What You'll Do
Design and maintain secure, automated CI/CD pipelines that align with the DoD Enterprise DevSecOps Reference Design. You'll integrate security testing tools directly into development workflows to ensure continuous compliance across all stages.
Automate infrastructure provisioning using Terraform, Ansible, or CloudFormation to deploy secure, compliant environments in cloud platforms such as AWS GovCloud or Azure Government. These environments will adhere to strict federal standards including FedRAMP and RMF.
Enforce security baselines by implementing DISA STIGs, NIST SP 800-53 controls, and Zero Trust principles within Infrastructure as Code. You'll translate regulatory requirements into automated checks and validation scripts using tools like OpenSCAP, Chef InSpec, or PowerSTIG.
Secure containerized workloads by integrating image scanning, managing hardened registries, and orchestrating deployments on Kubernetes—leveraging platforms such as Big Bang or Iron Bank. You'll also manage secrets using Vault or AWS Secrets Manager with strict rotation policies.
Collaborate with security and development teams to support ATO documentation, continuous monitoring, and control assessments. You'll serve as a technical authority on federal compliance, working closely with ISSOs, ISSMs, and assessors to streamline authorization efforts.
Requirements
- Bachelor’s degree in Computer Science or equivalent experience
- Minimum of 7 years in DevSecOps, particularly within AI/ML or data-heavy systems
- Proven track record supporting DoD ATO or FedRAMP authorization processes
- Deep familiarity with NIST 800-53, RMF, and federal cloud security frameworks
- Hands-on experience with Kubernetes, OpenShift, Docker, and container security hardening
- Proficiency in scripting languages such as Python or Bash for automation and compliance validation
- Experience with DevSecOps tooling including GitLab, Jenkins, ArgoCD, Nexus, SonarQube, and Anchore
- Working knowledge of cloud platforms (AWS, Azure, GCP), especially in isolated or air-gapped environments
- Active security clearance or ability to obtain one
Preferred Qualifications
- Current US Government Secret clearance or higher
Benefits
- 100% remote work with minimal travel (under 10%)
- Employment as a W-2 worker with full benefits through the hiring company