BigBear.ai, Inc.

DevSecOps Compliance Engineer

BigBear.ai, Inc.$100K — $130K *
Technical Services
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Active TS/SCI with Poly
  • Strong experience with CI/CD platforms like Jenkins and GitLab CI
  • Proficiency in Infrastructure as Code tools such as Terraform
  • Deep understanding of NIST 800-53 Rev 5 security controls
  • Experience with containerization platforms like Docker and Kubernetes
  • Proficiency in scripting languages such as Python or Bash
  • Experience integrating security scanning tools into automated pipelines

Responsibilities

  • Integrate ATO Automation platform with customer CI/CD pipelines and DevOps toolchains
  • Configure automated security control validation workflows using real-time code analysis
  • Implement continuous compliance monitoring via cloud service provider APIs
  • Automate System Security Plan generation and synchronize documentation
  • Establish security gates in CI/CD pipelines for automated control assessment
  • Collaborate with development teams to remediate compliance gaps
  • Deploy ATO Automation platform connectors for real-time code analysis

Benefits

  • Collaborative work environment with cutting-edge technology
  • Opportunities for continuous learning and professional development
  • Supportive team focused on innovation and quality
  • Engagement with diverse projects across multiple federal customers
  • Commitment to maintaining robust compliance frameworks
Full Job Description
Overview

BigBear.ai is seeking a DevSecOps Compliance Engineer to serve as the bridge between development operations and security compliance, responsible for implementing and maintaining an automated compliance platform within customer DevSecOps pipelines. This role ensures seamless integration of AI-driven compliance automation into existing software development lifecycles while maintaining continuous compliance monitoring and documentation generation capabilities. This position will be based out of our Columbia, MD office but will support multiple customers in the Baltimore/Washington corridor and beyond.

What you will do

  • Integrate ATO Automation platform with customer CI/CD pipelines, source control systems (GitHub, GitLab), and DevOps toolchains
  • Configure and maintain automated security control validation workflows using ATO Automation platform's real-time code analysis capabilities
  • Implement continuous compliance monitoring by connecting ATO Automation platform to cloud service provider APIs (AWS, Azure) and infrastructure-as-code repositories
  • Automate System Security Plan (SSP) generation and maintain synchronization between system configurations and compliance documentation
  • Establish security gates within CI/CD pipelines that leverage ATO Automation platform's automated control assessment capabilities
  • Collaborate with development teams to remediate compliance gaps identified through automated scanning
  • Configure integrations with security tools including SAST/DAST solutions (Fortify, SonarQube), container security platforms (Aqua, Twistlock), and vulnerability scanners (Tenable, Qualys)
  • Deploy ATO Automation platform connectors to GitLab or GitHub Enterprise repositories to enable real-time code analysis for NIST 800-53 control validation
  • Configure automated SSP generation workflows that parse infrastructure-as-code templates (Terraform, CloudFormation) and map security controls
  • Implement webhook integrations between ATO Automation platform and Jenkins pipelines to trigger compliance assessments on code commits
  • Create custom compliance dashboards that display real-time control implementation status across multiple frameworks (FedRAMP, CMMC, DoD SRG)
  • Develop automated remediation workflows that create JIRA tickets when ATO Automation platform detects compliance drift

What you need to have

  • Active TS/SCI with Poly
  • All applicants must currently reside in the United States
  • Strong experience with CI/CD platforms (Jenkins, GitLab CI, Azure DevOps, CircleCI)
  • Proficiency in Infrastructure as Code tools (Terraform, CloudFormation, ARM templates)
  • Deep understanding of NIST 800-53 Rev 5 security controls and FedRAMP compliance requirements
  • Experience with containerization and orchestration platforms (Docker, Kubernetes, OpenShift)
  • Knowledge of secure coding practices and application security testing methodologies
  • Proficiency in scripting languages (Python, Bash, PowerShell) for automation
  • Experience integrating security scanning tools into automated pipelines
  • Understanding of Git-based version control and branching strategies
  • Familiarity with OSCAL (Open Security Controls Assessment Language) standards

What we'd like you to have

  • Experience with LLM-based automation platforms and Retrieval-Augmented Generation (RAG) architectures
  • Prior implementation of compliance automation tools in federal environments
  • Hands-on experience with AWS GovCloud or Azure Government cloud platforms
  • Knowledge of CMMC 2.0 requirements and DoD Security Requirements Guide
  • Certifications: Certified DevSecOps Professional, AWS Security Specialty, Azure Security Engineer
  • Experience with SIEM platforms (Splunk, QRadar) and log aggregation
  • Understanding of zero-trust architecture principles
  • Familiarity with continuous monitoring (ConMon) requirements for federal systems

About BigBear.ai, Inc.

BigBear.ai is a leading provider of artificial intelligence and machine learning solutions that enable businesses to make better decisions by automating and augmenting their data analysis capabilities. The company's platform leverages advanced algorithms and data analytics tools to help organizations extract insights from large and complex data sets, and to develop predictive models that can be used to optimize business processes and improve operational efficiency. BigBear.ai's solutions are used by a wide range of industries, including defense, intelligence, finance, healthcare, and energy.
Learn more about BigBear.ai, Inc.
Size
200 employees
Market Cap
$90.6 million
Industry

Similar Jobs

More Jobs at BigBear.ai, Inc.

  • BigBear.ai, Inc.
    DevSecOps Compliance Engineer
    $100K — $130K *
    Annapolis Junction, MD 20701 (Howard County)
    Technical Services
    In-Person
  • BigBear.ai, Inc.
    Full Stack Developer
    $100K — $130K *
    Suitland, MD 20746 (Prince Georges County)
    Aerospace & Defense
    In-Person
  • BigBear.ai, Inc.
    UI/UX Developer
    $90K — $120K *
    Ashburn, VA 20147 (Loudoun County)
    Consumer Technology
    In-Person
  • BigBear.ai, Inc.
    Automation Tester
    $90K — $120K *
    Ashburn, VA 20147 (Loudoun County)
    Information Technology
    In-Person
  • BigBear.ai, Inc.
    Full Stack Software Engineer
    $100K — $130K *
    Columbia, MD 21044 (Howard County)
    Information Technology
    In-Person

More Technical Services Jobs

Find similar DevSecOps Compliance Engineer jobs: