1

Director Devsecops Jobs in Hanover, MD (NOW HIRING)

Jr DevSecOps Engineer

Washington, DC ยท On-site

$75K - $105K/yr

... directed. * Contribute to the development and documentation of DevSecOps methods of procedures (MOPs), governance structures, standard operating procedures, and operational runbooks under senior ...

... directed. * Contribute to the development and documentation of DevSecOps methods of procedures (MOPs), governance structures, standard operating procedures, and operational runbooks under senior ...

... directed. * Contribute to the development and documentation of DevSecOps methods of procedures (MOPs), governance structures, standard operating procedures, and operational runbooks under senior ...

Direct hire full-time position * Competitive base salary and comprehensive benefits * Mid-size company with room for growth Position Title : DevSecOps Engineer Position Location : On-site ...

DevSecOps Engineer

Washington, DC

$59.75 - $81.75/hr

... self-directed individual to fill the role of a DevSecOps Engineer, who will maintain multiple ... client-managed cloud application stacks (Tomcat, Drupal, React, Node.js, Nginx, etc.) running as ...

New

... self-directed individual to fill the role of a DevSecOps Engineer, who will maintain multiple ... client-managed cloud application stacks (Tomcat, Drupal, React, Node.js, Nginx, etc.) running as ...

Program Director

Washington, DC ยท On-site

$180K - $230K/yr

The Program Director will serve as a primary interface with the Government and provide overall ... DevSecOps pipelines, data services, identity/access management, observability, resiliency, and ...

next page

Showing results 1-20

Director Devsecops information

What does a director of DevSecOps do?

A Director of DevSecOps leads and oversees the integration of security practices into the DevOps process within an organization. They are responsible for developing strategies, managing teams, and implementing tools to ensure applications and infrastructure are secure throughout the software development lifecycle. This role collaborates with development, operations, and security teams to automate security controls, monitor threats, and ensure compliance with industry standards. Ultimately, the Director of DevSecOps works to minimize risks while enabling efficient and secure software delivery.

What are the key skills and qualifications needed to thrive as a director of DevSecOps?

To thrive as a Director of DevSecOps, you need deep expertise in cybersecurity, software development, and IT infrastructure, often supported by a degree in computer science or related field and significant leadership experience. Familiarity with CI/CD pipelines, cloud platforms (e.g., AWS, Azure), containerization tools (e.g., Docker, Kubernetes), and certifications like CISSP or CISM are typically required. Strong leadership, strategic thinking, and excellent communication skills help drive cross-functional collaboration and promote a security-first mindset. These skills and qualities are crucial for effectively integrating security into development processes, managing risk, and ensuring organizational resilience.

How does a director of DevSecOps typically collaborate with development and security teams to foster a culture of shared responsibility?

A Director of DevSecOps works closely with both development and security teams to integrate security practices seamlessly into the software development lifecycle. They facilitate regular cross-team meetings, establish clear communication channels, and advocate for security as a shared responsibility rather than a separate function. By implementing automated security tools and continuous feedback loops, they help teams proactively identify and address vulnerabilities, ensuring that security is considered at every stage of development. This collaborative approach not only enhances product security but also fosters a culture of trust and accountability across the organization.

What is the difference between Director Devsecops vs Security Manager?

AspectDirector DevsecopsSecurity Manager
Primary FocusIntegrating security into development and operations processesManaging overall security policies and team oversight
ResponsibilitiesAutomating security, CI/CD pipelines, DevSecOps practicesSecurity policy enforcement, incident response, risk management
Required SkillsDevOps, security tools, scripting, cloud platformsSecurity frameworks, leadership, compliance, risk assessment
Work EnvironmentCollaborative with development and operations teamsSecurity teams, executive management, compliance departments

The main difference is that the Director Devsecops focuses on embedding security into development and operational workflows, while the Security Manager oversees overall security policies and team management. Both roles require security expertise, but the Director Devsecops emphasizes automation and integration within tech processes, whereas the Security Manager concentrates on policy, compliance, and strategic security planning.

What are the most commonly searched types of Devsecops jobs in Hanover, MD?

The most popular types of Devsecops jobs in Hanover, MD are:

What are popular job titles related to Director Devsecops jobs in Hanover, MD?

For Director Devsecops jobs in Hanover, MD, the most frequently searched job titles are:

What job categories do people searching Director Devsecops jobs in Hanover, MD look for?

The top searched job categories for Director Devsecops jobs in Hanover, MD are:

What cities near Hanover, MD are hiring for Director Devsecops jobs?

