Logistics Management Institute

Senior DevSecOps Engineer

Logistics Management Institute • $122K — $200K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor’s degree in computer science, engineering, information security, or a related field.
  • Significant experience in DevOps, DevSecOps, platform engineering, site reliability engineering, or release engineering.
  • Advanced experience designing and operating GitLab CI/CD pipelines.
  • Strong Linux and shell-scripting skills.
  • Experience supporting build, test, and packaging workflows for JavaScript/TypeScript, Python, or Rust.
  • Hands-on experience with automated security scanning, vulnerability management, and CI/CD quality gates.
  • Experience building, scanning, signing, and publishing OCI container images.
  • Strong Kubernetes experience and familiarity with Azure or AWS.

Responsibilities

  • Design and maintain reusable GitLab CI/CD pipelines and templates.
  • Integrate automated testing, code-quality checks, and security scanning with various tools.
  • Build secure workflows for scanning, signing, and publishing containers and packages to Nexus.
  • Develop cross-platform release processes, including packaging, signing, and versioning.
  • Deploy and operate Kubernetes workloads across multiple cloud environments.
  • Support elastic and high-performance computing workloads.
  • Manage dependency updates and remediate vulnerabilities across various platforms.

Benefits

  • Collaborative work environment with engineering, security, and infrastructure teams.
  • Opportunity to establish reusable CI/CD standards and improve software delivery processes.
  • Exposure to a variety of technologies including GitLab, Kubernetes, and cloud providers.
  • Focus on enhancing security protocols without sacrificing delivery speed.
Full Job Description
Overview

We are seeking a Senior DevSecOps Engineer to build and improve secure software delivery, release engineering, and deployment platforms. This role will maintain GitLab CI/CD pipelines for TypeScript/JavaScript, Python, and Rust applications across Linux, Windows, and macOS.

 

The ideal candidate combines strong CI/CD and cloud-native engineering experience with practical application-security expertise. They will partner with engineering, security, and infrastructure teams to make secure, reliable delivery the default throughout the software development lifecycle.

 

Responsibilities
  • Design and maintain reusable GitLab CI/CD pipelines and templates.
  • Integrate automated testing, code-quality checks, and security scanning using tools such as SonarQube, Vitest, Playwright, Cypress, pytest, Cargo, Trivy, Sonatype, OWASP tools, and KICS.
  • Build secure workflows for scanning, signing, attesting, and publishing containers and packages to Nexus.
  • Develop cross-platform release processes, including packaging, signing, versioning, and artifact promotion.
  • Deploy and operate Kubernetes workloads across on-premises, Azure, and AWS environments.
  • Support elastic and high-performance computing workloads using platforms such as Slurm and Azure CycleCloud.
  • Manage dependency updates and remediate vulnerabilities across applications, containers, build systems, and infrastructure.
  • Establish practical security policies, remediation timelines, exceptions, and release quality gates.
  • Improve pipeline reliability, performance, documentation, and developer self-service capabilities.
  • Partner with engineering teams to strengthen security without unnecessarily slowing delivery.
Qualifications

Required Qualifications

  • Bachelor’s degree in computer science, engineering, information security, or a related field.
  • Significant experience in DevOps, DevSecOps, platform engineering, site reliability engineering, or release engineering.
  • Advanced experience designing and operating GitLab CI/CD pipelines.
  • Strong Linux and shell-scripting skills.
  • Experience supporting build, test, and packaging workflows for JavaScript/TypeScript, Python, or Rust.
  • Hands-on experience with automated security scanning, vulnerability management, and CI/CD quality gates.
  • Experience building, scanning, signing, and publishing OCI container images.
  • Experience with artifact repositories such as Sonatype Nexus Repository.
  • Strong Kubernetes experience and familiarity with Azure or AWS.
  • Working knowledge of infrastructure as code and configuration management.
  • Experience creating releases for Linux, Windows, or macOS.
  • Strong troubleshooting, documentation, communication, and cross-team collaboration skills.

Preferred Qualifications

  • Experience with Slurm, Azure CycleCloud, HPC, or compute-intensive workloads.
  • Familiarity with Helm, Kustomize, Terraform, Ansible, or similar tools.
  • Experience with SBOMs, artifact provenance, SLSA, Sigstore/Cosign, or code-signing systems.
  • Knowledge of OWASP, CWE, CVE, CVSS, CIS benchmarks, NIST guidance, and secure SDLC practices.
  • Experience with dependency automation, self-hosted GitLab runners, observability, or incident response.
  • Relevant cloud, Kubernetes, security, or GitLab certifications.

What Success Looks Like

Within the first year, the successful candidate will:

  • Establish reusable CI/CD standards across supported platforms and languages.
  • Increase automated testing and security coverage while improving pipeline reliability and speed.
  • Deliver secure, repeatable container, package, and cross-platform release workflows.
  • Improve vulnerability ownership, prioritization, and remediation.
  • Strengthen the consistency and resilience of Kubernetes and HPC deployments.
  • Enable teams to deliver secure software with less manual intervention.

 

Target salary range: $122,000 - $200,000

 

Disclaimer: 

The salary range displayed represents the typical salary range for this position and is not a guarantee of compensation. Individual salaries are determined by various factors including, but not limited to location, internal equity, business considerations, client contract requirements, and candidate qualifications, such as education, experience, skills, and security clearances.

Job LocationsUS-CO-Colorado Springs

About Logistics Management Institute

Logistics Management Institute (LMI) is a consulting firm dedicated to improving the management of government. LMI provides leaders with the objective analysis, tools, and programs they need to make informed decisions for their organizations. LMI is a not-for-profit organization that has been providing innovative solutions to complex problems since 1961. LMI serves clients in the federal government, state and local governments, and the private sector.
Learn more about Logistics Management Institute
Size
1,700 employees
Industry

Similar Jobs

More Jobs at Logistics Management Institute

More Information Technology Jobs

Find similar Senior DevSecOps Engineer jobs: