DevSecOps Engineer
DevSecOps Engineer
* Must be eligible for a federal security clearance (US Citizen)
Job Responsibilities:
• Translate complex technical concepts to better communicate with scientific, admin, and management staff.
• Help shape the security architectural vision.
• Lead teams to evaluate novel scientific and AI capabilities against our core security values.
• Develop and maintain security applications deployed with container orchestration tools.
• Automate policy assessments to verify cybersecurity and operational policy.
• Define and implement best practices and standards within the organization.
• Analyze, triage, and respond to application, system, and network events.
• Install, maintain, and monitor common security systems such as (N/H)IDS and SIEM.
• Interpret cybersecurity policy, recommend enhancements to current policies, and lead subsequent implementation efforts.
• Respond to system vulnerabilities and coordinate system patches and updates. Perform approved penetration testing and verification.
• Document cybersecurity procedures.
• Work with and Secure cloud infrastructure and container native applications.
• Follow, contribute to, and implement evolving AI safety and security standards.
• Collaborate with partners to understand and synthesize diverse security, operations, governance, and technical requirements.
• Participate in a 24-hour, 7-day on-call incident response rotation. (once every 8 weeks)
Basic Qualifications:
• Bachelor's Degree in Computer Science or related field.
• Equivalent combination of education and experience will be considered.
• Experience securing cloud infrastructure in one or more clouds (e.g., AWS)
• Experience with security tools as part of CI/CD pipelines (e.g., Trivy, SonarQube)
• Experience with container security tools (e.g. container capabilities, Gatekeeper, Neuvector)
• The ability to obtain and maintain a Department of Energy "Q" clearance is required. This requires US Citizenship.
• Must have Kubernetes security experience.
Preferred Qualifications:
• Master's Degree in Computer Science or related field and 1-2 years of relevant experience.
• Strong understanding of cybersecurity concepts, best practices, and tools.
• Experience deploying and maintaining systems in UNIX/Linux environments.
• Solid understanding of networked computing environment concepts.
• A DevSecOps mindset, including version control and scripting/programming experience.
• Ability to communicate effectively and work well in a team environment.
• Natural ability to understand and use new and emerging technologies.
• Experience with security tools such as NIDS/HIDS, Vulnerability Scanning, and SIEM.
• Experience in a high-performance computing environment.
• Experience with incident response and engaging in forensics.
• Experience with automated configuration management tools such as Puppet, Ansible, Terraform, etc.
• Experience in network, application, and/or security architecture and design.
• Familiarity with common protocols such as DNS, DHCP, LDAP, SNMP, SMTP, HTTP, SSL, etc, and features of cloud networking (e.g., VPCs)
• Experience in cloud infrastructure and cloud security.
• Familiarity with major cloud providers, including platform native technologies.
• Familiarity with container workflows, development practices, and secure operations.
• Familiarity with AI development, including evolving AI safety and security standards.
• Familiarity with software supply chain requirements, including provenance & attestations, and SBOMs.