DevSecOps Engineer
Indexed description
Position Overview
We are seeking a DevSecOps Engineer to support mission-critical defense and aerospace programs developing embedded real-time software and systems. The successful candidate will be a hands-on technical contributor responsible for automating software delivery pipelines, integrating cybersecurity controls into development workflows, and maintaining compliant development environments supporting classified programs.
This role collaborates closely with software, systems, cybersecurity, and platform engineering teams to enable secure, repeatable, and auditable software development practices throughout the system lifecycle.
Responsibilities
DevSecOps Implementation
- Design, build, and maintain CI/CD pipelines supporting embedded software development and test environments.
- Automate build, integration, testing, deployment, and release activities.
- Implement Infrastructure as Code (IaC) solutions for development and test environments.
- Manage source code repositories, artifact repositories, and software configuration management processes.
Security Integration
- Integrate cybersecurity controls into the Software Development Lifecycle (SDLC).
- Automate security scanning and compliance validation activities.
- Implement and maintain:
- SAST
- DAST
- Software Composition Analysis (SCA)
- Container security scanning
- Infrastructure security scanning
- Support secure coding initiatives and vulnerability remediation efforts.
Embedded Systems Support
- Support development environments for real-time and embedded software platforms.
- Enable automated testing for embedded firmware and software systems.
- Support cross-compilation environments and hardware-in-the-loop testing frameworks.
- Collaborate with systems and software engineers to streamline development workflows.
Compliance & RMF Support
- Support NIST 800-53 security control implementation.
- Participate in RMF accreditation and continuous monitoring activities.
- Assist in security assessment preparation and remediation activities.
- Support STIG compliance and vulnerability management processes.
Required Qualifications
- Bachelor's degree in Computer Science, Cybersecurity, Engineering, or related technical discipline.
- 6-10+ years of experience in DevOps, DevSecOps, Software Engineering, Systems Engineering, or related fields.
- Active Secret clearance.
- Experience supporting DoD or classified development environments.
Technical Experience
- Git, GitLab, GitHub Enterprise, or Bitbucket
- Jenkins, GitLab CI/CD, Azure DevOps, or equivalent
- Linux administration
- Docker containers
- Ansible and/or Terraform
- Python, Bash, or PowerShell scripting
- Artifact management solutions (Artifactory, Nexus)
- Security automation tools
Security Experience
- RMF
- NIST 800-53
- STIG implementation
- Vulnerability management
- Continuous monitoring concepts
- Secure software development practices
Preferred Qualifications
- Experience supporting aerospace, avionics, missile, radar, satellite, or command-and-control systems.
- Kubernetes or OpenShift experience.
- Experience with classified development networks.
- Security+ or equivalent DoD 8570 certification.
- Familiarity with Platform One or DoD DevSecOps Reference Architecture.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search