Point your AI agent at freehire and let it find you a job.

Get the CLI →

APV

NewBe an early applicant

DevSecOps Lead

Posted 2 views
Discussion

Summary

Leads DevSecOps for a large-scale federal healthcare technology program at APV: owning CI/CD pipelines (GitHub/Jenkins), AWS infrastructure-as-code (Terraform), security scanning (SAST/DAST/SCA), observability, and cloud cost optimization. Requires 7+ years experience, 3+ years leading DevSecOps, and ability to obtain a High-Risk Public Trust.

POSITION TITLE: DevSecOps Lead

LOCATION: Remote

CLEARANCE: Must be able to obtain a High-Risk Public Trust

COMPANY OVERVIEW

At APV, we’re more than a technology company — we’re a mission-driven powerhouse transforming organizations through advanced technology and human ingenuity. Our expertise spans AI/ML, data architecture, low-code/no-code development, Agile DevSecOps, and cloud services, delivering scalable and meaningful solutions.

In our Emerging Technology Lab, innovation drives progress. Our teams create intelligent chatbots, AI-powered assistants, robotic process automation (RPA), essay graders, and data analytics platforms. If you’re passionate about solving complex challenges and shaping the future, APV is the place for you. Since 2007, we’ve partnered with federal and state agencies to deliver IT, training, and consulting solutions that achieve mission-critical outcomes. Built on accountability, integrity, and quality, we go beyond expectations. With 70+ prime contracts and a proven record of client success, APV continues to grow — and we’re looking for exceptional talent to grow with us.

At APV, we Always Provide Value

POSITION SUMMARY

Seeking a mission-driven DevSecOps Lead to support a large-scale federal healthcare technology program. This role provides leadership across CI/CD, cloud engineering, automation, platform operations, infrastructure as code, and secure software delivery. This role is accountable for release quality, environment reliability, and measurable reduction in deployment risk and cloud cost.

DUTIES

  • Lead DevSecOps strategy and implementation across development, test, staging, and production environments.
  • Design, maintain, and optimize CI/CD pipelines supporting secure software delivery.
  • Implement Infrastructure as Code (IaC), automated deployments, configuration management, and environment provisioning.
  • Integrate SAST, DAST, SCA, container security, and vulnerability scanning into delivery pipelines.
  • Support Agile release management, deployment automation, release readiness, and production support.
  • Collaborate with architects, security teams, and engineering teams to improve platform reliability and scalability.
  • Support cloud optimization, observability, monitoring, logging, and operational automation initiatives.
  • Build and maintain CI/CD pipelines on agency enterprise tooling such as GitHub and Jenkins, including automated build, test, security scanning, and deployment gates.
  • Automate infrastructure and environment provisioning in AWS using infrastructure as code, and drive cloud cost optimization alongside reliability and scalability improvements.
  • Embed SAST, DAST, SCA, container and image scanning, and secrets management into pipelines so that vulnerabilities are caught before release rather than after.
  • Partner with the Security Manager on continuous monitoring, patching, and vulnerability remediation within agency-defined timelines, and support Authority to Operate (ATO) evidence collection.
  • Improve observability, logging, and alerting to sustain system availability and shorten incident detection and recovery.

EDUCATION

Bachelor’s degree in Computer Science, Engineering, Information Systems, or a related technical discipline; equivalent relevant experience may be considered.

REQUIRED QUALIFICATIONS

  • Minimum 7 years of software engineering, cloud, DevOps, platform engineering, or related experience, including at least 3 years leading DevSecOps implementations.
  • Demonstrated expertise with CI/CD pipelines, infrastructure as code, containerization, orchestration, automated testing, configuration management, observability, secrets management, and automated security scanning. Experience integrating SAST, DAST, SCA, container/image scanning, and other automated security controls into development and deployment pipelines.
  • Must be able to obtain and maintain a High-Risk Public Trust or equivalent federal client access. This role supports sensitive federal programs and involves elevated access to systems and data.
  • Position requires the current ability to obtain and maintain required access without interruption in alignment with long-term program needs.
  • Must be authorized to work in the United States without employer sponsorship now or in the future.

PREFERRED QUALIFICATIONS

  • Security+, or comparable cloud (AWS/Azure)/ DevSecOps credential. Hands-on experience with Terraform, Docker, Kubernetes, GitHub Actions or Jenkins, and federal ATO or FedRAMP environments is strongly preferred.

ABOUT APV

APV is an Equal Employment Opportunity employer. All qualified applicants are considered without regard to race, color, religion, sex, national origin, age, disability, genetic information, sexual orientation, gender identity, veteran status, or marital status.

Skills

What Lead Security jobs ask for — and how much of it you have →
Apply

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available