DevSecOps & Release Engineer
Indexed description
As we continue to grow, Swarm Defense is looking for a self-starting DevSecOps & Release Engineer to own the pipelines, releases and security practices behind our software. Our integrated software suite powers every stage of our operations, from mission design and field deployment to fleet management and real-time command interfaces. It ships to desktops, Android devices, ground station hardware and drones in the field. In this role, you'll build the systems that take code from review to a signed, versioned and verified release on every one of those targets. You'll also help us develop and deliver software in a controlled (CUI) environment.
We're a small, close-knit team, and we care as much about who you are as what you can build. We're looking for someone who communicates openly, takes feedback well, and makes the people around them better.
How to Apply
To apply please include your resume in the linkedin apply. Cover Letters are preferred but not required.
If you're not sure what to write for the cover letter, here are some things we'd love to hear about: a problem you identified and solved before anyone asked you to, a time you learned a new technology quickly, or simply why this kind of work excites you.
We read every application personally. To separate yourself from the noise, send your resume and an optional cover letter directly to [email protected]. It is a small thing that tells us a lot.
Key Responsibilities
- Own and evolve our CI/CD pipelines, covering Go, TypeScript/React, desktop, Android and embedded firmware builds across Linux, macOS and Windows.
- Define and enforce versioning, branching and release policy across both software and firmware.
- Design and build a secure, automated update system for our desktop apps, mobile apps, ground station hardware and drones, supporting both over-the-air and physical (wired or offline media) update methods.
- Build security into the development workflow: dependency and vulnerability scanning, static analysis, secret scanning, SBOM generation and artifact signing.
- Lead the setup and upkeep of a development environment suitable for Controlled Unclassified Information (CUI), aligned with NIST SP 800-171 and CMMC. You'll work with leadership on the policies and documentation this requires.
- Administer source control and build infrastructure: repository permissions, branch protection, code owners, self-hosted runners and secrets management.
- Partner with the software and firmware teams to bring software-in-the-loop (SITL) and hardware-in-the-loop (HITL) testing into the pipeline.
- Support security reviews, customer questionnaires, and configuration management documentation.
- Participate in field testing opportunities as needed.
Requirements
- Proof of US citizenship required. Ability to obtain and maintain a security clearance preferred.
- 4+ years of professional experience in DevOps, build and release, or platform engineering.
- Hands-on experience building and maintaining CI/CD pipelines on a modern platform such as GitLab CI, GitHub Actions or Jenkins.
- Strong Linux, shell scripting and Docker skills. You're comfortable reading and debugging Go, TypeScript or Python builds.
- Experience with semantic versioning, release management, and git workflows at scale.
- Working knowledge of application security tooling (for example CodeQL, Dependabot, Trivy, gitleaks or govulncheck) and secure secrets handling.
- Familiarity with NIST SP 800-171, CMMC, or other DoD cybersecurity frameworks.
- Clear technical writing. You'll write the runbooks and policies the rest of the team follows.
- Demonstrated ability to collaborate on complex software projects with many moving parts.
- Effective communicator comfortable working with technical and non-technical team members.
Bonus Points
- Experience standing up a CUI enclave, self-hosted source control and CI platforms, or an AWS GovCloud environment.
- Code signing and notarization for Windows and macOS, and Android release signing.
- Update systems for embedded devices, both over-the-air and physical or offline (for example Mender, SWUpdate or RAUC).
- Managing releases for both software and firmware, including PX4 or other embedded firmware pipelines.
- Infrastructure-as-code experience (Terraform, Ansible or similar).
- Prior work at a defense contractor, including ITAR/EAR awareness.
- Experience working with AI code development tools across the software development workflow.
Benefits
- Relocation Assistance: We offer financial support to help with your move, ensuring a smooth transition as you join our team.
- Comprehensive Health Benefits: We cover 100% of health insurance premiums for our employees.
- Retirement Plan: We offer a Simple IRA with employer contributions to help you plan for your future.
Swarm Defense is a rapidly expanding business operating in a dynamic and fast-paced environment that presents fresh challenges driven by project needs and customer feedback. Our team is passionate and deeply invested in the work we do, taking pride in the innovative products we build. We believe in rewarding initiative and encourage team members to take ownership of projects and explore areas that align with their passions. Whether it's improving existing systems or pioneering new ideas, our culture fosters creativity, autonomy, and continuous growth.
Swarm Defense is a sister company to Firefly Drone Shows and Systems, with an engineering team that works across both companies.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search