TCG

DevSecOps Engineer - 4173703

TCG$140K — $155K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of DevSecOps engineering experience, with 3+ years in AWS ecosystems.
  • Expertise in Kubernetes and Docker for container management.
  • Proficient in AWS cloud security, with a focus on Zero Trust Architecture.
  • Experience with CI/CD pipeline creation using GitLab and Infrastructure as Code (Terraform or Cloud Formation).
  • Familiar with security scanning tools like Sonarqube and vulnerability management systems like Tenable.
  • Able to thrive in an agile or iterative development setting.
  • Skilled in authoring Dockerfiles for web applications, especially Java or Angular.

Responsibilities

  • Design and maintain CI/CD pipelines in AWS with tools like GitLab.
  • Manage containerized applications in AWS using Kubernetes and Docker.
  • Configure AWS environments and enforce security policies.
  • Implement security best practices across the DevSecOps lifecycle.
  • Integrate security tools (SAST and DAST) into the CI/CD pipeline.
  • Collaborate with teams to address security vulnerabilities and track progress.
  • Automate deployments and configurations using tools like Ansible.
  • Establish monitoring and logging solutions to ensure application health.

Benefits

  • Comprehensive health care coverage.
  • 401(k) retirement plan with company match.
  • Generous parental leave policies.
  • Adoption assistance program.
  • Financial planning services.
  • Student loan repayment assistance.
  • Training budget for professional development.
Full Job Description
This Position Description (PD) is for an experienced DevSecOps Engineer to help design, develop, and implement solutions for one of our government customers.

U.S. citizenship is required for this role. In addition, the selected applicant must submit to a government background investigation and be favorably adjudicated before their first day.

This is a full-time position. It is primarily a remote role. However, the selected candidate may be required to be on site occasionally and therefore must live within commuting distance of Washington, D.C.

RESPONSIBILITIES:
  • Design, implement, and maintain CI/CD pipelines in an AWS environment, leveraging tools like GitLab.
  • Manage and deploy containerized applications using Kubernetes and Docker in an AWS environment.
  • Configure and maintain AWS environments for various applications, including defining and applying baselines and security policies.
  • Implement security best practices throughout the DevSecOps lifecycle, focusing on vulnerability management and secure configuration.
  • Integrate SAST and DAST tools, such as Sonarqube and Invicti, into the CI/CD pipeline for analysis of code and container images.
  • Ensure application security specifically for containers in the Kubernetes and AWS environments.
  • Collaborate with development teams to resolve security vulnerabilities reported by tools like Tenable and track resolution progress.
  • Automate deployment and configuration management tasks across development, test, and production environments, leveraging tools like Ansible.
  • Implement and maintain monitoring and logging solutions (e.g. Splunk or ELK Stack) to ensure system uptime, performance, and application health.
  • Support platform operations, including updates, patching, and system maintenance for the underlying AWS cloud infrastructure.
  • Review and suggest improvements and changes to the current cloud architecture to aid in scaling cloud presence.

REQUIRED SKILLS:
  • Five (5) plus years of experience in DevSecOps engineering, with at least 3+ years managing and maintaining AWS ecosystems.
  • Expertise in managing and deploying containerized applications using Kubernetes and Docker.
  • Proficiency with AWS cloud security, including configuring baselines and security policies to create a Zero Trust Architecture for tools such as encrypted S3 buckets, IAM role, and service/network logging.
  • Proficiency in designing, implementing, and maintaining CI/CD pipelines using tools such as GitLab, and utilizing tools, such as Terraform or Cloud Formation, to implement an Infrastructure as Code methodology.
  • Hands-on experience with security scanning and analysis tools, including SAST/DAST (e.g., Sonarqube, Invicti) and vulnerability management (e.g., Tenable);
  • Ability to work in an agile or iterative development environment.
  • Experience authoring and debugging Dockerfiles for web applications, preferably for Docker images using Java or Angular.
  • Experience standing up and managing an AWS/Gitlab architecture, preferably in a non-DOD federal government space.

PREFERRED SKILLS:
  • DevSecOps relevant certifications in Cloud platforms (AWS preferred).
  • Experience ensuring application security for Java Spring Boot API containers.
  • Practice working with regulatory, legal, or government data sets.

EDUCATION:
  • Bachelor's degree in Information Systems, Computer Engineering, Computer Science or a related discipline.

Our B Corp mission is reflected in our benefits, including offerings like health care, 401K, parental leave, adoption assistance, financial planning services, student loan repayment assistance, and training budget. There's more, .

Salary Range: $140,000 - $155,000

About TCG

TCG Capital Management is an American investment advisory firm focused on private equity investments in the media, entertainment, technology, sports and consumer and digital media sectors.
Learn more about TCG

Similar Jobs

More Jobs at TCG

  • TCG
    DevSecOps Engineer - 4173703
    $140K — $155K *
    Washington, DC 20011 (District Of Columbia County)
    Information Technology
    In-Person
  • TCG
    Network Engineer-4134903
    $120K — $145K *
    Washington, DC 20011 (District Of Columbia County)
    Information Technology
    In-Person

More Information Technology Jobs

Find similar DevSecOps Engineer - 4173703 jobs: