JOBSEARCHER

DevSecOps Engineer

Role: DevSecOps Engineer Company: Arch systems Client: ACF OHS Digital Services Location: Remote Type: Full-time Requirements: Federal experience is mandatory, with strong preference for candidates who have worked with HHS (Health and Human Services) or ACF (Administration for Children and Families). Candidates with existing HHS or ACF clearance will be preferred. About Role: Security-first owner of CI/CD and infrastructure in Azure/cloud.gov. You codify infra with Terraform/Ansible, operate Docker/Kubernetes, integrate security gates (Snyk/Trivy/CodeQL/Semgrep, ZAP/Burp), create SBOMs and sign (Syft/Grype/Cosign), and deliver observability (Prometheus/Grafana/New Relic). You run vuln/patch cadences, secrets rotation (Vault/External-Secrets), and DR drills with audit-ready evidence. You also integrate identity at runtime/pipeline layers (workload identity, OIDC to Okta/IdP) to harden supply chain and access. Success = safer, faster releases with strong SLO visibility and low toil. What you’ll do Build CI/CD with tests & security gates; generate SBOMs; sign and gate promotions; enforce provenance. Codify infra (Terraform/Ansible); infra tests; drift detection; peer-reviewed changes. Operate K8s (networking/TLS/ingress/autoscaling/workload identity); manage WAF/TLS and image policies. Implement policy-as-code (OPA/Kyverno) and compliance checks; assemble audit evidence. Stand up logging/metrics/tracing (Prometheus/Grafana/New Relic); craft actionable alerts & runbooks; SLO dashboards. Run vuln/patch SLAs; manage exceptions; publish remediation dashboards. Manage secrets/rotation (Vault/External-Secrets); secure supply chain; enforce signed images/manifests. Execute backup/restore & DR; document RPO/RTO; remediate gaps; chaos-style DR drills. Lead incident response & post-incident remediation; improve MTTD/MTTR. Optimize pipelines (caching/parallelism); automate toil; coach developers on container hygiene/secure coding. Identity integration: configure workload identity (OIDC) to Okta/IdP for pipelines and runtime; enforce least-privilege policies. Plan capacity & cost controls; forecast two quarters out. Minimum Qualifications Hands-on DevSecOps in cloud containers; CI/CD automation; scans; SRE/observability; ATO-style evidence. Preferred Certifications CompTIA Security+, CySA+/CASP+; (ISC)² CISSP/CCSP/CSSLP; AWS DevOps Pro, Azure AZ-400, Google PCDOE; CKA/CKAD; HashiCorp Terraform Associate. Job Type: Full-time Pay: $120,000.00 - $135,000.00 per year Work Location: Remote