DevSecOps Engineer

Fortreum

$155K — $205K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years of experience in DevOps, Platform Engineering, or Site Reliability Engineering
  • Hands-on experience architecting AWS infrastructure using Terraform
  • Strong production expertise in Kubernetes, including EKS and GitOps workflows
  • Experience with FedRAMP, CMMC, or NIST compliance environments
  • Familiarity with OSCAL compliance frameworks
  • Proficient in integrating security scanning tools in CI/CD pipelines
  • Scripting skills in Python, Bash, or similar languages
  • U.S. Citizenship with ability to secure a Top Secret clearance

Responsibilities

  • Design and maintain CI/CD pipelines for secure software delivery
  • Manage cloud infrastructure using Infrastructure as Code (Terraform)
  • Administer container workloads with Kubernetes/EKS and ArgoCD
  • Implement security controls aligned to NIST 800-53 standards
  • Develop observability strategies for production reliability
  • Integrate DevOps tools into automated compliance workflows
  • Collaborate with engineering teams to maintain continuous authorization posture
  • Support continuous monitoring and prepare for audits

Benefits

  • Medical, dental, and vision insurance
  • 401K plan with 4% match
  • Company-paid short-term and long-term disability insurance
  • Company-paid life insurance and AD&D
  • Flex time off policy
  • Annual bonuses and training stipends
  • Certification reimbursements and access to extensive online training resources
  • Personal cell phone allowance and home office stipend
  • Spot awards and eleven paid holidays
Full Job Description
The Opportunity

On our team, you will have the opportunity to work with industry-leading experts who've supported the world's most security-conscious organizations. As a DevSecOps Engineer, you will embed with enterprise and federal customers to deploy, integrate, and operationalize the Kovr AI Platform within their environments-building integrations with their DevSecOps toolchains, automating evidence collection and continuous monitoring, and configuring compliance workflows that accelerate Authority to Operate (ATO). You will serve as the hands-on technical bridge between our customers and Kovr's engineering team, solving complex deployment challenges across cloud, hybrid, and classified National Security and Intelligence Community (IC) environments..

Key Responsibilities
  • Design, build, and maintain CI/CD pipelines supporting rapid, secure software delivery
  • Manage cloud infrastructure (AWS, with exposure to Azure/GCP) using Infrastructure as Code (Terraform), including module design and reusable patterns for the broader team
  • Administer and scale containerized workloads (Kubernetes/EKS, Helm, ArgoCD)
  • Implement and maintain security controls and monitoring aligned to NIST 800-53 and OSCAL-based frameworks
  • Design observability strategy (logging, metrics, alerting, SLOs) to support production reliability at scale
  • Integrate DevOps tooling (GitHub, JIRA, Splunk, Snyk) into automated compliance and remediation workflows
  • Collaborate with existing engineering and compliance teams to ensure infrastructure changes maintain continuous authorization posture
  • Support continuous monitoring and audit-readiness activities, including evidence collection and control mapping
  • Troubleshoot production issues and drive continuous improvement in deployment reliability
  • Build and maintain documentation, runbooks, and architecture decision records
  • Represent infrastructure/security in cross-functional planning, including customer-facing technical conversations when needed
Basic Qualifications
  • 7+ years of DevOps, Platform Engineering, or Site Reliability Engineering experience
  • Hands-on experience architecting AWS infrastructure using Terraform at scale
  • Strong production experience with Kubernetes (EKS or similar), including cluster design, Helm Charts, and GitHub/GitOps workflows
  • Direct experience with FedRAMP, CMMC, NIST 800-53/800-171, or DoD SRG compliance environments
  • Familiarity with OSCAL or other machine-readable compliance/documentation frameworks
  • Experience integrating SAST/DAST or IaC security scanning into a pipeline
  • Scripting/automation proficiency (Python, Bash, or similar)
  • U.S. Citizenship, with the ability to obtain and maintain a Top Secret clearance
  • Comfortable working in a fast-moving startup-within-a-company environment
  • Local to Washington, DC metro area
Preferred Qualifications
  • Existing security or cloud certifications (Security+, AWS Certified Security, CYSA+, CISSP)
  • Experience integrating LLM coding agents, MCPs, and automations into DevOps workflows
  • Prior experience holding or maintaining a Top Secret security clearance
  • Background supporting federal DevSecOps deployments or highly regulated commercial clients Charts
Posted Salary Range

$155,000 - $205,000 annual salary

What Fortreum Offers

We offer a competitive compensation package, where you will be rewarded based on your performance/outcomes and recognized for the value you bring to our business. Our benefits package includes medical insurance, dental insurance, vision insurance, 401K plan with a 4% match, company paid short-term disability, company paid long-term disability, company paid AD&D and life insurance, flex time off, annual bonuses, training stipends, certification reimbursements, access to over 30,000 free online training courses, personal cell phone allowance, new hire and annual home office stipend, spot awards and eleven paid holidays.

Similar Jobs

More Jobs at Fortreum

More Information Technology Jobs

Find similar DevSecOps Engineer jobs: