{"schemaVersion":"jobsearcher.job.v1","id":"621d0ce06a5d6c72fd64a571","url":"https://jobsearcher.com/jobs/621d0ce06a5d6c72fd64a571","canonicalUrl":"https://jobsearcher.com/jobs/621d0ce06a5d6c72fd64a571","title":"DevSecOps Engineer","description":"About Metron\nMetron is an employee‑owned company dedicated to delivering innovative solutions for the most challenging national security problems. For over 40 years, our principled approach to problem‑solving has yielded creative solutions at the intersection of advanced mathematics, computer science, physics, and engineering. Our people are leaders in their technical fields and are passionate about solving challenging problems. We look for individuals who share this same passion and can apply their experience in real‑world settings.\n\nJob Description\nOur Reston, VA office isseeking a DevSecOpsEngineer to help secure and improve software delivery across the enterprise. This role focuses on embedding security, quality, compliance, and software supply‑chain controls into CI/CD workflows while partnering with software development, cybersecurity, platform engineering, systems engineering, and program teams.\n\nThis is an engineering role, not a pure governance or vulnerability‑management position. The DevSecOpsEngineer will work across Azure DevOps Server, Nexus, SonarQube, Kubernetes/K3s deployment workflows, artifact controls, and secure release patterns to help teams deliver software securely and reliably.\n\nOccasional after‑hours/weekend maintenance and emergency response may be required.\n\nSecure CI/CD & Release Workflows\n\nDesign, implement, and improve secure CI/CD patterns in Azure DevOps, including reusable YAML templates, quality gates, artifact controls, and release safeguards\n\nSupport secure release workflows across development, test, integration, staging, and production environments\n\nTroubleshoot pipeline failures, permissions issues, dependency problems, scan failures, and release blockers\n\nSoftware Supply Chain & Security Controls\n\nIntegrate security and quality checks into build and release workflows, including SAST, SCA, dependency scanning, secrets scanning, code‑quality gates, container scanning, and artifact validation\n\nSupport tools such as Nexus, SonarQube, Azure DevOps artifacts, and related code‑quality or artifact‑management platforms\n\nPartner with cybersecurity to align CI/CD controls with SSP, RMF, NIST, CMMC, STIG, Zero Trust, audit, and program requirements\n\nKubernetes Guardrails & Developer Enablement\n\nPartner with platform engineering on secure Kubernetes/K3s deployment standards, including namespaces, RBAC, ServiceAccounts, Helm, ingress, TLS, storage, quotas, and workload security\n\nCreate documentation, examples, runbooks, and onboarding materials for secure pipeline and deployment workflows\n\nTrack recurring developer pain points, pipeline health, scan outcomes, release blockers, and control gaps; turn findings into automation, templates, documentation, or improved guardrails\n\nRequired Qualifications\n\n5+ years of experience in DevOps, DevSecOps, platform engineering, software delivery, systems engineering, or a closely related technical role\n\nHands‑on experience with Azure DevOps pipelines, YAML, build/release workflows, repositories, artifacts, permissions, or agent‑based builds\n\nExperience implementing security, quality, or compliance controls in CI/CD workflows\n\nExperience with secure software delivery practices such as SAST, SCA, dependency scanning, secrets handling, code‑quality gates, artifact controls, or container scanning\n\nExperience troubleshooting CI/CD failures, build issues, deployment problems, permissions issues, or dependency‑related errors\n\nExperience with Kubernetes, K3s, containers, Helm, or similar deployment technologies\n\nExperience with scripting or automation using PowerShell, Bash, Python, or similar languages\n\nAbility to write clear technical documentation, runbooks, onboarding guides, and troubleshooting procedures\n\nEligible to obtain and maintain a U.S. security clearance\n\nWilling and able to work in regulated, secure, or compliance‑bounded environments\n\nPreferred Qualifications\n\nActive U.S. security clearance\n\nExperience with Azure DevOps Server\n\nExperience integrating or administering Nexus, SonarQube, or similar artifact and code‑quality platforms\n\nExperience with SBOM generation, SCA, container scanning, artifact signing, provenance, or software supply‑chain security\n\nExperience with policy‑as‑code, OPA/Gatekeeper, Kubernetes admission controls, or secure workload policies\n\nExperience with Infrastructure‑as‑Code or Configuration‑as‑Code practices using Terraform, Ansible, Bicep, CloudFormation, or similar tools\n\nExperience with Prometheus, Grafana, Loki, or similar observability platforms\n\nExperience in defense contracting, government programs, CMMC, NIST 800‑171, RMF, STIGs, or other compliance‑driven environments\n\nPosition Location: Reston, VA (the selected individual will be expected to work onsite in the Reston, VA office)\n\nPerks and Benefits\n\nMedical, Dental and Vision Insurance\n\nAccompanying FSA and HSA options\n\nAdditional Voluntary Benefits\n\nPaid Time Off\n\n9 Observed Holidays and 2 Floating Holidays\n\nPaid Parental Leave\n\nMilitary Leave\n\nTuition Reimbursement\n\nProfessional Development Reimbursement\n\nAnnual Salary Reviews\n\nProfit Sharing\n\n401(k) Traditional and Roth Options\n\nGym and Fitness Reimbursement\n\nEmployee Assistance Program\n\nEmployee Referral Program\n\nMetron is an Equal Employment Opportunity (EEO) employer. It is the policy of the company to provide equal employment opportunities to all qualified applicants without regard to race, color, religious, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status, or genetic information.