DevSecOps EngineerResponsibilities and Duties:
- Design, implement, and maintain secure DevSecOps pipelines that integrate security throughout the Software Development Lifecycle (SDLC).
- Lead the implementation of security controls and automation solutions supporting Digital Solution Development, Automation, and Infrastructure Support initiatives.
- Develop and maintain Continuous Integration/Continuous Delivery (CI/CD) pipelines to support rapid and secure software delivery.
- Integrate automated security testing tools, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), and container security scanning.
- Collaborate with application developers, architects, cybersecurity personnel, and infrastructure teams to embed security requirements into system designs and development processes.
- Establish and enforce secure coding practices, vulnerability management procedures, and DevSecOps best practices.
- Support cloud security architecture and automation efforts across cloud-hosted and hybrid environments.
- Design and implement Infrastructure as Code (IaC) solutions using modern automation tools and frameworks.
- Conduct security assessments, code reviews, architecture reviews, and risk analyses for applications and infrastructure platforms.
- Monitor, analyze, and remediate security vulnerabilities identified through automated scanning and assessment tools.
- Develop and maintain security baselines, secure configuration standards, and deployment templates.
- Support containerization and orchestration technologies, including security hardening and compliance monitoring activities.
- Lead security-related technical projects and provide technical guidance to project teams and stakeholders.
- Collaborate with system administrators, network engineers, and developers to ensure secure deployment and operation of enterprise systems.
- Support Authority to Operate (ATO), FISMA, NIST, FedRAMP, and other compliance-related activities as applicable.
- Develop security automation capabilities to improve detection, response, monitoring, and reporting functions.
- Participate in incident response, root cause analysis, and corrective action planning activities.
- Mentor junior engineers and provide technical leadership on information security initiatives.
- Create and maintain technical documentation, architecture diagrams, operational procedures, and security implementation guides.
- Evaluate emerging DevSecOps, cloud, and security technologies and recommend improvements to organizational security posture.
- Support enterprise modernization, automation, and digital transformation initiatives by ensuring security is integrated from design through deployment.
- Develop security metrics, dashboards, and reports to communicate program health, risk posture, and compliance status to leadership.
Basic Qualifications
- Bachelor's Degree in Computer Science, Information Technology, Cybersecurity, Computer Engineering, or a related field.
- Minimum of eight (8) years of progressive experience in information security, cybersecurity engineering, or related disciplines. Minimum of two (2) years of experience providing technical leadership for information security projects.
- Experience supporting DoD information systems and Security Technical Implementation Guide (STIG) compliance programs.
- Develop and maintain automation scripts and Infrastructure as Code (IaC) templates to enforce STIG-compliant configurations across enterprise environments.
- Experience implementing DevSecOps practices within Agile, DevSecOps, or CI/CD environments.
- Experience with security automation tools, vulnerability management platforms, and secure software development methodologies.
- Knowledge of secure coding standards, application security principles, and security testing methodologies.
- Experience with CI/CD platforms such as Azure DevOps, Jenkins, GitLab, GitHub Actions, or similar technologies.
- Experience supporting cloud environments, including Microsoft Azure, AWS, or Google Cloud Platform (GCP).
- Familiarity with Infrastructure as Code (IaC) technologies such as Terraform, Ansible, CloudFormation, or ARM Templates.
- Knowledge of containerization and orchestration technologies such as Docker, Kubernetes, and OpenShift.
- Strong understanding of NIST Cybersecurity Framework, NIST 800-53, RMF, FISMA, and related federal security standards.
- Experience identifying, assessing, and mitigating application and infrastructure security risks.
- Strong analytical, troubleshooting, and problem-solving skills.
- Excellent written, verbal, and presentation communication skills.
- Ability to work effectively across multidisciplinary technical and business teams.
- U.S. Citizen, and ability to get the clearance.
Preferred Qualifications
- Experience supporting Department of Homeland Security (DHS) and/or Cybersecurity and Infrastructure Security Agency (CISA) programs.
- Experience designing and implementing Zero Trust architectures and modern cloud security solutions.
- Knowledge of Infrastructure Automation, Platform Engineering, and Site Reliability Engineering (SRE) practices.
- Experience supporting FedRAMP, Continuous Diagnostics and Mitigation (CDM), or enterprise cybersecurity programs.
- Hands-on experience with SIEM, SOAR, and security monitoring technologies.
- Relevant certifications such as CISSP, CCSP, AWS Security Specialty, Azure Security Engineer Associate, GIAC certifications, Certified DevSecOps Professional, Security+, or equivalent.
- Experience supporting enterprise modernization, application transformation, and infrastructure automation programs.