DevSecOps Engineer
Are you looking to advance your IT career in being a DevSecOps Engineer? Let's chat and see if we are a good match!
Opportunity:
The DevSecOps Engineer is a hands-on practitioner responsible for building, automating, and sustaining the delivery infrastructure that enables mission-critical software to move fast without compromising compliance. You will actively build and maintain CI/CD pipelines, harden and manage Kubernetes environments, automate security compliance, and leverage AI as a force multiplier across the entire delivery lifecycle. When team capacity demands it, you will contribute directly to feature development — bringing a security-first perspective to application code.
Primary Responsibilities:
- Design, implement, and maintain automated CI/CD pipelines that carry code from development through security scanning, compliance validation, and deployment into Navy and DoD environments
- Build and maintain hardened Kubernetes environments aligned to DISA STIG requirements across cloud and restricted network deployment contexts
- Automate security artifact generation including SBOM production, CVE scanning, and continuous compliance validation
- Drive adoption of Infrastructure as Code, GitOps practices, and controls-as-code across the team
- Leverage AI tooling to accelerate pipeline development, vulnerability triage, compliance remediation, and operational documentation
- Partner closely with software engineers, systems engineers, and ISSE's to embed security and compliance requirements from the start of development
- Maintain and evolve deployment infrastructure across multiple secure environments, including cloud and air-gapped or intermittently connected contexts
- Support ATO processes through automated evidence generation, documentation as code, and direct collaboration with the security team
- Establish and promote standards for pipeline design, container security, secrets management, and deployment consistency
- Contribute to feature development when team capacity requires, applying security-first development practices to application code
- Maintain operational documentation including runbooks, deployment guides, and architecture diagrams as version-controlled artifacts