DevSecOps Engineer - Remote
Required Skills & ExperienceRequired Qualifications:Bachelor's degree and four (4) years of specialized information technology experience; OR o In lieu of bachelor's degree, eight (8) years of relevant information technology experience, with at least four (4) years in a specialized experienceHands-on experience building and maintaining secure CI/CD pipelines, including automated security testing, vulnerability scanning, secrets detection, artifact signing, and release gates.Experience with security automation tools such as SAST, SCA, DAST, container scanning, IaC scanning, secrets scanning, SBOM generation, and policy-as-code.Ability to write scripts, pipeline logic, configuration, or automation in support of security and compliance objectives.Hands-on experience securing AWS cloud environments including EKS, S3, VPC, Security Hub, Inspector, WAF, and Secrets ManagerExperience producing security and compliance evidence for federal environments, including continuous monitoring artifacts, control evidence, vulnerability reports, and audit-ready documentationUnderstanding of the Authority to Operate (ATO) process, including POA&Ms and continuous monitoring.Understanding of federal security frameworks such as NIST RMFExperience working on a fully integrated Agile product teamStrong documentation and problem-solving skillsAbility to work in a fast-paced, team-oriented environmentExperience with Atlassian Jira/Confluence50-80HExact compensation may vary based on several factors, including skills, experience, and education.Employees in this role will enjoy a comprehensive benefits package starting on day one ofemployment, including options for medical, dental, and vision insurance. Eligibility to enroll inthe 401(k) retirement plan begins after 90 days of employment. Additionally, employees in thisrole will have access to paid sick leave and other paid time off benefits as required under theapplicable law of the worksite location.Job DescriptionRole Overview:We are seeking a hands-on DevSecOps Engineer to join a cross-functional, entrepreneurial, collaborative team dedicated to solving difficult problems for our clients. This individual will have experience with RMF through implementation and customization of controls in a DevSecOps pipeline and tech stack. Additionally, this individual will have experience implementing controls as applicable and understand how they will affect the tech stack within the DevSecOps pipeline. The role is primarily focused on being the DevSecOps engineer within the product team but must be able to ensure that the security controls are in place and work with the security team to validate controls and evidence.Responsibilities:Partner with the development team to implement secure engineering patterns, maintain secure CI/CD pipelines, and remediate vulnerabilities, including contributing code, configuration, pipeline changes, and infrastructure updates where appropriate.Design and maintain security gates for code quality, dependency scanning, container image scanning, secrets detection, infrastructure misconfiguration, and policy compliance.Support Kubernetes and container security for AWS EKS environments, including image hardening, admission controls, runtime monitoring, network policies, workload identity, secrets management, and least-privilege access patterns.Support controls for new tooling/integration usage, the handling of sensitive data, and access controls.Help define and enforce secure-by-default engineering standards across the application, infrastructure, and delivery pipeline.Help drive the move toward ATO and near-real-time compliance.Implement monitoring of production runtime environments for vulnerabilities and compliance drift and make security and compliance reporting available on demand.Translate security findings into actionable engineering work items in JIRA and support teams through remediation, validation, and closure.Identify, document, and communicate security risks tied to modernization effortsMonitor cloud environments using AWS toolsParticipates in Agile processes including daily standups, demos, retrospectives, and sprint planningCollaborates with a fully integrated Agile team to deliver continuous improvement to designs, processes, and standards