Ernst & Young

Government and Infrastructure - Cybersecurity - DevSecOps Engineer

Ernst & Young • $99K — $148K *
Education, Government & Non-Profit
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in computer science, software engineering, information systems, or related field, or equivalent experience
  • 2+ years in DevOps, software engineering, or security engineering
  • Hands-on experience with CI/CD pipeline tools like Jenkins, GitHub Actions, or Azure DevOps
  • Familiarity with application security scanning tools such as Fortify or Snyk
  • Working knowledge of containers and Infrastructure-as-Code
  • Scripting skills in Python, PowerShell, or Bash
  • Understanding of NIST Risk Management Framework and secure software development practices

Responsibilities

  • Assess application delivery toolchains and identify gaps in security practices
  • Evaluate application security posture and recommend rationalization strategies
  • Design and maintain secure CI/CD pipelines with integrated security testing
  • Implement policy-as-code and automate evidence collection for compliance
  • Harden container images against security benchmarks
  • Integrate governance gates for AI-assisted development
  • Support vulnerability triage and collaborate with cybersecurity stakeholders

Benefits

  • Comprehensive compensation and benefits package based on performance
  • Flexible vacation policy allowing for personal circumstances
  • Medical and dental coverage, pension and 401(k) plans
  • Paid time off for designated holidays and personal care
  • Career-long training and coaching for skill development
Full Job Description
Government and Infrastructure - Technology Consulting - Cybersecurity - DevSecOps Engineer - Consultant

From strategy to execution, the Government & Infrastructure of Ernst & Young provides a full range of consulting and audit services to help our Federal, State, Local and Education clients implement new ideas to help achieve their mission outcomes. We deliver real change and measurable results through our diverse, high-performing teams, quality work at the highest professional standards, operational know-how from across our global organization, and creative and bold ideas that drive innovation. We enable our government clients to achieve their mission of protecting the nation and serving the people; increasing public safety; improving healthcare for our military, veterans and citizens; delivering essential public services; and helping those in need. EY is ready to help our government build a better working world.

The opportunity

Our cybersecurity professionals possess diverse industry knowledge, along with unique technical expertise and specialized skills. The team works together in planning, pursuing, delivering and managing engagements to assess, improve, build, and in some cases operate integrated security operations for our clients.

We will support you with career-long training and coaching to develop your skills. As EY is a global leading service provider in this space, you will be working with the best of the best in a collaborative environment. So, whenever you join, however long you stay, the exceptional EY experience lasts a lifetime.

Your key responsibilities

Our cybersecurity professionals possess diverse industry knowledge, along with unique technical expertise and specialized skills. The team stays highly relevant by researching and discovering the newest security vulnerabilities, attending and speaking at top security conferences around the world, and sharing knowledge on a variety of cybersecurity topics with key industry groups. The team frequently provides thought leadership and information exchanges through traditional and less conventional communications channels such as speaking at conferences and publishing white papers.

The DevSecOps Engineer assesses the delivery and security maturity of each application in the portfolio and builds the secure pipelines, controls and automated evidence that the modernization factory runs on. This role ensures that security is built into how software is delivered - not added afterwards - and that rationalization recommendations reflect each application's true security posture and delivery risk.
• Assess each application's delivery toolchain and practices - source control, build and release automation (for example, Jenkins and Bitbucket), artifact management (Artifactory), code quality (SonarQube), Infrastructure-as-Code and configuration management (Terraform, Ansible) and monitoring (Datadog) - and identify manual release processes and gaps.
• Assess application security posture as an input to rationalization, including open vulnerabilities, outdated or vulnerable dependencies, software bill of materials (SBOM) availability, secrets handling, authentication patterns and open plans of action and milestones (POA&Ms).
• Design, build and maintain secure CI/CD pipelines for the modernization factory with integrated static and dynamic application security testing (SAST/DAST), software composition analysis, container image scanning, Infrastructure-as-Code scanning, secrets detection and quality gates.
• Implement policy-as-code and automated evidence collection that support continuous Authorization to Operate (cATO) and NIST SP 800-53 control traceability.
• Harden container images and environments against applicable security configuration benchmarks (DISA STIGs or CIS Benchmarks).
• Integrate governance gates for AI-assisted development, including provenance, human review and traceability of AI-generated code.
• Define reference DevSecOps patterns and reusable pipeline templates for future modernization waves, and report delivery and security metrics (for example, DORA metrics and vulnerability aging).
• Support vulnerability triage and remediation guidance and collaborate with client cybersecurity and authorization stakeholders.

