{"schemaVersion":"jobsearcher.job.v1","id":"394d744165d12a7a11f1a092","url":"https://jobsearcher.com/jobs/394d744165d12a7a11f1a092","canonicalUrl":"https://jobsearcher.com/jobs/394d744165d12a7a11f1a092","title":"DevSecOps Engineer","description":"1 week ago Be among the first 25 applicants\nThis range is provided by SOC LLC. Your actual pay will be based on your skills and experience — talk with your recruiter to learn more.\nBase pay range $65.00/hr - $85.00/hr\nDirect message the job poster from SOC LLC\nTechnical Recruiter at SOC LLC, Expert in #TechnicalRecruiting #SecurityClearanceTalent #FederalServices #Cybersecurity DevSecOps Engineer needed for a contract to hire opportunity with SOC’s client to work onsite in Malibu, CA\n*Active TS/SCI is required for the role*\nRESPONSIBILITIES:\nDesign, implement, and maintain advanced cybersecurity controls and solutions directly within DevSecOps pipelines and associated toolchains (e.g., GitLab, Artifactory, Ansible, SonarQube)\nConfigure, integrate, and optimize security tools such as GitLab's SAST/DAST, Artifactory X-Ray, Tenable, Cortex XSIAM, and SonarQube to automate vulnerability detection, code quality analysis, and artifact security\nTranslate complex security requirements, including those derived from Risk Management Framework (RMF) and Information Assurance (IA) policies, into actionable technical designs and implementation strategies for software systems\nProvide expert-level technical guidance and hands-on assistance to DevSecOps engineers and software developers on secure coding practices, vulnerability remediation, threat modeling, and building security into CI/CD workflows\nDevelop and implement automated security testing procedures (e.g., unit tests, integration tests, fuzzing, penetration testing) to ensure continuous security validation\nConduct technical deep dives into software architectures and development practices to identify security weaknesses and propose effective mitigation strategies across multi-classification networks\nCollaborate with ISSOs to ensure technical security implementations align with overall security policy, accreditation requirements, and compliance standards\nManage security configurations of development, test, and production environments, ensuring adherence to baselines and addressing configuration drift\nResearch, evaluate, and recommend new security technologies, tools, and best practices to enhance the security posture of our DevSecOps ecosystem\nDevelop custom security scripts, automation, and integrations to streamline security processes and improve operational efficiency\nParticipate in incident response activities related to software vulnerabilities and security breaches within the development and deployment pipelines\nDocument technical security implementations, architectural designs, and standard operating procedures for secure DevSecOps practices\nREQUIRED QUALIFICATIONS :\nActive Top Secret (TS/SCI) security clearance\nMinimum of 7 years of experience in a highly technical cybersecurity role, such as Security Engineer, DevSecOps Engineer, or Software Security Engineer\nMinimum of 3 years of hands-on, in-depth experience securing DevSecOps pipelines and integrating security tools\nDemonstrable expertise with GitLab, including extensive experience configuring and utilizing its SAST and DAST capabilities\nProven experience with Artifactory, specifically leveraging Artifactory X-Ray for software composition analysis (SCA) and vulnerability management\nDeep technical knowledge and hands-on experience with SonarQube for static code analysis and code quality gates\nExpertise in implementing and enforcing the Secure Software Development Framework (SSDF) and secure SDLC principles\nStrong understanding of secure coding practices, common vulnerabilities (e.g., OWASP Top 10), and remediation techniques\nProficiency in scripting and automation using languages such as Python, Bash, PowerShell, or similar\nExperience securing systems operating on multiple government networks with varying classification levels and understanding of data diode security implications\nComprehensive technical understanding of the Risk Management Framework (RMF) and Information Assurance (IA) principles as they apply to system implementation and security control mapping\nFamiliarity with containerization technologies (e.g., Docker, Kubernetes) and their security best practices\nExcellent problem-solving skills, with the ability to diagnose and resolve complex technical security issues\nStrong collaboration and communication skills, capable of working effectively with development, operations, and security teams\nPREFFERED QUALIFICATIONS :\nA current Top Secret/SCI security clearance\nExperience with other security testing tools (e.g., dynamic application security testing (DAST) tools, penetration testing tools, fuzzing tools)\nBackground in software development or system administration is a plus, providing a stronger foundation for DevSecOps integration\nExperience with Infrastructure as Code (IaC) and its security implications\nKnowledge of supply chain security best practices for software\nEDUCATION:\nBachelor’s degree in computer science, Cybersecurity, Information Technology, or a related technical discipline. (Relevant experience and certifications may be considered in lieu of a degree for exceptionally qualified candidates.)\nDoD 8570.01-M IAT Level II (or higher) certification (e.g., CompTIA Security+, CySA+, GICSP, GSEC, CISSP)\nRelevant technical security certifications such as CSSLP, GCSA, GWAPT, OSCP, or equivalent\nEmployment Prerequisites\nThe following requirements must be met to be eligible for this position: successful completion of a background investigation and drug urinalysis.\nSOC, a Day & Zimmermann company, is an Equal Opportunity Employer, EOE AA M/F/Vet/Disability.\nNote: Any pay ranges displayed are estimations, which may have been provided by job boards. Actual pay is determined by an applicant’s experience, technical expertise, and other qualifications as listed in the job description. All qualified applicants are welcome to apply.\nEstimated Min Rate : $49.00\nSeniority level Seniority level Mid-Senior level\nEmployment type Employment type Full-time\nJob function Industries Defense and Space Manufacturing\nReferrals increase your chances of interviewing at SOC LLC by 2x\nSign in to set job alerts for “Cyber Security Engineer” roles. Analyst, Information Security - Training & Awareness Culver City, CA $70,000.00-$93,000.00 2 weeks ago\nBeverly Hills, CA $120,000.00-$150,000.00 1 week ago\nBurbank, CA $126,400.00-$169,500.00 2 weeks ago\nSecurity & Governance Analyst - Identity & Access Management Burbank, CA $114,900.00-$154,100.00 1 week ago\nCamarillo, CA $120,000.00-$153,000.00 2 weeks ago\nWe're Hiring! Cybersecurity Analyst (Mid-Level) Santa Monica, CA $95,000.00-$120,000.00 6 days ago\nCybersecurity Operations Specialist - Hybrid Beverly Hills, CA $94,390.40-$151,028.80 2 weeks ago\nSr. Engineer, Information Security (Cloud Security) Culver City, CA $120,000.00-$150,000.00 2 weeks ago\nSecurity Engineer (Identity and Access Management) Hawthorne, CA $130,000.00-$150,000.00 3 weeks ago\nMalibu, CA $99,705.00-$124,683.00 1 week ago\nInformation Security Analyst II - FT Days We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.\n\n#J-18808-Ljbffr","company":"Soc","rawCompany":"soc","city":"Malibu","state":"CA","isRemote":false,"isActive":false,"createdAt":"2026-07-16T03:49:08.258Z","occupations":[{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"DevSecOps Engineer","description":"1 week ago Be among the first 25 applicants\nThis range is provided by SOC LLC. Your actual pay will be based on your skills and experience — talk with your recruiter to learn more.\nBase pay range $65.00/hr - $85.00/hr\nDirect message the job poster from SOC LLC\nTechnical Recruiter at SOC LLC, Expert in #TechnicalRecruiting #SecurityClearanceTalent #FederalServices #Cybersecurity DevSecOps Engineer needed for a contract to hire opportunity with SOC’s client to work onsite in Malibu, CA\n*Active TS/SCI is required for the role*\nRESPONSIBILITIES:\nDesign, implement, and maintain advanced cybersecurity controls and solutions directly within DevSecOps pipelines and associated toolchains (e.g., GitLab, Artifactory, Ansible, SonarQube)\nConfigure, integrate, and optimize security tools such as GitLab's SAST/DAST, Artifactory X-Ray, Tenable, Cortex XSIAM, and SonarQube to automate vulnerability detection, code quality analysis, and artifact security\nTranslate complex security requirements, including those derived from Risk Management Framework (RMF) and Information Assurance (IA) policies, into actionable technical designs and implementation strategies for software systems\nProvide expert-level technical guidance and hands-on assistance to DevSecOps engineers and software developers on secure coding practices, vulnerability remediation, threat modeling, and building security into CI/CD workflows\nDevelop and implement automated security testing procedures (e.g., unit tests, integration tests, fuzzing, penetration testing) to ensure continuous security validation\nConduct technical deep dives into software architectures and development practices to identify security weaknesses and propose effective mitigation strategies across multi-classification networks\nCollaborate with ISSOs to ensure technical security implementations align with overall security policy, accreditation requirements, and compliance standards\nManage security configurations of development, test, and production environments, ensuring adherence to baselines and addressing configuration drift\nResearch, evaluate, and recommend new security technologies, tools, and best practices to enhance the security posture of our DevSecOps ecosystem\nDevelop custom security scripts, automation, and integrations to streamline security processes and improve operational efficiency\nParticipate in incident response activities related to software vulnerabilities and security