Cities near Hanover, MD with the most Director Devsecops job openings:

Infographic showing various Director Devsecops job openings in Hanover, MD as of August 2026, with employment types broken down into 1% As Needed, 83% Full Time, 12% Part Time, 1% Temporary, and 3% Contract. Highlights an 89% Physical, 2% Hybrid, and 9% Remote job distribution.

Jr DevSecOps Engineer

Koniag, Inc.

Washington, DC โ€ข On-site

$75K - $105K/yr

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 4 days ago


Job description

Koniag Data Solutions, a Koniag Government Services company, is seeking a motivated and technically driven DevSecOps Engineer (Jr) to support a comprehensive enterprise cybersecurity services engagement for a federal civilian agency. This position requires the ability to obtain and maintain a government background investigation commensurate with a Moderate Risk designation (Minimum Background Investigation or higher) and applicable system access authorizations prior to performing work. Work will be performed primarily at the client's facility located in Washington, DC, with potential for hybrid/remote arrangements as approved.
We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.
The ideal candidate is an early-career software or cybersecurity professional with foundational knowledge of secure software development principles, DevSecOps practices, and application security concepts who is eager to build deep technical expertise in a complex, mission-driven federal IT environment. This individual must be a technically curious self-starter with strong analytical skills, a foundational understanding of software development and security integration practices, and the ability to contribute effectively to cross-functional engineering and security teams under the guidance of senior cybersecurity engineers and program leadership.
This role sits within the Information Security Division (ISD) and provides foundational DevSecOps engineering support, security integration assistance, and application security services in support of the agency's secure software development lifecycle (SDLC), continuous integration and continuous delivery (CI/CD) pipeline security, and enterprise cybersecurity architecture and engineering program.
Position Description:
The DevSecOps Engineer (Jr) provides foundational engineering support across a range of DevSecOps integration, application security testing, security tool management, and continuous monitoring activities under the direction of senior cybersecurity engineers, the cybersecurity architecture and engineering team, and program leadership. This individual assists in the integration of security requirements into the software development lifecycle, supports CI/CD pipeline security tooling, contributes to application security testing activities including static and dynamic code analysis and API security testing, and helps ensure that security is embedded throughout the development-to-delivery pipeline for agency IT systems and applications.
This role offers significant professional development opportunities for an early-career DevSecOps or cybersecurity professional seeking to build expertise in secure SDLC integration, application security testing, cloud security, Zero Trust Architecture implementation, and enterprise cybersecurity engineering within a dynamic and mission-critical federal environment.
Principal responsibilities will include but are not limited to:
DevSecOps Integration Support
  • Assist senior engineers with the assessment of current DevSecOps practices and the integration of security tooling and processes into the agency's development-to-delivery pipeline under established guidance and direction.
  • Support the implementation of security controls and automated security checks within CI/CD pipelines, including code scanning, dependency analysis, and vulnerability detection at the build and deployment stages.
  • Assist with the integration of enterprise and security tools and practices into the development pipeline, supporting DevSecOps integration activities across agency IT Services and Business Technology Solutions projects as directed.
  • Contribute to the development and documentation of DevSecOps methods of procedures (MOPs), governance structures, standard operating procedures, and operational runbooks under senior staff direction.
  • Support the configuration, maintenance, and troubleshooting of DevSecOps tooling integrated into the agency's Azure DevOps environment, including pipeline configurations, security scan integrations, and automated testing frameworks.
  • Assist with the development of recommendations for DevSecOps governance structures and workforce development plans, contributing research, analysis, and draft documentation under senior engineer direction.
  • Support the automation and orchestration of CI/CD pipelines with ongoing security enhancements, assisting senior engineers in identifying and implementing improvements to pipeline security posture.

Application Security Testing Support
  • Assist with the execution of static code analysis (SAST) activities, supporting the configuration of static analysis tools, interpretation of scan results, and preparation of findings reports under senior staff direction.
  • Support dynamic code analysis (DAST) activities, including test environment setup coordination, scan execution assistance, and results documentation for review by senior engineers.
  • Assist with API security testing activities, supporting the execution of API scans against the OWASP API Top Ten criteria, organizing test results, and preparing formatted findings reports for senior staff review and stakeholder out-briefs.
  • Contribute to sprint-based penetration and API testing activities, supporting test coordination, results documentation, and remediation tracking under senior engineer direction.
  • Assist with the validation of remediation activities for identified application security findings, supporting re-testing execution and documentation of remediation verification results.
  • Research and document common application security vulnerabilities, attack vectors, and remediation strategies to support the development of senior engineer recommendations and findings reports.

