primary field(s) of study and the educational institution(s) attended. If you did not attend an undergraduate program, enter N/A.
- Enter your cumulative undergraduate grade point average and the grading scale used, for example, 3.2 on a 4.0 scale. If you did not attend an undergraduate program or your institution did not calculate a cumulative GPA, enter N/A and briefly explain.
- Enter the month and year of the test and the score you received. If you selected Other, identify the test. If you selected None, enter None.
- Paste the full web address (URL) of your GitHub profile or portfolio, beginning with https, for example, https://github.com/yourname. If you do not have one, enter None.
- Paste the full web address (URL) of your LinkedIn profile, beginning with https, for example, https://www.linkedin.com/in/yourname. If you do not have one, enter None.
Attachments (1)
- Resume