Senior DevSecOps Engineer
About Us:
eSimplicity is a modern digital services company that works across government, partnering with our clients to improve the health and lives of millions of Americans, ensure the security of all Americans—from soldiers and veterans to kids and the elderly, and defend national interests on the battlefield. Our engineers, designers, and strategists cut through complexity to create intuitive products and services that courageously equip Federal agencies with solutions to transform today for a better tomorrow for all Americans.
This role is contingent upon successful Moderate Risk Public Trust (MRPT) clearance and award.
This is a full-time position through July 2027, with the possibility of extension based on customer needs.
Role Overview:
We are seeking a hands-on DevSecOps Engineer to join a cross-functional, entrepreneurial, collaborative team dedicated to solving difficult problems for our clients. This individual will have experience with RMF through implementation and customization of controls in a DevSecOps pipeline and tech stack. Additionally, this individual will have experience implementing controls as applicable and understand how they will affect the tech stack within the DevSecOps pipeline. The role is primarily focused on being the DevSecOps engineer within the product team but must be able to ensure that the security controls are in place and work with the security team to validate controls and evidence.
Responsibilities:
- Partner with the development team to implement secure engineering patterns, maintain secure CI/CD pipelines, and remediate vulnerabilities, including contributing code, configuration, pipeline changes, and infrastructure updates where appropriate.
- Design and maintain security gates for code quality, dependency scanning, container image scanning, secrets detection, infrastructure misconfiguration, and policy compliance.
- Support Kubernetes and container security for AWS EKS environments, including image hardening, admission controls, runtime monitoring, network policies, workload identity, secrets management, and least-privilege access patterns.
- Support controls for new tooling/integration usage, the handling of sensitive data, and access controls.
- Help define and enforce secure-by-default engineering standards across the application, infrastructure, and delivery pipeline.
- Help drive the move toward ATO and near-real-time compliance.
- Implement monitoring of production runtime environments for vulnerabilities and compliance drift and make security and compliance reporting available on demand.
- Translate security findings into actionable engineering work items in JIRA and support teams through remediation, validation, and closure.
- Identify, document, and communicate security risks tied to modernization efforts
- Monitor cloud environments using AWS tools
- Participates in Agile processes including daily standups, demos, retrospectives, and sprint planning
- Collaborates with a fully integrated Agile team to deliver continuous improvement to designs, processes, and standards