The
DevSecOps Engineer provides security engineering expertise to Mission Partners, system owners, ISSMs/ISSOs, architects, and software development teams throughout the SDLC. The position integrates cybersecurity requirements and controls directly into Agile development and CI/CD processes, enabling development teams to identify and address security issues earlier in the lifecycle and securely move applications and capabilities from concept through production.
Essential Duties and Responsibilities:- Embed cybersecurity engineering into Agile software development and modernization activities.
- Integrate security requirements and controls throughout the SDLC and CI/CD pipelines.
- Apply DevSecOps and shift-left security principles to identify and remediate vulnerabilities earlier in development.
- Implement and support automated security testing within CI/CD workflows.
- Participate with development teams in requirements discussions, design activities, sprint planning, and other lifecycle events.
- Translate RMF, NIST SP 800-53, DoD cybersecurity policy, STIGs, SRGs, and related security requirements into actionable development and engineering tasks.
- Collaborate with developers, architects, system owners, ISSMs, and ISSOs to develop achievable technical security controls before formal assessment.
- Provide threat-informed security engineering guidance for legacy, modernized, and cloud-native applications.
- Support secure development involving APIs, microservices, containerized workloads, and other modern application architectures as applicable.
- Help development teams remediate security vulnerabilities while preserving mission functionality and delivery objectives.
- Provide engineering recommendations for technical controls such as authentication, encryption, network segmentation, and application security.
- Communicate security findings, technical risks, recommended remediation, and implementation approaches to technical and Government stakeholders.
- Manage security-engineering activities across multiple concurrent projects and development sprints.
Required Skills, Qualifications and Experience:- Bachelor's degree and 10+ years of related experience.
- DoD 8140 Work Role 652 - Security Architect Certification requirement (must have at least one of the following): Security X/CASP+CE, CCSP, Cloud+, CISSP, CSSLP, CISM, CISSP-ISSAP, CISSP-ISSIP, CSSLP, and GSEC.
- Must have and maintain a current DoD Top Secret clearance.
- Must reside within a commutable distance of Fort Meade, MD or Chambersburg, PA in order to work a hybrid onsite schedule (4 days onsite weekly).
- Demonstrated experience integrating cybersecurity into Agile SDLC environments.
- Demonstrated hands-on experience with CI/CD pipelines.
- Practical experience implementing DevSecOps and shift-left security practices.
- Experience using automated security testing tools within software development processes.
- Knowledge of RMF, NIST SP 800-37, and NIST SP 800-53.
- Knowledge and practical application of DoD STIGs and SRGs.
- Ability to convert security/compliance requirements into specific technical development tasks and controls.
- Understanding of modern application architectures and cloud-native development.
- Ability to collaborate effectively with cybersecurity, engineering, architecture, and software-development teams.
- Strong written and verbal communication skills.
- Ability to manage multiple development efforts and sprints in a high-tempo environment.
The projected salary range for this position is $130,000+ annually. Final compensation will be determined based on factors including years of relevant experience, active security clearance level, certifications, technical skillset, contract requirements, and overall qualifications.
- 26 Days Paid Leave: Includes vacation, sick, personal time, and holidays. You choose how to use it.
- Performance Bonuses: Performance bonuses are awarded based on individual contributions and company-wide results, aligning recognition with impact.
- 401(k) with Match: We match 3% of your contributions with immediate vesting.
- Financial Protection: Company-paid life insurance up to $300K and options for additional coverage for you and your dependents.
- Health Benefits: Multiple medical plans, dental, vision, FSA and HSA options to fit your needs.
- Parental Leave: 15 days of fully paid leave for new parents, because family matters.
- Military Differential Pay: We bridge the gap for employees on active duty, so they don't take a financial hit while serving.
- Professional Growth: Paid training and certifications, tuition reimbursement, and the tools and tech to get the job done right.
- Shared Success: In the event of a company sale, our CEO has committed to returning 80% of net proceeds to employees. This ensures our team shares in the long term value they help create.