Full Job Description
Sr. DevSecOps Engineer III to work onsite in support of a government contract for a client located in Reston, VA. An active TS/SCI clearance with CI Polygraph is required.
Responsibilities
• Collaborate with customers and internal teams to design and implement automatic technical solutions across multiple classification environments, working independently or as part of the team to address complex technical requirements.
• Develop CI/CD pipelines from scratch in GitLab CI and Jenkins with integrated security scanning and STIG compliance validation, providing expert guidance to development teams on pipeline troubleshooting and implementing DevSecOps best practices.
• Create and maintain Infrastructure as Code (IaC) templates primarily using CloudFormation to architect highly available, resilient, and secure DevSecOps tool infrastructure across AWS environments (GovCloud, C2S, TC2S) while ensuring STIG compliance and guiding junior engineers on IaC best practices.
• Lead advanced troubleshooting efforts by analyzing system and application logs using Linux command-line tools, conducting root cause analysis for complex issues, and developing mitigation strategies for service degradation.
• Provide expert security guidance to development teams on secure coding practices, STIG compliance, vulnerability remediation, and other best practices in support of their ATO efforts.
• Architect and build secure containerized solutions by designing Docker images with security best practices, implementing and optimizing OpenShift deployments and configurations, remediating Prisma security findings, and providing guidance to development teams on container orchestration and best practices.
• Perform code reviews and knowledge sharing while maintaining technical documentation, promoting best practices, and fostering continuous team improvement.
Required Skills and Qualifications
• Active TS/SCI security clearance with CI Polygraph.
• 10+ years of experience as a DevSecOps Engineer or similar role, with a strong focus on infrastructure automation, scalability, and reliability across the software development lifecycle.
• Expert experience with DevOps practices, CI/CD pipelines, containerization, and other automation tools (e.g., Jenkins, GitLab CI/CD, Artifactory, SonarQube, and Prisma Cloud).
• Strong experience with scripting languages (e.g., Python, Bash), in a Linux environment (RHEL, Oracle Linux, or similar).
• Strong experience with infrastructure as code (IaC) tools such as Terraform, CloudFormation, or Ansible.
• Experience with Tier 1 - 3 customer support and ticketing systems, such as GitLab Service Desk and ServiceNow.
• Expert experience delivering DevSecOps services across multiple classified domains.
• Expert understanding of AWS capabilities (EC2, S3, IAM, RDS, etc) and architecting secure cloud-based infrastructure and services (familiarity with other cloud platforms a plus).
• Hands-on experience configuring applications and systems to comply with Secure Technical Implementation Guides (STIG), Security Requirements Guide (SRG) by implementing security best practices.
• Knowledge of security best practices, common vulnerabilities, and exposure to security frameworks (e.g., OWASP, NIST, OpenSCAP).
• Ability to work independently and communicate with stakeholders across a global enterprise and cross-functional teams to drive project completion.
• Minimum IAT Level 2 Certification (CompTIA Security+, GSEC, SSCP, ETC.)
GH 1008
Full-Time Employee Compensation
• M9 Solutions' pay range for this position is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include, but are not limited to, responsibilities of the position, education, experience, knowledge, skills, abilities, as well as internal equity, location, alignment with market data, applicable bargaining agreement (if any), or other law.
• M9 Benefits - https://m9solutions.com/why-join-m9/#our-benefits
Salary Range
$200,000-$220,000 USD