Skills and attributes for success

  • Convey complex technical security concepts to technical and non-technical audiences including executives.

• Experience with Design, building and maintaining secure CI/CD pipelines for the modernization factory with integrated static and dynamic application security testing (SAST/DAST), software composition analysis, container image scanning, Infrastructure-as-Code scanning, secrets detection and quality gates.

To qualify for the role you must have
• Bachelor's degree in computer science, software engineering, information systems, computer engineering or a related field, or equivalent practical experience
• 2+ years of experience in DevOps, software engineering or security engineering
• Hands-on CI/CD pipeline engineering with Jenkins, GitHub Actions, GitLab CI or Azure DevOps.
• Experience with at least one application security scanning tool (for example, Fortify, Checkmarx, SonarQube, Snyk, Trivy or OWASP ZAP).
• Working knowledge of containers and Infrastructure-as-Code.
• Scripting in Python, PowerShell or Bash.
• Understanding of the NIST Risk Management Framework, NIST SP 800-53 and secure software development lifecycle practices.
• Must be able to obtain and maintain a secret level clearance
• Must be comfortable with working in-person as needed in the Washington, DC area

Due to the nature of our work in the Government and Public Sector, work may be required to be completed at client, EY and/or contractor sites. Our goal is to assign professionals to projects within a commutable distance of their work location office. In certain circumstances, travel may be required beyond your work location based on client and project needs. Candidates should be willing to travel 20 - 30% or more.

Ideally, you'll also have
• Experience supporting continuous ATO or FedRAMP authorizations and managing POA&Ms.
• Kubernetes security and policy engines (OPA/Gatekeeper, Azure Policy).
• SBOM tooling and standards (CycloneDX, SPDX).
• Certifications such as CompTIA Security+, CISSP, CCSP, Certified Kubernetes Security Specialist (CKS) or relevant GIAC certifications.

What we offer you

At EY, we harness our collective strength to empower you to shape your future with confidence through professional growth, personal fulfillment and an inclusive culture. Learn more at ey.com/us/careers.
  • We offer a comprehensive compensation and benefits package where you'll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job is:
    • New York City, Boston, and Washington DC Metro Areas, Washington State, and Southern California offices - $99,100 to $148,500
    • Bay Area California offices - $103,100 to $154,600
    • All other offices locations in the US, including Sacramento - $82,500 to $136,000
  • Individual salaries within these ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Under our flexible vacation policy, you'll decide how much vacation time you need based on your own personal circumstances. You'll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.

Are you ready to shape your future with confidence? Apply today.
  • To make the most of your application experience, please limit yourself to two applications within a six-month period.
  • EY accepts applications for this position on an on-going basis.
  • For those living in California, please click here for additional information.
  • At EY, our values set the foundation for how we work and the behaviors we expect of our people. Any misrepresentation or falsification of information or lack of integrity at any point in the recruiting process may result in withdrawal of your candidacy, revocation of an offer or immediate termination of employment.

About Ernst & Young

Ernst & Young (EY) is a multinational professional services firm that provides audit, tax, consulting, and advisory services to clients in a wide range of industries. The firm was founded in 1989 through the merger of Ernst & Whinney and Arthur Young & Co., and has since grown to become one of the largest professional services firms in the world. EY is committed to building a better working world by helping its clients solve their toughest challenges, and by creating a positive impact on the communities it serves.
Learn more about Ernst & Young
Size
300,000 employees
Industry
Founded
1989

Similar Jobs

More Jobs at Ernst & Young

More Education, Government & Non-Profit Jobs

Find similar Government and Infrastructure - Cybersecurity - DevSecOps Engineer jobs: