Senior DevSecOps Engineer
Overview
As a DevSecOps Engineer at Noblis, you embed security into the DevOps lifecycle to support critical national security missions. You will work across development, operations, and security teams to close gaps and promote shared accountability for secure software delivery. You will design secure CI/CD pipelines, automate security controls, and guide junior engineers while ensuring compliance with policies and standards. This role offers the chance to shape secure cloud and container practices at scale and contribute to mission-driven projects.
Compensation / Benefitshealthlifedisabilityfinancial benefitsretirement benefitspaid leave
ResponsibilitiesDesign, build, and maintain CI/CD pipelines with automated build, test, security scan, and deployment stepsIntegrate automated testing, security scanning, and compliance validation into pipelinesDevelop and manage Infrastructure as Code using Terraform or CloudFormation with guardrails and scanningImplement security practices for Docker, Kubernetes, and EKS, including image hardening and policy-as-codeCollaborate with teams to design and enforce AWS/Azure security guardrails (IAM least-privilege, network controls, encryption)Operationalize vulnerability management to identify, prioritize, and remediate threatsTranslate security compliance requirements into automated controls and audit-ready evidenceEnsure development and deployment processes comply with security policies and standardsAct as a security champion, mentoring others on secure coding and DevSecOps principles
Key requirementsUS Citizenship is requiredActive TS/SCI with PolygraphBachelor’s or Master’s with 7+ years of related experience; or Associate’s with 11+ years; or High School/GED with 14+ yearsProficiency in Python and automation scripting (e.g., Bash)Familiarity with CI/CD tools (GitLab CI, GitHub Actions)Experience with container orchestration (Kubernetes, EKS) and IaC (Terraform, Ansible)Experience with cloud environments (AWS, Azure, GCP) and cloud-native security practicesAbility to identify security issues and distill guidance for development teamsstrong communicationmentoringproblem-solvingCI/CD design and automationSecurity scanning and compliance toolingTerraform / CloudFormation