{"schemaVersion":"jobsearcher.job.v1","id":"a4cb6ed39d26a5b7f0b46fad","url":"https://jobsearcher.com/jobs/a4cb6ed39d26a5b7f0b46fad","canonicalUrl":"https://jobsearcher.com/jobs/a4cb6ed39d26a5b7f0b46fad","title":"Senior DevSecOps Engineer","description":"Company Overview\n\nPantheon Data (a Kenific Holding company) is a private, small business based in the Washington, DC, area. Pantheon Data was founded in 2011, initially providing acquisition and supply chain management services to the US Coast Guard. Our service offerings have grown in the past ten years, including infrastructure resiliency, contact center operations, information technology, software engineering, program management, strategic communications, engineering, and cybersecurity. We have also grown our customer base to include commercial clients. The company has used this experience to expand our service offerings to other agencies within the Department of Homeland Security (DHS), the Department of Defense (DoD), and other Federal Civilian Agencies.\n\nPosition Overview\n\nPantheon Data is seeking a SeniorDevSecOpsEngineer to design, build, andoperatesecure, cloud-native platforms in AWS GovCloud supporting ML-enabled workloads and applications that process CUI, PII, and PHI. GitLab Ultimate is ourDevSecOpsplatform: youwill own our GitLab CI/CD architecture end to end - pipelines, runners, security scanning, policy enforcement, and compliance evidence - and lead the migration of existing repositories and pipelines onto it.\n\nThe role combines secure pipeline engineering with platform operations: hardened infrastructure as code, production Amazon EKS administered throughGitOps, and gated security controls that satisfy NIST 800-53, FedRAMP, and DoD SRG requirements while keeping delivery fast. Successful candidates can walk through pipelines and platforms they have personally built - stage design, security gates, runner architecture, failure modes, and the compliance evidence they produced.\n\nResponsibilities\n\nGitLab CI/CD Engineering:Design, implement, andoperateenterprise-grade GitLab CI/CD pipelines, including multi-project/parent-child pipeline orchestration, environment promotion gates, protected branches and environments, and reusable pipeline templates and CI components.\nGitLab Ultimate Security Suite:Deploy, configure, and tune the full GitLab Ultimate security suite as required pipeline gates: Advanced SAST, DAST, secret detection (including push protection), dependency scanning, container scanning,IaCscanning, license compliance, and API security - with findings triaged through the vulnerability management dashboard and merge request security widgets.\nPolicy-as-CodeCompliance Automation:Enforce security centrally using scan execution policies, merge request approval policies, compliance frameworks, and compliance pipelines so scanning is mandatory across all projects; maintain audit events and evidence packages that support ATO, POA&M, and continuous-monitoring activities.\nSoftware Supply Chain Security:Generate and manage SBOMs (CycloneDX), enforce dependency and license policies, sign and verify build artifacts and container images, andmaintaina secure, traceable path from commit to production.\nRunnersCloud Auth:Architect and operate GitLab Runner fleets in GovCloud (autoscaling, isolation, hardened images) and implement keyless OIDC authentication from GitLab to AWS IAM roles - no long-lived cloud credentials in CI.\nSecure Infrastructure:Design andmaintainhardened AWS GovCloud environments with Terraform (modular design, remote state, multi-repo dependency ordering), aligned to NIST 800-53 and FedRAMP High baselines and DISA STIG/CIS benchmarks.\nKubernetes &GitOps:Manage lifecycle, networking, and security for production Amazon EKS clusters; orchestrate deployments with Helm andGitOpstooling (Argo CD or Flux) for declarative state management; harden clusters, registries, and OCI image workflows.\nML Workload Support:Deploy and scale containerized ML models and data pipelines; build observability (metrics, logging, alerting, tracing) for regulated, restricted-egress environments.\nPlatform Migration:Lead the migration of repositories, pipelines, and integrations from GitHub/GitHub Actions to GitLab, including translation of workflows, secrets strategy, branch protection parity, and developer enablement.\nTeam Enablement:Mentor engineers on secure delivery practices, author runbooks and pipeline documentation, and partner with security and compliance teams on control implementation and assessment support.\n\nRequired Skills and Experience\n\nBachelor's degree in Computer Science, Information Technology, Information Systems, Engineering, or a related technical field,froman ABETaccredited university.\n5+ years inDevSecOps/DevOps engineering with responsibility forproductionAWS environments.Plusanadditional5 years of experience in arelatedtechnical field.\nDeep, hands-on GitLabexpertise: GitLab CI/CD pipeline design at scale, GitLab Ultimatesecurityand compliance features (SAST/DAST/secret detection/dependency/container/IaCscanning, scan execution and approval policies, security dashboards), and GitLab Runner administration.\nExperience implementing gatedDevSecOpscontrols in CI/CD - pipelines thatblock onsecurity findings, enforce approvals, and produce auditable evidence.\nDeep hands-onexpertisewith Amazon EKS: cluster hardening, OCI-compliant image management, Helm, andGitOpsdeployment patterns (Argo CD or Flux).\nProficiencyin Terraform for complex networking and security stacks: modular design, state management, and multi-environment promotion.\nPractical understanding of NIST SP 800-53, FedRAMP, and DoD RMF/SRG, and their application to technical configurations in AWS GovCloud (STIGs, CIS benchmarks, boundary controls, audit logging).\nScriptingproficiencyin Python or Bash for operational automation and security tooling.\nCurrent AWS Certified DevOps Engineer – Professional or AWS Certified Security – Specialty.\nAbility to work effectively in remote, cross-functional teams; meet deadlines; and produce quality work with clear written communication.\nProficient in Microsoft Suite software including Outlook, Word, Excel, SharePoint, and PowerPoint.\n\nPreferred Skills and Experience\n\nExperience administering self-managed GitLab (or GitLab Dedicated for Government) in GovCloud or another isolated/restricted-egress environment, including upgrades, backups, and instance hardening.\nExperience migrating organizations from GitHub/GitHub Actions (including GitHub Advanced Security) to GitLab Ultimate.\nExperience supporting FedRAMP High or DoD IL4/IL5 ATO efforts: control implementation statements, POA&M management, continuous monitoring, and assessor engagement.\nSupply-chain security depth: SLSA,Sigstore/cosign artifact signing, SBOM management, and dependency provenance.\nExperience supporting ML/AI platforms (model serving, GPU workloads, Amazon Bedrock integrations, or data pipelines) in regulated environments.\nSecrets management with AWS KMS, Secrets Manager, orHashiCorpVault; policy-as-code tools such as OPA/Kyverno; and admission control for Kubernetes.\nAdditional AWS certifications such as Solutions Architect orSysOpsAdministrator; Kubernetes certifications (CKA/CKS).\n\nClearance Requirements\n\nApplicants selected will be subject to a security investigation and may need to meet eligibility requirements. Secret Clearance is required for continued employment.\n\nWork Location: Reston, VA - Hybrid\n\nOur company prioritizes the benefits of flexibility and collaboration, whether that happens in person or remotely.\nIf the position is remote or hybrid, you may periodically work from a Pantheon Data office location or client site.\nIf this position is assigned to a Pantheon Data office location or client site, you'll work with colleagues and clients in person, as needed for specific client requirements.\n\nInterview Requirement: Candidates who are local to the area should be prepared to participate in an in-person interview as part of the selection process. Candidates outside the local area may be considered for a virtual interview.\n\nCompensation\n\nThe salary range for this position is $140,000 - $200,000. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.\n\nBenefits Overview\n\nWe are always looking for good people! Pantheon Data is committed to providing its employees with competitive salaries and benefits in order to increase employee satisfaction and productivity.In addition to our benefits, we also offer SmartBenefits through the Washington Metro Area Transportation Authority, where you specify an amount of your pre-tax wages be paid directly to your SmarTrip account. In some cases, tuition assistance may be available for continuing education expenses and certifications related to their position. Additional details may be found at https://pantheon-data.com/careers/\n\nPantheon Data Important Information\n\nAll qualified applicants will be considered for employment without regard to disability, status as a protected veteran, or any other status protected by applicable federal, state, local, or international law.\n\nAs part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.\n\nIf you require reasonable accommodation in completing this application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please direct your inquiries to our Talent Team at Recruiting@pantheon-data.com or by phone (571) 363-4020.