Dark Wolf is seeking a
DevSecOps Subject Matter Expert (SME) to architect, lead, and optimize Continuous Integration/Continuous Deployment (CI/CD) tooling, security paradigms, and operational observability across the entire software development lifecycle. In this role, you will serve as the principal authority on modern DevSecOps strategies, driving shift-left security practices, zero-trust architectures, and high-reliability platform engineering.
We are seeking a technical leader and strategic problem solver capable of delivering superior, high-impact results across high-performing teams in fast-paced environments.
Key Responsibilities- Enterprise CI/CD Strategy & Operations: Architect, maintain, and optimize mission-critical CI/CD pipelines and infrastructure, leveraging tools such as Jenkins, GitLab CI/CD, and enterprise automation engines.
- Automated Security Integration & Continuous ATO: Spearhead the seamless integration of dynamic security tools and automated governance into pipelines-including SAST, DAST, dependency scanning, and container analysis-to support Continuous Authority to Operate (cATO).
- Testing & Quality Framework Design: Establish and maintain comprehensive automated testing architectures covering unit testing, integration testing, and User Acceptance Testing (UAT).
- Vulnerability & Threat Remediation: Lead cross-functional collaboration with software development and security teams to proactively identify, prioritize, and remediate application and infrastructure vulnerabilities.
- Governance & Standards Compliance: Define and enforce compliance strategies aligned with federal security regulations, DoD guidelines, and strict agency security standards.
- Technical Leadership & Innovation: Drive DevSecOps roadmaps, evaluate cutting-edge tools, define infrastructure-as-code (IaC) governance, and mentor multi-disciplinary engineering teams.
Qualifications:- Clearance: Must be a US Citizen holding an active TS/SCI security clearance with an active Full-Scope Polygraph.
- Education: Bachelor's degree in Computer Science, Information Systems, Engineering, or a related technical field.
- Experience: Minimum 15+ years of total technical experience, with at least 7+ years specializing in building, securing, and maintaining automated CI/CD pipelines.
- Infrastructure Automation: Minimum 7+ years of hands-on experience using automation tools for infrastructure provisioning and configuration management (e.g., Terraform, Ansible).
- Source Control & Developer Tooling: Expert-level proficiency with version control systems and ecosystem platforms (e.g., Git, GitLab, Jira).
- Systems & Networking Mastery: Strong understanding of Containerization, Linux systems administration, kernel-level operations, and fundamental networking protocols.
- Communication & Leadership: Superior problem-solving skills and excellent communication abilities to articulate complex technical architectures, risks, and strategies to executive leadership, technical teams, and government stakeholders.
- Security Discipline: Deep commitment to adhering to strict security protocols, defensive systems design, and DoD/IC best practices.
Core SME Technical Competencies:- Continuous ATO (cATO) & Compliance-as-Code: Proven expertise translating NIST SP 800-53, DISA STIGs, and CNSSI 1253 controls into automated pipeline validation checks (e.g., using OSCAL, Open Policy Agent).
- Air-Gapped & High-Security Environment Engineering: Hands-on experience designing, deploying, and maintaining CI/CD pipelines and mirror repositories within disconnected, air-gapped, or Cross Domain Solution (CDS) networks.
- Advanced Container Orchestration Security: Expert-level knowledge of Kubernetes security architectures, Service Mesh traffic policies (Istio), Admission Controllers (OPA/Gatekeeper, Kyverno), and runtime security tooling (Falco).
- Zero Trust & Secrets Lifecycle Management: Architecture experience implementing identity-aware security models and enterprise secrets management solutions (HashiCorp Vault, AWS Secrets Manager) for automated dynamic dynamic secret rotation.
Desired Qualifications:- Programming & Scripting: Strong proficiency in programming/scripting languages such as Python, Go, Bash, or C/C++.
- Containerization: Deep practical experience with containerized software practices and container runtimes (Docker, Podman, Kubernetes).
- Agile Frameworks: Experience driving outcomes within Agile, Scrum, or SAFe software engineering methodologies.
- Multi-Cloud Architecture: Direct experience architecting secure cloud platforms across AWS, Azure, GCP, or specialized IC cloud environments (C2S/GovCloud).
- Security Scanning Tooling: Deep familiarity with modern vulnerability management and static/dynamic scanning tools (e.g., SonarQube, Snyk, Trivy, OWASP ZAP, Fortify).
Advanced Certifications:- Certified Kubernetes Security Specialist (CKS) or Certified Kubernetes Administrator (CKA)
- Certified Information Systems Security Professional (CISSP)
- AWS Certified DevOps Engineer - Professional
- CompTIA Security+ or GIAC DevSecOps Automation (GCSA)
Position Clearance Requirement: US Citizenship with an active TS/SCI security clearance with Full-Scope Polygraph
Location: Chantilly/Herndon, VA.
Target Salary Range: $185,000.00 - $240,000.00+ (Commensurate with specialized expertise and technical skillset).