DevSecOps Engineer
Indexed description
We're looking for a hands-on DevSecOps Engineer to join our Release Engineering team. You’ll work across DevOps, cloud infrastructure, security, and compliance, to build secure AWS environments, improve deployment and release workflows, and support FedRAMP and other government security requirements.
If you're technically curious, security-minded, and comfortable moving between DevOps engineering and security/compliance work, we'd love to talk.
What You'll Do
- Build, operate, assess, and secure AWS environments against established security baselines, FedRAMP requirements, and other applicable security standards.
- Partner with Software Engineering and AI teams to incorporate security and compliance requirements into system architecture, CI/CD, deployment, and operational workflows.
- Support FedRAMP authorization and continuous monitoring activities, including evidence collection, control maintenance, audit preparation, Plans of Action and Milestones (POA&Ms), and remediation tracking.
- Perform and support security architecture reviews, risk and gap assessments, vulnerability management, and system hardening, including applicable DISA STIGs.
- Implement security controls across networking, Linux systems, IAM, encryption, logging, and security monitoring.
- Build and maintain Infrastructure as Code, CI/CD, deployment, and release automation using tools such as Terraform, Pulumi, and Python, incorporating security and compliance into repeatable infrastructure deployments.
- Maintain required security documentation, system diagrams, asset inventories, and control implementation details.
- Work with engineering teams, external assessors, compliance partners, and 3PAOs to support assessments, audits, evidence requests, and ongoing authorization requirements.
- Contribute to broader Release Engineering initiatives, including CI/CD pipelines, deployment automation, release workflows, cloud infrastructure, developer tooling, and platform reliability.
Required
- 3-6 years of experience in security engineering, cloud security, DevSecOps, infrastructure security, or a related technical field.
- Hands-on AWS experience, including networking, Linux, IAM, encryption, logging, vulnerability management, and security monitoring.
- Experience working with one or more security frameworks such as FedRAMP, NIST 800-53, NIST 800-171, CMMC, RMF, or similar standards.
- Experience translating security and compliance requirements into practical technical controls alongside engineering teams.
- Hands-on experience with DevOps practices, Infrastructure as Code, source control, CI/CD pipelines, and automated deployment workflows.
- Knowledge of system hardening vulnerability remediation, secure configurations, and security control lifecycle management.
- Strong problem-solving, communication, and cross-functional collaboration skills.
- Enjoys being hands-on with infrastructure, automation, security, and release engineering.
- Can move comfortably between technical implementation, compliance requirements, documentation, and conversations with engineers and assessors.
- Take ownership of issues from identification through remediation and closure.
- Prefers building security into engineering workflows rather than treating it as a separate audit function.
- Is curious about how complex systems work and looks for ways to make security and compliance more automated, repeatable, and scalable.
- Direct experience supporting a FedRAMP authorization, particularly within a FedRAMP High environment.
- Familiarity with AWS GovCloud and NIST 800-53 Experience working directly with external assessors, compliance partners, or a Third-Party Assessment Organization (3PAO).
- Understanding FIPS 140, encryption and key management, secure system boundaries, and requirements associated with Controlled Unclassified Information (CUI).
- Experience hardening Linux operating systems using DISA STIGs or similar security configuration standards.
- Experience with Infrastructure as Code technologies such as Terraform or Pulumi, and/or Python automation.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search