\n\nThis company uses E-Verify to confirm each employee's work authorization. For more information, click here E-Verify Participation Poster","company":"Pantheondata","rawCompany":"pantheondata","city":"Reston","state":"VA","isRemote":false,"isActive":false,"createdAt":"2026-08-29T11:18:22.341Z","occupations":[{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Senior DevSecOps Engineer","description":"Company Overview\n\nPantheon Data (a Kenific Holding company) is a private, small business based in the Washington, DC, area. Pantheon Data was founded in 2011, initially providing acquisition and supply chain management services to the US Coast Guard. Our service offerings have grown in the past ten years, including infrastructure resiliency, contact center operations, information technology, software engineering, program management, strategic communications, engineering, and cybersecurity. We have also grown our customer base to include commercial clients. The company has used this experience to expand our service offerings to other agencies within the Department of Homeland Security (DHS), the Department of Defense (DoD), and other Federal Civilian Agencies.\n\nPosition Overview\n\nPantheon Data is seeking a SeniorDevSecOpsEngineer to design, build, andoperatesecure, cloud-native platforms in AWS GovCloud supporting ML-enabled workloads and applications that process CUI, PII, and PHI. GitLab Ultimate is ourDevSecOpsplatform: youwill own our GitLab CI/CD architecture end to end - pipelines, runners, security scanning, policy enforcement, and compliance evidence - and lead the migration of existing repositories and pipelines onto it.\n\nThe role combines secure pipeline engineering with platform operations: hardened infrastructure as code, production Amazon EKS administered throughGitOps, and gated security controls that satisfy NIST 800-53, FedRAMP, and DoD SRG requirements while keeping delivery fast. Successful candidates can walk through pipelines and platforms they have personally built - stage design, security gates, runner architecture, failure modes, and the compliance evidence they produced.\n\nResponsibilities\n\nGitLab CI/CD Engineering:Design, implement, andoperateenterprise-grade GitLab CI/CD pipelines, including multi-project/parent-child pipeline orchestration, environment promotion gates, protected branches and environments, and reusable pipeline templates and CI components.\nGitLab Ultimate Security Suite:Deploy, configure, and tune the full GitLab Ultimate security suite as required pipeline gates: Advanced SAST, DAST, secret detection (including push protection), dependency scanning, container scanning,IaCscanning, license compliance, and API security - with findings triaged through the vulnerability management dashboard and merge request security widgets.\nPolicy-as-CodeCompliance Automation:Enforce security centrally using scan execution policies, merge request approval policies, compliance frameworks, and compliance pipelines so scanning is mandatory across all projects; maintain audit events and evidence packages that support ATO, POA&M, and continuous-monitoring activities.\nSoftware Supply Chain Security:Generate and manage SBOMs (CycloneDX), enforce dependency and license policies, sign and verify build artifacts and container images, andmaintaina secure, traceable path from commit to production.\nRunnersCloud Auth:Architect and operate GitLab Runner fleets in GovCloud (autoscaling, isolation, hardened images) and implement keyless OIDC authentication from GitLab to AWS IAM roles - no long-lived cloud credentials in CI.\nSecure Infrastructure:Design andmaintainhardened AWS GovCloud environments with Terraform (modular design, remote state, multi-repo dependency ordering), aligned to NIST 800-53 and FedRAMP High baselines and DISA STIG/CIS benchmarks.\nKubernetes &GitOps:Manage lifecycle, networking, and security for production Amazon EKS clusters; orchestrate deployments with Helm andGitOpstooling (Argo CD or Flux) for declarative state management; harden clusters, registries, and OCI image workflows.\nML Workload Support:Deploy and scale containerized ML models and data pipelines; build observability (metrics, logging, alerting, tracing) for regulated, restricted-egress environments.\nPlatform Migration:Lead the migration of repositories, pipelines, and integrations from GitHub/GitHub Actions to GitLab, including translation of workflows, secrets strategy, branch protection parity, and developer enablement.\nTeam Enablement:Mentor engineers on secure delivery practices, author runbooks and pipeline documentation, and partner with security and compliance teams on control implementation and assessment support.\n\nRequired Skills and Experience\n\nBachelor's degree in Computer Science, Information Technology, Information Systems, Engineering, or a related technical field,froman ABETaccredited university.\n5+ years inDevSecOps/DevOps engineering with responsibility forproductionAWS environments.Plusanadditional5 years of experience in arelatedtechnical field.\nDeep, hands-on GitLabexpertise: GitLab CI/CD pipeline design at scale, GitLab Ultimatesecurityand compliance features (SAST/DAST/secret detection/dependency/container/IaCscanning, scan execution and approval policies, security dashboards), and GitLab Runner administration.\nExperience implementing gatedDevSecOpscontrols in CI/CD - pipelines thatblock onsecurity findings, enforce approvals, and produce auditable evidence.\nDeep hands-onexpertisewith Amazon EKS: cluster hardening, OCI-compliant image management, Helm, andGitOpsdeployment patterns (Argo CD or Flux).\nProficiencyin Terraform for complex networking and security stacks: modular design, state management, and multi-environment promotion.\nPractical understanding of NIST SP 800-53, FedRAMP, and DoD RMF/SRG, and their application to technical configurations in AWS GovCloud (STIGs, CIS benchmarks, boundary controls, audit logging).\nScriptingproficiencyin Python or Bash for operational automation and security tooling.\nCurrent AWS Certified DevOps Engineer – Professional or AWS Certified Security – Specialty.\nAbility to work effectively in remote, cross-functional teams; meet deadlines; and produce quality work with clear written communication.\nProficient in Microsoft Suite software including Outlook, Word, Excel, SharePoint, and PowerPoint.\n\nPreferred Skills and Experience\n\nExperience administering self-managed GitLab (or GitLab Dedicated for Government) in GovCloud or another isolated/restricted-egress environment, including upgrades, backups, and instance hardening.\nExperience migrating organizations from GitHub/GitHub Actions (including GitHub Advanced Security) to GitLab Ultimate.\nExperience supporting FedRAMP High or DoD IL4/IL5 ATO efforts: control implementation statements, POA&M management, continuous monitoring, and assessor engagement.\nSupply-chain security depth: SLSA,Sigstore/cosign artifact signing, SBOM management, and dependency provenance.\nExperience supporting ML/AI platforms (model serving, GPU workloads, Amazon Bedrock integrations, or data pipelines) in regulated environments.\nSecrets management with AWS KMS, Secrets Manager, orHashiCorpVault; policy-as-code tools such as OPA/Kyverno; and admission control for Kubernetes.\nAdditional AWS certifications such as Solutions Architect orSysOpsAdministrator; Kubernetes certifications (CKA/CKS).\n\nClearance Requirements\n\nApplicants selected will be subject to a security investigation and may need to meet eligibility requirements. Secret Clearance is required for continued employment.\n\nWork Location: Reston, VA - Hybrid\n\nOur company prioritizes the benefits of flexibility and collaboration, whether that happens in person or remotely.\nIf the position is remote or hybrid, you may periodically work from a Pantheon Data office location or client site.\nIf this position is assigned to a Pantheon Data office location or client site, you'll work with colleagues and clients in person, as needed for specific client requirements.\n\nInterview Requirement: Candidates who are local to the area should be prepared to participate in an in-person interview as part of the selection process. Candidates outside the local area may be considered for a virtual interview.\n\nCompensation\n\nThe salary range for this position is $140,000 - $200,000. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.\n\nBenefits Overview\n\nWe are always looking for good people! Pantheon Data is committed to providing its employees with competitive salaries and benefits in order to increase employee satisfaction and productivity.In addition to our benefits, we also offer SmartBenefits through the Washington Metro Area Transportation Authority, where you specify an amount of your pre-tax wages be paid directly to your SmarTrip account. In some cases, tuition assistance may be available for continuing education expenses and certifications related to their position. Additional details may be found at https://pantheon-data.com/careers/\n\nPantheon Data Important Information\n\nAll qualified applicants will be considered for employment without regard to disability, status as a protected veteran, or any other status protected by applicable federal, state, local, or international law.\n\nAs part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.\n\nIf you require reasonable accommodation in completing this application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please direct your inquiries to our Talent Team at Recruiting@pantheon-data.com or by phone (571) 363-4020.\n\nThis company uses E-Verify to confirm each employee's work authorization. For more information, click here E-Verify Participation Poster","datePosted":"2026-08-29T11:18:22.341Z","dateModified":"2026-08-29T11:18:22.341Z","hiringOrganization":{"@type":"Organization","name":"Pantheondata","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Reston","addressRegion":"VA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"a4cb6ed39d26a5b7f0b46fad"},"url":"https://jobsearcher.com/jobs/a4cb6ed39d26a5b7f0b46fad"}}