Job Title: Senior DevSecOps Engineer
Job Category: Information Technology
Time Type: Full time
Minimum Clearance Required to Start: Secret
Employee Type: Regular
Percentage of Travel Required: Up to 10%
Type of Travel: Local
* * *
The Opportunity:
Join a high-performing DevSecOps team supporting our DoD/AF customer in delivering, securing, and operating cloud-native enterprise platforms. This role centers on Kubernetes platform engineering, Big Bang deployment and sustainment, Terraform-based Infrastructure as Code, GitOps, and secure CI/CD automation across mission-critical environments.
Responsibilities:
- Deploy, configure, and sustain Kubernetes-based platforms and mission applications using Big Bang, Helm, and GitOps deployment practices.
- Develop and maintain Terraform-based Infrastructure as Code (IaC) for cloud infrastructure, Kubernetes resources, networking, IAM, and platform services.
- Build, secure, and optimize CI/CD pipelines for application and infrastructure delivery, including reusable pipeline templates, automated testing, and controlled release promotion.
- Triage, prioritize, remediate, and validate infrastructure, container, and application security findings in accordance with established vulnerability-management SLAs.
- Implement and maintain hardened Kubernetes and cloud configuration baselines aligned with DISA STIGs, NIST 800-53, RMF, and organizational security requirements.
- Manage Kubernetes security controls, including RBAC, network policies, pod security standards, admission controls, secrets management, and secure ingress/egress configurations.
- Maintain GitOps workflows using Git as the authoritative source for infrastructure and platform configuration; ensure deployed environments remain aligned with approved code.
- Monitor CI/CD platforms, runners, deployments, and Kubernetes workloads; troubleshoot build, deployment, performance, and availability issues.
- Develop automated patching, configuration management, and compliance-validation processes to reduce manual effort and configuration drift.
- Produce security and operational documentation, including architecture diagrams, implementation procedures, scan evidence, remediation plans, and POA&M updates.
- Support RMF and ATO lifecycle activities by collecting control evidence, addressing assessment findings, and maintaining continuous-monitoring artifacts.
Qualifications:
Required:
- U.S Citizen with eligibility for Secret Clearance
- At least 7 years of relevant professional experience with a related degree
- Strong experience developing and maintaining Terraform modules and reusable Infrastructure as Code patterns for cloud, network, and Kubernetes resources.
- Experience implementing GitOps workflows with tools such as Argo CD, Flux, GitLab, GitHub, or similar platforms.
- 3–5 years experience designing and deploying Kubernetes-based solutions; Big Bang is a plus.
- Experience with CI/CD pipelines, containerization, and secure DevSecOps practices.
- Strong familiarity with DISA STIGs, RMF, NIST SP 800-53, ATO processes, POA&M management, continuous monitoring, and security compliance evidence generation.
Desired:
- 5–10 years of experience in DevSecOps, platform engineering, cloud engineering, SRE, or software delivery roles.
- Experience with CAC authentication, PIV tokens, and client-side PKI certificate handling.
- Experience with AWS cloud services, including EKS, IAM, VPC, EC2, S3, Route 53, CloudWatch, load balancers, and security services.
- Proficiency in Python, Bash, PowerShell, Go, or similar languages for automation, tooling, and operational support.
- Relevant certifications such as CKA, CKAD, CKS, HashiCorp Terraform Associate, AWS certifications, Security+, CISSP, or CCSP.
- Experience with ATO/accreditation processes.
- Familiarity with scanning and compliance tools like RMF, ACAS, Twistlock, Prisma Cloud.
- Proven ability to work across multi-tenant identity services, supporting thousands of users and integrating with microservices.
-
Pay Range:
There are a host of factors that can influence final salary including, but not limited to, geographic location, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, education, and certifications. Our employees value the flexibility at CACI that allows them to balance quality work and their personal lives. We offer competitive compensation, benefits and learning and development opportunities. Our broad and competitive mix of benefits options is designed to support and protect employees and their families. At CACI, you will receive comprehensive benefits such as; healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits.
Since this position can be worked in more than one location, the range shown is the national average for the position.
The proposed salary range for this position is:
$98,500-$206,800