{"schemaVersion":"jobsearcher.job.v1","id":"40993e4a4e36ec6544d36b0c","url":"https://jobsearcher.com/jobs/40993e4a4e36ec6544d36b0c","canonicalUrl":"https://jobsearcher.com/jobs/40993e4a4e36ec6544d36b0c","title":"DevSecOps Engineer","description":"Role: DevSecOps Engineer\nCompany: Arch systems\nClient: ACF OHS Digital Services\nLocation: Remote\nType: Full-time\nRequirements:\nFederal experience is mandatory, with strong preference for candidates who have worked with HHS (Health and Human Services) or ACF (Administration for Children and Families).\nCandidates with existing HHS or ACF clearance will be preferred.\nAbout Role:\nSecurity-first owner of CI/CD and infrastructure in Azure/cloud.gov. You codify infra with Terraform/Ansible, operate Docker/Kubernetes, integrate security gates (Snyk/Trivy/CodeQL/Semgrep, ZAP/Burp), create SBOMs and sign (Syft/Grype/Cosign), and deliver observability (Prometheus/Grafana/New Relic). You run vuln/patch cadences, secrets rotation (Vault/External-Secrets), and DR drills with audit-ready evidence. You also integrate identity at runtime/pipeline layers (workload identity, OIDC to Okta/IdP) to harden supply chain and access. Success = safer, faster releases with strong SLO visibility and low toil.\nWhat you’ll do\nBuild CI/CD with tests & security gates; generate SBOMs; sign and gate promotions; enforce provenance.\nCodify infra (Terraform/Ansible); infra tests; drift detection; peer-reviewed changes.\nOperate K8s (networking/TLS/ingress/autoscaling/workload identity); manage WAF/TLS and image policies.\nImplement policy-as-code (OPA/Kyverno) and compliance checks; assemble audit evidence.\nStand up logging/metrics/tracing (Prometheus/Grafana/New Relic); craft actionable alerts & runbooks; SLO dashboards.\nRun vuln/patch SLAs; manage exceptions; publish remediation dashboards.\nManage secrets/rotation (Vault/External-Secrets); secure supply chain; enforce signed images/manifests.\nExecute backup/restore & DR; document RPO/RTO; remediate gaps; chaos-style DR drills.\nLead incident response & post-incident remediation; improve MTTD/MTTR.\nOptimize pipelines (caching/parallelism); automate toil; coach developers on container hygiene/secure coding.\nIdentity integration: configure workload identity (OIDC) to Okta/IdP for pipelines and runtime; enforce least-privilege policies.\nPlan capacity & cost controls; forecast two quarters out.\nMinimum Qualifications\nHands-on DevSecOps in cloud containers; CI/CD automation; scans; SRE/observability; ATO-style evidence.\nPreferred Certifications\nCompTIA Security+, CySA+/CASP+; (ISC)² CISSP/CCSP/CSSLP; AWS DevOps Pro, Azure AZ-400, Google PCDOE; CKA/CKAD; HashiCorp Terraform Associate.\nJob Type: Full-time\nPay: $120,000.00 - $135,000.00 per year\nWork Location: Remote","company":"Archsystemsllc","rawCompany":"archsystemsllc","city":"Remote","state":"OR","isRemote":false,"isActive":false,"createdAt":"2026-08-04T15:15:00.575Z","occupations":[{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"DevSecOps Engineer","description":"Role: DevSecOps Engineer\nCompany: Arch systems\nClient: ACF OHS Digital Services\nLocation: Remote\nType: Full-time\nRequirements:\nFederal experience is mandatory, with strong preference for candidates who have worked with HHS (Health and Human Services) or ACF (Administration for Children and Families).\nCandidates with existing HHS or ACF clearance will be preferred.\nAbout Role:\nSecurity-first owner of CI/CD and infrastructure in Azure/cloud.gov. You codify infra with Terraform/Ansible, operate Docker/Kubernetes, integrate security gates (Snyk/Trivy/CodeQL/Semgrep, ZAP/Burp), create SBOMs and sign (Syft/Grype/Cosign), and deliver observability (Prometheus/Grafana/New Relic). You run vuln/patch cadences, secrets rotation (Vault/External-Secrets), and DR drills with audit-ready evidence. You also integrate identity at runtime/pipeline layers (workload identity, OIDC to Okta/IdP) to harden supply chain and access. Success = safer, faster releases with strong SLO visibility and low toil.\nWhat you’ll do\nBuild CI/CD with tests & security gates; generate SBOMs; sign and gate promotions; enforce provenance.\nCodify infra (Terraform/Ansible); infra tests; drift detection; peer-reviewed changes.\nOperate K8s (networking/TLS/ingress/autoscaling/workload identity); manage WAF/TLS and image policies.\nImplement policy-as-code (OPA/Kyverno) and compliance checks; assemble audit evidence.\nStand up logging/metrics/tracing (Prometheus/Grafana/New Relic); craft actionable alerts & runbooks; SLO dashboards.\nRun vuln/patch SLAs; manage exceptions; publish remediation dashboards.\nManage secrets/rotation (Vault/External-Secrets); secure supply chain; enforce signed images/manifests.\nExecute backup/restore & DR; document RPO/RTO; remediate gaps; chaos-style DR drills.\nLead incident response & post-incident remediation; improve MTTD/MTTR.\nOptimize pipelines (caching/parallelism); automate toil; coach developers on container hygiene/secure coding.\nIdentity integration: configure workload identity (OIDC) to Okta/IdP for pipelines and runtime; enforce least-privilege policies.\nPlan capacity & cost controls; forecast two quarters out.\nMinimum Qualifications\nHands-on DevSecOps in cloud containers; CI/CD automation; scans; SRE/observability; ATO-style evidence.\nPreferred Certifications\nCompTIA Security+, CySA+/CASP+; (ISC)² CISSP/CCSP/CSSLP; AWS DevOps Pro, Azure AZ-400, Google PCDOE; CKA/CKAD; HashiCorp Terraform Associate.\nJob Type: Full-time\nPay: $120,000.00 - $135,000.00 per year\nWork Location: Remote","datePosted":"2026-08-04T15:15:00.575Z","dateModified":"2026-08-04T15:15:00.575Z","hiringOrganization":{"@type":"Organization","name":"Archsystemsllc","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Remote","addressRegion":"OR","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"40993e4a4e36ec6544d36b0c"},"url":"https://jobsearcher.com/jobs/40993e4a4e36ec6544d36b0c"}}