breaches within the development and deployment pipelines\nDocument technical security implementations, architectural designs, and standard operating procedures for secure DevSecOps practices\nREQUIRED QUALIFICATIONS :\nActive Top Secret (TS/SCI) security clearance\nMinimum of 7 years of experience in a highly technical cybersecurity role, such as Security Engineer, DevSecOps Engineer, or Software Security Engineer\nMinimum of 3 years of hands-on, in-depth experience securing DevSecOps pipelines and integrating security tools\nDemonstrable expertise with GitLab, including extensive experience configuring and utilizing its SAST and DAST capabilities\nProven experience with Artifactory, specifically leveraging Artifactory X-Ray for software composition analysis (SCA) and vulnerability management\nDeep technical knowledge and hands-on experience with SonarQube for static code analysis and code quality gates\nExpertise in implementing and enforcing the Secure Software Development Framework (SSDF) and secure SDLC principles\nStrong understanding of secure coding practices, common vulnerabilities (e.g., OWASP Top 10), and remediation techniques\nProficiency in scripting and automation using languages such as Python, Bash, PowerShell, or similar\nExperience securing systems operating on multiple government networks with varying classification levels and understanding of data diode security implications\nComprehensive technical understanding of the Risk Management Framework (RMF) and Information Assurance (IA) principles as they apply to system implementation and security control mapping\nFamiliarity with containerization technologies (e.g., Docker, Kubernetes) and their security best practices\nExcellent problem-solving skills, with the ability to diagnose and resolve complex technical security issues\nStrong collaboration and communication skills, capable of working effectively with development, operations, and security teams\nPREFFERED QUALIFICATIONS :\nA current Top Secret/SCI security clearance\nExperience with other security testing tools (e.g., dynamic application security testing (DAST) tools, penetration testing tools, fuzzing tools)\nBackground in software development or system administration is a plus, providing a stronger foundation for DevSecOps integration\nExperience with Infrastructure as Code (IaC) and its security implications\nKnowledge of supply chain security best practices for software\nEDUCATION:\nBachelor’s degree in computer science, Cybersecurity, Information Technology, or a related technical discipline. (Relevant experience and certifications may be considered in lieu of a degree for exceptionally qualified candidates.)\nDoD 8570.01-M IAT Level II (or higher) certification (e.g., CompTIA Security+, CySA+, GICSP, GSEC, CISSP)\nRelevant technical security certifications such as CSSLP, GCSA, GWAPT, OSCP, or equivalent\nEmployment Prerequisites\nThe following requirements must be met to be eligible for this position: successful completion of a background investigation and drug urinalysis.\nSOC, a Day & Zimmermann company, is an Equal Opportunity Employer, EOE AA M/F/Vet/Disability.\nNote: Any pay ranges displayed are estimations, which may have been provided by job boards. Actual pay is determined by an applicant’s experience, technical expertise, and other qualifications as listed in the job description. All qualified applicants are welcome to apply.\nEstimated Min Rate : $49.00\nSeniority level Seniority level Mid-Senior level\nEmployment type Employment type Full-time\nJob function Industries Defense and Space Manufacturing\nReferrals increase your chances of interviewing at SOC LLC by 2x\nSign in to set job alerts for “Cyber Security Engineer” roles. Analyst, Information Security - Training & Awareness Culver City, CA $70,000.00-$93,000.00 2 weeks ago\nBeverly Hills, CA $120,000.00-$150,000.00 1 week ago\nBurbank, CA $126,400.00-$169,500.00 2 weeks ago\nSecurity & Governance Analyst - Identity & Access Management Burbank, CA $114,900.00-$154,100.00 1 week ago\nCamarillo, CA $120,000.00-$153,000.00 2 weeks ago\nWe're Hiring! Cybersecurity Analyst (Mid-Level) Santa Monica, CA $95,000.00-$120,000.00 6 days ago\nCybersecurity Operations Specialist - Hybrid Beverly Hills, CA $94,390.40-$151,028.80 2 weeks ago\nSr. Engineer, Information Security (Cloud Security) Culver City, CA $120,000.00-$150,000.00 2 weeks ago\nSecurity Engineer (Identity and Access Management) Hawthorne, CA $130,000.00-$150,000.00 3 weeks ago\nMalibu, CA $99,705.00-$124,683.00 1 week ago\nInformation Security Analyst II - FT Days We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.\n\n#J-18808-Ljbffr","datePosted":"2026-07-16T03:49:08.258Z","dateModified":"2026-07-16T03:49:08.258Z","hiringOrganization":{"@type":"Organization","name":"Soc","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Malibu","addressRegion":"CA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"394d744165d12a7a11f1a092"},"url":"https://jobsearcher.com/jobs/394d744165d12a7a11f1a092"}}