JOBSEARCHER

DevSecOps Engineer

*About Optisources* Optisources, Inc. is a small business technology consulting firm headquartered in McLean, Virginia. We deliver secure data engineering, cloud and DevSecOps engineering, AI/ML platforms, and analytics for federal and state government customers. We are Virginia SWaM certified. *Position Summary* We are seeking a DevSecOps Engineer to work on site with our client in Maryland, building and maintaining secure automated delivery pipelines for enterprise applications. You will embed security controls directly into CI/CD workflows, automate infrastructure provisioning, and automate the evidence collection that keeps systems compliant with agency security policy. *Responsibilities* * Design, build, and maintain CI/CD pipelines in GitLab CI, Jenkins, Azure DevOps, or GitHub Actions with integrated SAST, DAST, SCA, and container image scanning. * Automate infrastructure provisioning using Terraform, Ansible, and Helm across development, test, and production environments. * Build and harden container images against CIS Benchmarks and DISA STIGs, then deploy and operate workloads on Kubernetes using EKS, AKS, or OpenShift. * Implement secrets management, least privilege access, and software supply chain controls including SBOM generation and artifact signing. * Develop automation and orchestration scripting to replace manual security and release tasks. * Automate security control validation and continuous compliance evidence collection against NIST SP 800-53 and agency security policy. * Instrument platforms for observability across logging, metrics, tracing, and alerting, and support incident response. * Perform secure code review and work with development teams to remediate findings. * Produce pipeline design documentation, security configuration baselines, runbooks, and as-built documentation. *Required Qualifications* * U.S. citizenship. * Bachelor degree in Computer Science, Engineering, or a related field, or equivalent practical experience. * [5] or more years of DevOps or DevSecOps engineering experience. * Hands-on expertise with Kubernetes, Docker or Podman, and infrastructure as code, with Terraform preferred. * Strong scripting and automation skills in Python, Bash, or PowerShell. * Experience integrating security tooling into pipelines, such as SonarQube, Fortify, Trivy, Anchore, Prisma Cloud, or Nessus. * Working knowledge of NIST SP 800-53, CIS Benchmarks, and secure configuration hardening. * Ability to pass a background investigation and any customer screening required for site access. *Preferred Qualifications* * Experience supporting state government or federal agency customers. * AWS, Azure, or Google Cloud platform experience. * CKA, CKS, AWS Certified DevOps Engineer Professional, or Security+ CE. * Experience in environments governed by CJIS, HIPAA, or IRS Publication 1075. Pay: $80,000.00 - $120,000.00 per year Benefits: * 401(k) * 401(k) matching * Health insurance * Paid time off * Retirement plan Work Location: In person