{"schemaVersion":"jobsearcher.job.v1","id":"13d9c17cc0f3d27aae5309b1","url":"https://jobsearcher.com/jobs/13d9c17cc0f3d27aae5309b1","canonicalUrl":"https://jobsearcher.com/jobs/13d9c17cc0f3d27aae5309b1","title":"Cybersecurity Engineer – DevSecOps","description":"OverviewMillennium is proud to be part of the Markon enterprise, a network of specialized organizations united in support of critical national security missions. This partnership strengthens our ability to deliver results by expanding our technical depth, operational reach, and access to a broader bench of proven experts, ensuring our customers continue to receive best-in-class cybersecurity support.Since 2004, Millennium has operated at the forefront of cybersecurity. Our elite team of over 300 professionals brings an unmatched record of performance across Red Team Operations, Defensive Cyber Operations, Software Engineering, and Technical Engineering. As home to the largest contingent of contracted Red Team operators supporting the Department of Defense, Millennium delivers unparalleled threat intelligence and battle-tested expertise to both DoD and federal civilian customers.\r\nWhat We BelieveMillennium is an equal opportunity employer and does not discriminate or allow discrimination on the basis of race, color, religion, gender, age, national origin, citizenship, disability, veteran status or any other classification protected by federal, state, or local law.\r\nResponsibilitiesMillennium Corporation is seeking aCybersecurity Engineer – DevSecOpsto support cybersecurity, software assurance, and security engineering activities within a DoD/DoN environment. This position is100% remoteand will focus on integrating cybersecurity throughout the software development and delivery lifecycle, with an emphasis on application security, CI/CD pipeline security, container security, vulnerability management, and DoD cybersecurity compliance.\r\nCandidates located in or near major U.S. Navy installations are preferred, with priority given to candidates in the New Orleans, Orlando, and Washington, DC metropolitan areas. Candidates located near other major Navy facilities may also be considered.\r\nKey ResponsibilitiesConduct code and container vulnerability assessments using approved DoD vulnerability scanning tools, DISA Security Technical Implementation Guides (STIGs), Security Requirements Guides (SRGs), and other DoD/DoN software assurance tools.\r\nImplement and assess operating system security configurations in accordance with applicable DISA STIGs and SRGs.\r\nPerform cybersecurity assessments, security audits, and risk analyses to identify vulnerabilities and compliance gaps.\r\nApply security testing methodologies, includingStatic Application Security Testing (SAST)andDynamic Application Security Testing (DAST) , throughout the software development lifecycle.\r\nReview and implement cybersecurity policies and security controls withinCI/CD pipelinesto support secure software delivery and DoD/DoN requirements.\r\nServe as aGitLab security reviewer and approverfor merge requests, reviewing security scan results and verifying that identified findings are remediated or appropriately documented through the approved risk-management process prior to release.\r\nReview GitLab SAST, dependency, secret detection, and container scanning results; coordinate remediation activities with development teams and track findings through closure.\r\nReview changes to GitLab security policies, pipeline controls, and protected branch settings to ensure required security checks and approvals remain properly enforced.\r\nProvide cybersecurity oversight for containerized workloads usingNeuVector , including review of vulnerability findings, admission control decisions, and runtime security alerts.\r\nCollaborate with application and platform teams to investigate NeuVector findings, tune security policies, and document remediation actions or accepted risks.\r\nEnsure security-related provisions within system acquisition and program documentation address identified cybersecurity requirements.\r\nProvide cybersecurity guidance and assist with developing mitigation strategies for DoD information systems.\r\nPrepareRisk Management Framework (RMF) artifactsand Memoranda of Agreement (MoAs) with system owners supporting interface and networking implementations.\r\nIdentify and evaluateCommon Criteria and National Information Assurance Partnership (NIAP)certified technologies when applicable.\r\nEvaluate cybersecurity products and technologies used by programs to validate compliance with applicable DoD/DoN requirements.\r\nSupport cybersecurity activities across the software lifecycle and collaborate with engineering, development, platform, and program teams to address security requirements and risks.\r\nQualificationsActive Secret clearance.\r\nBachelor's degree with 8 years of relevant experience, or a high school diploma/equivalent with 13 years of relevant experience.\r\nExperience working within the DoD Risk Management Framework (RMF) and familiarity with DoDI 8510.01.\r\nAn Information Assurance Manager (IAM) Level II certification in accordance with DoD 8570.01-M, such as:-CISSP-GSLC-CISM\r\nExperience with DoD cybersecurity requirements, including DISA STIGs and SRGs.\r\nExperience with software security testing methodologies, including SAST and DAST.\r\nExperience supporting cybersecurity within CI/CD or DevSecOps environments.\r\nExperience with GitLab security tools and processes, including reviewing security scan results and supporting vulnerability remediation.\r\nCandidates should be located in or near a major U.S. Navy installation. Preferred locations include New Orleans, LA; Orlando, FL; and the Washington, DC metropolitan area. Candidates near other major Navy facilities may also be considered.\r\nPreferred Qualifications\r\nProficiency with GitLab, NeuVector, and Sonatype.\r\nExperience with container security and vulnerability management.\r\nExperience supporting cybersecurity within a DoD or Department of the Navy (DoN) environment.\r\nExperience with the Navy's Rapid Assess and Incorporate Software Engineering (RAISE) methodology.\r\nExperience with the RAISE Platform of Choice (RPOC).\r\nExperience evaluating Common Criteria and NIAP-certified technologies.\r\nExperience developing or supporting RMF artifacts, security documentation, and cybersecurity mitigation strategies.\r\nBusiness DevelopmentAssist with Business Development activities as required to support Millennium's strategic business objectives, which may include but not limited to participation in technical interviews, creation of technical documentation, general proposal writing support and proposal color reviews.\r\nPhysical RequirementsMust be comfortable with prolonged periods of sitting at a desk and working on a computer.\r\nMust be able to lift up to 10-15 pounds at a time.\r\nCOMPENSATION:$125,000- $135,000\r\nThe salary range provided for this position is intended as a general guideline and does not guarantee a specific salary or compensation amount. Final compensation will be determined based on a variety of factors, including, relevant education, experience, knowledge, skills, and abilities#J-18808-Ljbffr","company":"Millennium","rawCompany":"millennium","city":"Washington","state":"DC","isRemote":false,"isActive":true,"createdAt":"2026-10-05T01:33:18.058Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"541519","title":"Other Computer Related Services","slug":"other-computer-related-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Cybersecurity Engineer – DevSecOps","description":"OverviewMillennium is proud to be part of the Markon enterprise, a network of specialized organizations united in support of critical national security missions. This partnership strengthens our ability to deliver results by expanding our technical depth, operational reach, and access to a broader bench of proven experts, ensuring our customers continue to receive best-in-class cybersecurity support.Since 2004, Millennium has operated at the forefront of cybersecurity. Our elite team of over 300 professionals brings an unmatched record of performance across Red Team Operations, Defensive Cyber Operations, Software Engineering, and Technical Engineering. As home to the largest contingent of contracted Red Team operators supporting the Department of Defense, Millennium delivers unparalleled threat intelligence and battle-tested expertise to both DoD and federal civilian customers.\r\nWhat We BelieveMillennium is an equal opportunity employer and does not discriminate or allow discrimination on the basis of race, color, religion, gender, age, national origin, citizenship, disability, veteran status or any other classification protected by federal, state, or local law.\r\nResponsibilitiesMillennium Corporation is seeking aCybersecurity Engineer – DevSecOpsto support cybersecurity, software assurance, and security engineering activities within a DoD/DoN environment. This position is100% remoteand will focus on integrating cybersecurity throughout the software development and delivery lifecycle, with an emphasis on application security, CI/CD pipeline security, container security, vulnerability management, and DoD cybersecurity compliance.\r\nCandidates located in or near major U.S. Navy installations are preferred, with priority given to candidates in the New Orleans, Orlando, and Washington, DC metropolitan areas. Candidates located near other major Navy facilities may also be considered.\r\nKey ResponsibilitiesConduct code and container vulnerability assessments using approved DoD vulnerability scanning tools, DISA Security Technical Implementation Guides (STIGs), Security Requirements Guides (SRGs), and other DoD/DoN software assurance tools.\r\nImplement and assess operating system security configurations in accordance with applicable DISA STIGs and SRGs.\r\nPerform cybersecurity assessments, security audits, and risk analyses to identify vulnerabilities and compliance gaps.\r\nApply security testing methodologies, includingStatic Application Security Testing (SAST)andDynamic Application Security Testing (DAST) , throughout the software development lifecycle.\r\nReview and implement cybersecurity policies and security controls withinCI/CD pipelinesto support secure software delivery and DoD/DoN requirements.\r\nServe as aGitLab security reviewer and approverfor merge requests, reviewing security scan results and verifying that identified findings are remediated or appropriately documented through the approved risk-management process prior to release.\r\nReview GitLab SAST, dependency, secret detection, and container scanning results; coordinate remediation activities with development teams and track findings through closure.\r\nReview changes to GitLab security policies, pipeline controls, and protected branch settings to ensure required security checks and approvals remain properly enforced.\r\nProvide cybersecurity oversight for containerized workloads usingNeuVector , including review of vulnerability findings, admission control decisions, and runtime security alerts.\r\nCollaborate with application and platform teams to investigate NeuVector findings, tune security policies, and document remediation actions or accepted risks.\r\nEnsure security-related provisions within system acquisition and program documentation address identified cybersecurity requirements.\r\nProvide cybersecurity guidance and assist with developing mitigation strategies for DoD information systems.\r\nPrepareRisk Management Framework (RMF) artifactsand Memoranda of Agreement (MoAs) with system owners supporting interface and networking implementations.\r\nIdentify and evaluateCommon Criteria and National Information Assurance Partnership (NIAP)certified technologies when applicable.\r\nEvaluate cybersecurity products and technologies used by programs to validate compliance with applicable DoD/DoN requirements.\r\nSupport cybersecurity activities across the software lifecycle and collaborate with engineering, development, platform, and program teams to address security requirements and risks.\r\nQualificationsActive Secret clearance.\r\nBachelor's degree with 8 years of relevant experience, or a high school diploma/equivalent with 13 years of relevant experience.\r\nExperience working within the DoD Risk Management Framework (RMF) and familiarity with DoDI 8510.01.\r\nAn Information Assurance Manager (IAM) Level II certification in accordance with DoD 8570.01-M, such as:-CISSP-GSLC-CISM\r\nExperience with DoD cybersecurity requirements, including DISA STIGs and SRGs.\r\nExperience with software security testing methodologies, including SAST and DAST.\r\nExperience supporting cybersecurity within CI/CD or DevSecOps environments.\r\nExperience with GitLab security tools and processes, including reviewing security scan results and supporting vulnerability remediation.\r\nCandidates should be located in or near a major U.S. Navy installation. Preferred locations include New Orleans, LA; Orlando, FL; and the Washington, DC metropolitan area. Candidates near other major Navy facilities may also be considered.\r\nPreferred Qualifications\r\nProficiency with GitLab, NeuVector, and Sonatype.\r\nExperience with container security and vulnerability management.\r\nExperience supporting cybersecurity within a DoD or Department of the Navy (DoN) environment.\r\nExperience with the Navy's Rapid Assess and Incorporate Software Engineering (RAISE) methodology.\r\nExperience with the RAISE Platform of Choice (RPOC).\r\nExperience evaluating Common Criteria and NIAP-certified technologies.\r\nExperience developing or supporting RMF artifacts, security documentation, and cybersecurity mitigation strategies.\r\nBusiness DevelopmentAssist with Business Development activities as required to support Millennium's strategic business objectives, which may include but not limited to participation in technical interviews, creation of technical documentation, general proposal writing support and proposal color reviews.\r\nPhysical RequirementsMust be comfortable with prolonged periods of sitting at a desk and working on a computer.\r\nMust be able to lift up to 10-15 pounds at a time.\r\nCOMPENSATION:$125,000- $135,000\r\nThe salary range provided for this position is intended as a general guideline and does not guarantee a specific salary or compensation amount. Final compensation will be determined based on a variety of factors, including, relevant education, experience, knowledge, skills, and abilities#J-18808-Ljbffr","datePosted":"2026-10-05T01:33:18.058Z","dateModified":"2026-10-05T01:33:18.058Z","hiringOrganization":{"@type":"Organization","name":"Millennium","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Washington","addressRegion":"DC","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"13d9c17cc0f3d27aae5309b1"},"url":"https://jobsearcher.com/jobs/13d9c17cc0f3d27aae5309b1"}}