DevSecOps Engineer - SME

Dark Wolf Solutions

$185K — $240K *
Information Technology
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • Active TS/SCI security clearance with Full-Scope Polygraph
  • Bachelor's degree in Computer Science, Information Systems, Engineering, or related field
  • Minimum 15 years of technical experience; at least 7 years in CI/CD pipelines
  • 7+ years of hands-on experience with infrastructure automation tools (e.g., Terraform, Ansible)
  • Expertise in version control systems (e.g., Git, GitLab)
  • Strong understanding of Containerization and Linux systems administration
  • Excellent communication and leadership capabilities to convey complex technical concepts.

Responsibilities

  • Architect and optimize CI/CD pipelines and infrastructure using tools like Jenkins and GitLab.
  • Integrate automated security tools into CI/CD processes for continuous compliance.
  • Establish automated testing architectures including unit, integration, and UAT testing.
  • Collaborate with development and security teams to address application and infrastructure vulnerabilities.
  • Define governance strategies aligned with federal and agency security standards.
  • Drive innovation in DevSecOps roadmaps and mentor engineering teams.

Benefits

  • Opportunity to lead and influence cutting-edge DevSecOps practices.
  • Work within a high-security environment with complex technical challenges.
  • Be part of a dynamic team focused on continuous operational improvement.
  • Access to advanced tools and technologies in a rapidly evolving field.
Full Job Description
Dark Wolf is seeking a DevSecOps Subject Matter Expert (SME) to architect, lead, and optimize Continuous Integration/Continuous Deployment (CI/CD) tooling, security paradigms, and operational observability across the entire software development lifecycle. In this role, you will serve as the principal authority on modern DevSecOps strategies, driving shift-left security practices, zero-trust architectures, and high-reliability platform engineering.

We are seeking a technical leader and strategic problem solver capable of delivering superior, high-impact results across high-performing teams in fast-paced environments.

Key Responsibilities
  • Enterprise CI/CD Strategy & Operations: Architect, maintain, and optimize mission-critical CI/CD pipelines and infrastructure, leveraging tools such as Jenkins, GitLab CI/CD, and enterprise automation engines.
  • Automated Security Integration & Continuous ATO: Spearhead the seamless integration of dynamic security tools and automated governance into pipelines-including SAST, DAST, dependency scanning, and container analysis-to support Continuous Authority to Operate (cATO).
  • Testing & Quality Framework Design: Establish and maintain comprehensive automated testing architectures covering unit testing, integration testing, and User Acceptance Testing (UAT).
  • Vulnerability & Threat Remediation: Lead cross-functional collaboration with software development and security teams to proactively identify, prioritize, and remediate application and infrastructure vulnerabilities.
  • Governance & Standards Compliance: Define and enforce compliance strategies aligned with federal security regulations, DoD guidelines, and strict agency security standards.
  • Technical Leadership & Innovation: Drive DevSecOps roadmaps, evaluate cutting-edge tools, define infrastructure-as-code (IaC) governance, and mentor multi-disciplinary engineering teams.

Qualifications:
  • Clearance: Must be a US Citizen holding an active TS/SCI security clearance with an active Full-Scope Polygraph.
  • Education: Bachelor's degree in Computer Science, Information Systems, Engineering, or a related technical field.
  • Experience: Minimum 15+ years of total technical experience, with at least 7+ years specializing in building, securing, and maintaining automated CI/CD pipelines.
  • Infrastructure Automation: Minimum 7+ years of hands-on experience using automation tools for infrastructure provisioning and configuration management (e.g., Terraform, Ansible).
  • Source Control & Developer Tooling: Expert-level proficiency with version control systems and ecosystem platforms (e.g., Git, GitLab, Jira).
  • Systems & Networking Mastery: Strong understanding of Containerization, Linux systems administration, kernel-level operations, and fundamental networking protocols.
  • Communication & Leadership: Superior problem-solving skills and excellent communication abilities to articulate complex technical architectures, risks, and strategies to executive leadership, technical teams, and government stakeholders.
  • Security Discipline: Deep commitment to adhering to strict security protocols, defensive systems design, and DoD/IC best practices.

Core SME Technical Competencies:
  • Continuous ATO (cATO) & Compliance-as-Code: Proven expertise translating NIST SP 800-53, DISA STIGs, and CNSSI 1253 controls into automated pipeline validation checks (e.g., using OSCAL, Open Policy Agent).
  • Air-Gapped & High-Security Environment Engineering: Hands-on experience designing, deploying, and maintaining CI/CD pipelines and mirror repositories within disconnected, air-gapped, or Cross Domain Solution (CDS) networks.
  • Advanced Container Orchestration Security: Expert-level knowledge of Kubernetes security architectures, Service Mesh traffic policies (Istio), Admission Controllers (OPA/Gatekeeper, Kyverno), and runtime security tooling (Falco).
  • Zero Trust & Secrets Lifecycle Management: Architecture experience implementing identity-aware security models and enterprise secrets management solutions (HashiCorp Vault, AWS Secrets Manager) for automated dynamic dynamic secret rotation.

Desired Qualifications:
  • Programming & Scripting: Strong proficiency in programming/scripting languages such as Python, Go, Bash, or C/C++.
  • Containerization: Deep practical experience with containerized software practices and container runtimes (Docker, Podman, Kubernetes).
  • Agile Frameworks: Experience driving outcomes within Agile, Scrum, or SAFe software engineering methodologies.
  • Multi-Cloud Architecture: Direct experience architecting secure cloud platforms across AWS, Azure, GCP, or specialized IC cloud environments (C2S/GovCloud).
  • Security Scanning Tooling: Deep familiarity with modern vulnerability management and static/dynamic scanning tools (e.g., SonarQube, Snyk, Trivy, OWASP ZAP, Fortify).

Advanced Certifications:
  • Certified Kubernetes Security Specialist (CKS) or Certified Kubernetes Administrator (CKA)
  • Certified Information Systems Security Professional (CISSP)
  • AWS Certified DevOps Engineer - Professional
  • CompTIA Security+ or GIAC DevSecOps Automation (GCSA)

Position Clearance Requirement:

US Citizenship with an active TS/SCI security clearance with Full-Scope Polygraph

Location: Chantilly/Herndon, VA.

Target Salary Range: $185,000.00 - $240,000.00+ (Commensurate with specialized expertise and technical skillset).

Similar Jobs

More Jobs at Dark Wolf Solutions

More Information Technology Jobs

Find similar DevSecOps Engineer - SME jobs: