{"schemaVersion":"jobsearcher.job.v1","id":"646b7e6444bfbe995ae1dbbf","url":"https://jobsearcher.com/jobs/646b7e6444bfbe995ae1dbbf","canonicalUrl":"https://jobsearcher.com/jobs/646b7e6444bfbe995ae1dbbf","title":"Mid-Level DevSecOps Engineer","description":"GRVTY is seeking a Mid-level DevSecOps Engineer with a TS/SCI to join one of our top projects in Herndon, VA, to support the development, integration, and cybersecurity compliance of intelligence capabilities in Development and Production environments. This is a software engineering-focused DevSecOps role. The primary focus is designing, coding, testing, and maintaining software and automation tools that streamline Cyber Security workflows and improve the reliability of our platforms. We are looking for a candidate with a software development background who can build scalable, reliable systems and developer tools, and contribute to DevSecOps pipelines that integrate and deploy components across multiple networks into private cloud infrastructures hosted for our government customer.\nAs a GRVTY team member, you will closely support our mission partners, and your work will have direct mission impact. You will work with DevSecOps engineers, software developers, infrastructure technicians, and cybersecurity professionals to use open-source technology to create and maintain the full stack of a High-Performance Computing (HPC) system that hosts applications for thousands of users.\nWhat You'll be Owning\n\nDeploy and manage highly available applications to ensure system reliability and scalability.\nImplement and maintain HashiCorp Nomad and Kubernetes clusters for workload orchestration.\nExecute DNS configuration, management, and performance tuning for enterprise-grade systems.\nDevelop and implement Infrastructure-as-Code (IaC) solutions using tools like Terraform, Ansible, or similar.\nBuild and manage multiple CI/CD pipelines with GitLab or equivalent tools to automate deployments and streamline development workflows for rapid development and integration\nPerform system monitoring, logging, and troubleshooting to proactively identify and resolve issues.\nAutomate security testing and monitoring within the DevOps workflows using ACAS and Trivy.\nAnalyze cybersecurity scan findings and work with the cybersecurity team to identify false positives.\nAssist the cybersecurity team in assembling the required Body of Evidence for False Positive exceptions.\nAssist the cybersecurity team in assembling the required Body of Evidence to submit containerized and non-containerized software packages for enterprise software approval.\nIntegrate static code analysis tools such as GitLab SAST, Fortify, or SonarQube and other security mechanisms into CI/CD pipelines.\nBuild and maintain software tools that automate cybersecurity analysis and correlation workflows as compliance requirements evolve.\nPerform cybersecurity remediation on DevSecOps-managed virtual machines, including OS patching, OS STIG implementation, and software package updates.\nBuild, maintain, and monitor configuration management of release products.\nTroubleshoot and resolve issues in networks, automation pipelines, and infrastructure.\n\nWhat You Must Have\n\nActive TS/SCI and be willing and able to pass a CI polygraph\nMust be able and willing to work 40 hours per week in a SCIF in Herndon, Virginia.\nAt least 3 years of industry experience in software development or software engineering.\nAt least 5 years of industry experience in DevSecOps, with a bachelor’s degree in Computer Science, Information Systems, or a related field; or a master’s degree and at least 3 years of relevant experience.\nDemonstrated professional software development experience is required. Candidates must be able to design, write, test, debug, and maintain software using at least one language such as Python, Go, Java, C#, or similar. Experience building automation tools, APIs, or applications is central to this role.\nStrong expertise in cloud environments, including deployment, optimization, and troubleshooting.\nProven track record in building and operating Cloud Native Applications using tools like Kubernetes and Docker.\nIn-depth experience with IaC tools such as Terraform, Ansible, or equivalent.\nSolid experience in creating and managing CI/CD build pipelines using GitLab or similar tools (e.g., Jenkins, Azure DevOps).\nStrong software automation skills using Python, Bash, or equivalent languages; Python or comparable application development experience is required.\nExcellent problem-solving skills with attention to detail and the ability to thrive in a fast-paced environment.\nExperience applying security best practices in DevSecOps pipelines (e.g., Trivy, Grype, GitLab SAST, or SonarQube).\nFamiliarity with monitoring tools like Prometheus, Grafana, or ELK Stack.\nStrong knowledge of networking and load balancing technologies.\nExperience with source control tools such as Git, including collaborative development workflows.\nExperience with automated deployment technologies such as Cloud Formation, Ansible, Puppet or Chef.\nExperience deploying and maintaining open-source and custom applications.\nWorking knowledge of Linux and Windows operating systems, web services, and SQL databases.\nExperience working in an Agile environment.\n\nWhat Would be Nice to Have\n\nSecurity+ or comparable certification for privileged user access.\nExperience with distributed processing methods and tools, such as REST APIs, microservices, IaaS/PaaS services.\nExperience developing and deploying web services.\nExperience in implementing Docker STIGs\nExperience with CONMON cybersecurity remediation.\nRHCSA/LPIC 1/2, CKA, or Docker Certified Associate certification.\n\nPay Range:At GRVTY, we understand that compensation is influenced by many factors—such as geographic location, federal contract labor categories, wage rates, prior experience, skillsets, education, and certifications.We’re proud to offer a work environment that empowers our team to achieve a strong work-life balance. GRVTY provides competitive pay, comprehensive benefits, and meaningful opportunities for professional growth.Our benefits package is designed to support the well-being of our employees and their families, and includes coverage in areas such as healthcare, financial wellness, retirement planning, family assistance, continued education, and paid time off.\n#J-18808-Ljbffr","company":"Grvty","rawCompany":"grvty","city":"Herndon","state":"VA","isRemote":false,"isActive":true,"createdAt":"2026-10-03T04:16:52.927Z","occupations":[{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Mid-Level DevSecOps Engineer","description":"GRVTY is seeking a Mid-level DevSecOps Engineer with a TS/SCI to join one of our top projects in Herndon, VA, to support the development, integration, and cybersecurity compliance of intelligence capabilities in Development and Production environments. This is a software engineering-focused DevSecOps role. The primary focus is designing, coding, testing, and maintaining software and automation tools that streamline Cyber Security workflows and improve the reliability of our platforms. We are looking for a candidate with a software development background who can build scalable, reliable systems and developer tools, and contribute to DevSecOps pipelines that integrate and deploy components across multiple networks into private cloud infrastructures hosted for our government customer.\nAs a GRVTY team member, you will closely support our mission partners, and your work will have direct mission impact. You will work with DevSecOps engineers, software developers, infrastructure technicians, and cybersecurity professionals to use open-source technology to create and maintain the full stack of a High-Performance Computing (HPC) system that hosts applications for thousands of users.\nWhat You'll be Owning\n\nDeploy and manage highly available applications to ensure system reliability and scalability.\nImplement and maintain HashiCorp Nomad and Kubernetes clusters for workload orchestration.\nExecute DNS configuration, management, and performance tuning for enterprise-grade systems.\nDevelop and implement Infrastructure-as-Code (IaC) solutions using tools like Terraform, Ansible, or similar.\nBuild and manage multiple CI/CD pipelines with GitLab or equivalent tools to automate deployments and streamline development workflows for rapid development and integration\nPerform system monitoring, logging, and troubleshooting to proactively identify and resolve issues.\nAutomate security testing and monitoring within the DevOps workflows using ACAS and Trivy.\nAnalyze cybersecurity scan findings and work with the cybersecurity team to identify false positives.\nAssist the cybersecurity team in assembling the required Body of Evidence for False Positive exceptions.\nAssist the cybersecurity team in assembling the required Body of Evidence to submit containerized and non-containerized software packages for enterprise software approval.\nIntegrate static code analysis tools such as GitLab SAST, Fortify, or SonarQube and other security mechanisms into CI/CD pipelines.\nBuild and maintain software tools that automate cybersecurity analysis and correlation workflows as compliance requirements evolve.\nPerform cybersecurity remediation on DevSecOps-managed virtual machines, including OS patching, OS STIG implementation, and software package updates.\nBuild, maintain, and monitor configuration management of release products.\nTroubleshoot and resolve issues in networks, automation pipelines, and infrastructure.\n\nWhat You Must Have\n\nActive TS/SCI and be willing and able to pass a CI polygraph\nMust be able and willing to work 40 hours per week in a SCIF in Herndon, Virginia.\nAt least 3 years of industry experience in software development or software engineering.\nAt least 5 years of industry experience in DevSecOps, with a bachelor’s degree in Computer Science, Information Systems, or a related field; or a master’s degree and at least 3 years of relevant experience.\nDemonstrated professional software development experience is required. Candidates must be able to design, write, test, debug, and maintain software using at least one language such as Python, Go, Java, C#, or similar. Experience building automation tools, APIs, or applications is central to this role.\nStrong expertise in cloud environments, including deployment, optimization, and troubleshooting.\nProven track record in building and operating Cloud Native Applications using tools like Kubernetes and Docker.\nIn-depth experience with IaC tools such as Terraform, Ansible, or equivalent.\nSolid experience in creating and managing CI/CD build pipelines using GitLab or similar tools (e.g., Jenkins, Azure DevOps).\nStrong software automation skills using Python, Bash, or equivalent languages; Python or comparable application development experience is required.\nExcellent problem-solving skills with attention to detail and the ability to thrive in a fast-paced environment.\nExperience applying security best practices in DevSecOps pipelines (e.g., Trivy, Grype, GitLab SAST, or SonarQube).\nFamiliarity with monitoring tools like Prometheus, Grafana, or ELK Stack.\nStrong knowledge of networking and load balancing technologies.\nExperience with source control tools such as Git, including collaborative development workflows.\nExperience with automated deployment technologies such as Cloud Formation, Ansible, Puppet or Chef.\nExperience deploying and maintaining open-source and custom applications.\nWorking knowledge of Linux and Windows operating systems, web services, and SQL databases.\nExperience working in an Agile environment.\n\nWhat Would be Nice to Have\n\nSecurity+ or comparable certification for privileged user access.\nExperience with distributed processing methods and tools, such as REST APIs, microservices, IaaS/PaaS services.\nExperience developing and deploying web services.\nExperience in implementing Docker STIGs\nExperience with CONMON cybersecurity remediation.\nRHCSA/LPIC 1/2, CKA, or Docker Certified Associate certification.\n\nPay Range:At GRVTY, we understand that compensation is influenced by many factors—such as geographic location, federal contract labor categories, wage rates, prior experience, skillsets, education, and certifications.We’re proud to offer a work environment that empowers our team to achieve a strong work-life balance. GRVTY provides competitive pay, comprehensive benefits, and meaningful opportunities for professional growth.Our benefits package is designed to support the well-being of our employees and their families, and includes coverage in areas such as healthcare, financial wellness, retirement planning, family assistance, continued education, and paid time off.\n#J-18808-Ljbffr","datePosted":"2026-10-03T04:16:52.927Z","dateModified":"2026-10-03T04:16:52.927Z","hiringOrganization":{"@type":"Organization","name":"Grvty","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Herndon","addressRegion":"VA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"646b7e6444bfbe995ae1dbbf"},"url":"https://jobsearcher.com/jobs/646b7e6444bfbe995ae1dbbf"}}