\n\nVEVRAA Federal Contractor\n\n#J-18808-Ljbffr","company":"Metron As","rawCompany":"metron as","city":"Reston","state":"VA","isRemote":false,"isActive":false,"createdAt":"2026-07-16T03:22:05.791Z","occupations":[{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"DevSecOps Engineer","description":"About Metron\nMetron is an employee‑owned company dedicated to delivering innovative solutions for the most challenging national security problems. For over 40 years, our principled approach to problem‑solving has yielded creative solutions at the intersection of advanced mathematics, computer science, physics, and engineering. Our people are leaders in their technical fields and are passionate about solving challenging problems. We look for individuals who share this same passion and can apply their experience in real‑world settings.\n\nJob Description\nOur Reston, VA office isseeking a DevSecOpsEngineer to help secure and improve software delivery across the enterprise. This role focuses on embedding security, quality, compliance, and software supply‑chain controls into CI/CD workflows while partnering with software development, cybersecurity, platform engineering, systems engineering, and program teams.\n\nThis is an engineering role, not a pure governance or vulnerability‑management position. The DevSecOpsEngineer will work across Azure DevOps Server, Nexus, SonarQube, Kubernetes/K3s deployment workflows, artifact controls, and secure release patterns to help teams deliver software securely and reliably.\n\nOccasional after‑hours/weekend maintenance and emergency response may be required.\n\nSecure CI/CD & Release Workflows\n\nDesign, implement, and improve secure CI/CD patterns in Azure DevOps, including reusable YAML templates, quality gates, artifact controls, and release safeguards\n\nSupport secure release workflows across development, test, integration, staging, and production environments\n\nTroubleshoot pipeline failures, permissions issues, dependency problems, scan failures, and release blockers\n\nSoftware Supply Chain & Security Controls\n\nIntegrate security and quality checks into build and release workflows, including SAST, SCA, dependency scanning, secrets scanning, code‑quality gates, container scanning, and artifact validation\n\nSupport tools such as Nexus, SonarQube, Azure DevOps artifacts, and related code‑quality or artifact‑management platforms\n\nPartner with cybersecurity to align CI/CD controls with SSP, RMF, NIST, CMMC, STIG, Zero Trust, audit, and program requirements\n\nKubernetes Guardrails & Developer Enablement\n\nPartner with platform engineering on secure Kubernetes/K3s deployment standards, including namespaces, RBAC, ServiceAccounts, Helm, ingress, TLS, storage, quotas, and workload security\n\nCreate documentation, examples, runbooks, and onboarding materials for secure pipeline and deployment workflows\n\nTrack recurring developer pain points, pipeline health, scan outcomes, release blockers, and control gaps; turn findings into automation, templates, documentation, or improved guardrails\n\nRequired Qualifications\n\n5+ years of experience in DevOps, DevSecOps, platform engineering, software delivery, systems engineering, or a closely related technical role\n\nHands‑on experience with Azure DevOps pipelines, YAML, build/release workflows, repositories, artifacts, permissions, or agent‑based builds\n\nExperience implementing security, quality, or compliance controls in CI/CD workflows\n\nExperience with secure software delivery practices such as SAST, SCA, dependency scanning, secrets handling, code‑quality gates, artifact controls, or container scanning\n\nExperience troubleshooting CI/CD failures, build issues, deployment problems, permissions issues, or dependency‑related errors\n\nExperience with Kubernetes, K3s, containers, Helm, or similar deployment technologies\n\nExperience with scripting or automation using PowerShell, Bash, Python, or similar languages\n\nAbility to write clear technical documentation, runbooks, onboarding guides, and troubleshooting procedures\n\nEligible to obtain and maintain a U.S. security clearance\n\nWilling and able to work in regulated, secure, or compliance‑bounded environments\n\nPreferred Qualifications\n\nActive U.S. security clearance\n\nExperience with Azure DevOps Server\n\nExperience integrating or administering Nexus, SonarQube, or similar artifact and code‑quality platforms\n\nExperience with SBOM generation, SCA, container scanning, artifact signing, provenance, or software supply‑chain security\n\nExperience with policy‑as‑code, OPA/Gatekeeper, Kubernetes admission controls, or secure workload policies\n\nExperience with Infrastructure‑as‑Code or Configuration‑as‑Code practices using Terraform, Ansible, Bicep, CloudFormation, or similar tools\n\nExperience with Prometheus, Grafana, Loki, or similar observability platforms\n\nExperience in defense contracting, government programs, CMMC, NIST 800‑171, RMF, STIGs, or other compliance‑driven environments\n\nPosition Location: Reston, VA (the selected individual will be expected to work onsite in the Reston, VA office)\n\nPerks and Benefits\n\nMedical, Dental and Vision Insurance\n\nAccompanying FSA and HSA options\n\nAdditional Voluntary Benefits\n\nPaid Time Off\n\n9 Observed Holidays and 2 Floating Holidays\n\nPaid Parental Leave\n\nMilitary Leave\n\nTuition Reimbursement\n\nProfessional Development Reimbursement\n\nAnnual Salary Reviews\n\nProfit Sharing\n\n401(k) Traditional and Roth Options\n\nGym and Fitness Reimbursement\n\nEmployee Assistance Program\n\nEmployee Referral Program\n\nMetron is an Equal Employment Opportunity (EEO) employer. It is the policy of the company to provide equal employment opportunities to all qualified applicants without regard to race, color, religious, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status, or genetic information.\n\nVEVRAA Federal Contractor\n\n#J-18808-Ljbffr","datePosted":"2026-07-16T03:22:05.791Z","dateModified":"2026-07-16T03:22:05.791Z","hiringOrganization":{"@type":"Organization","name":"Metron As","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Reston","addressRegion":"VA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"621d0ce06a5d6c72fd64a571"},"url":"https://jobsearcher.com/jobs/621d0ce06a5d6c72fd64a571"}}