Job Title: DevSecOps Engineer
Position Type: Full-Time
Location: Hybrid (2 days onsite)
Days Remote: 3 days remote
Position Summary:The DevSecOps Engineer designs, builds, and operates secure software delivery pipelines for a large-scale federal cloud platform built on AWS. This role is responsible for implementing CI/CD pipelines, infrastructure-as-code, security automation, and deployment automation while embedding DevSecOps and shift-left security practices throughout the software development lifecycle. Working closely with developers, architects, and security teams, the DevSecOps Engineer helps deliver secure, compliant, and highly automated software releases that meet federal security and compliance requirements.
Key Responsibilities:- Design, build, and maintain secure CI/CD pipelines using AWS-native services, including AWS CodePipeline and AWS CodeBuild.
- Implement and maintain infrastructure-as-code using AWS CDK and AWS CloudFormation.
- Integrate security scanning capabilities, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), and policy-as-code into CI/CD pipelines.
- Automate compliance evidence collection to support FedRAMP and NIST security controls.
- Support automated environment provisioning and deployment strategies, including blue/green and canary deployments.
- Integrate AI-assisted development and DevSecOps tools for code scanning, testing, and pipeline automation.
- Monitor CI/CD pipeline health, reliability, and performance while driving continuous improvements in delivery metrics.
- Collaborate with development and security teams to implement secure software delivery best practices across the software development lifecycle.
Minimum Experience: - 3+ years of DevOps or DevSecOps engineering experience.
- Hands-on experience with AWS cloud services and infrastructure-as-code.
- Experience implementing CI/CD pipelines and security automation.
- Experience developing automation scripts using Python, Bash, or similar scripting languages.
Mandatory Skills: - DevSecOps.
- DevOps.
- AWS.
- AWS CodePipeline.
- AWS CodeBuild.
- AWS CDK.
- AWS CloudFormation.
- Infrastructure as Code (IaC).
- CI/CD.
- Security automation.
- Static Application Security Testing (SAST).
- Dynamic Application Security Testing (DAST).
- Software Composition Analysis (SCA).
- Policy as Code.
- FedRAMP compliance.
- NIST security controls.
- Blue/green deployments.
- Canary deployments.
- Python, Bash, or similar scripting languages.
- AI-assisted DevSecOps tools.
- Pipeline monitoring and optimization.
- U.S. work authorization.
- Ability to obtain a Public Trust clearance.
Nice-to-Have Skills: - AWS DevOps Engineer or AWS Security certification.
- FedRAMP implementation experience.
- NIST compliance experience.
- Experience using AI-assisted DevSecOps and software engineering tools.
Degrees and Certifications Preferred - AWS DevOps Engineer certification.
- AWS Security certification.