Vulnerability Management Support
  • Assist with the scheduling and execution of vulnerability scans across the enterprise IT environment using Tenable Security Center, supporting scan configuration, results export, and preliminary findings review under senior staff direction.
  • Support the preparation of weekly vulnerability debrief slides and reports, compiling scan data, formatting outputs, and organizing findings for senior staff review and stakeholder distribution.
  • Assist with the review of vulnerability reports from Microsoft Threat and Vulnerability Management (TVM) to support the confirmation of CVE impact and applicability to the enterprise environment.
  • Contribute to the tracking and reporting of zero-day vulnerabilities, assisting senior staff with status tracking, closure documentation, and ad hoc reporting activities.
  • Support the management of scanning infrastructure, assisting with monitoring scanner operational status, performing basic troubleshooting under senior guidance, and escalating issues requiring advanced resolution.
  • Assist with compliance scans of newly provisioned servers and newly created OS baseline images, supporting scan execution and results documentation in accordance with established procedures.

Security Tools Management Support
  • Assist senior engineers with the administration, configuration, and maintenance of enterprise cybersecurity tools across the agency's security tool stack, including endpoint protection, SIEM, vulnerability management, and application security platforms.
  • Support the development and maintenance of tools inventory documentation, standard operating procedures (SOPs), and tools procedures documentation, ensuring all materials are current, accurately formatted, and uploaded to the designated SharePoint repository.
  • Assist with the identification of misconfigurations in security tools and capabilities for agency-operated systems, documenting findings and supporting remediation coordination under senior staff direction.
  • Contribute to the design, development, integration, and testing of automated security testing tools and scripts in support of Assessment and Authorization (A&A) activities.
  • Support the development and maintenance of compliance content leveraging the agency's Continuous Diagnostics and Mitigation (CDM) toolset, assisting senior engineers with content configuration and alignment to approved Security Configuration Specifications.
  • Research and document emerging cybersecurity tools, technologies, and capabilities, supporting senior engineer assessments of potential additions or enhancements to the agency's security tool stack.

Cybersecurity Architecture & Engineering Support
  • Assist senior security architects and engineers with the development and maintenance of cybersecurity architecture documentation, including architecture diagrams, data flow diagrams, topology maps, and recommendation documents under senior staff direction.
  • Support the development of Security Configuration Baselines (SCBs), assisting with research, documentation, and alignment to DISA STIGs, CIS Benchmarks, and agency-approved hardening standards.
  • Contribute to security design reviews for new technologies and services by researching security considerations, documenting relevant standards and requirements, and preparing supporting materials for senior engineer review.
  • Assist with the development of Zero Trust Architecture (ZTA) documentation and implementation support materials, contributing research, diagram drafts, and supporting content under senior architect direction in alignment with NIST SP 800-207 and applicable federal ZTA guidance.
  • Support configuration management activities, assisting senior engineers with the maintenance of the Configuration Management Database (CMDB) and contributing to the development of configuration management process documentation.
  • Assist with tracking and documenting new, revised, or emerging applicable federal policies and regulations, supporting senior architects in assessing impacts to the agency's cybersecurity architecture and engineering posture.

Cloud Security Support
  • Assist senior engineers with security engineering activities for cloud-hosted systems and services across AWS and Microsoft Azure Government environments, supporting configuration review, security assessment, and documentation activities under established guidance.
  • Support the monitoring and review of cloud security posture management outputs from AWS Security Hub, Amazon GuardDuty, Microsoft Defender for Cloud, and related cloud security tools, assisting with findings documentation and escalation to senior engineers.
  • Contribute to the development and maintenance of cloud security architecture documentation, assisting senior engineers with diagram preparation, findings write-ups, and recommendation documentation.
  • Assist with ensuring that FedRAMP JAB Provisional ATO or Agency ATO requirements are considered in cloud solution implementations, supporting senior engineers with documentation and compliance verification activities.

Automation & Scripting Support
  • Assist senior engineers with the development, testing, and maintenance of automation scripts and tools supporting security operations, vulnerability management, compliance monitoring, and DevSecOps pipeline integration activities.
  • Support the development of PowerShell, Python, or equivalent scripts for automating routine security administration, compliance data collection, and reporting tasks under senior engineer direction.
  • Assist with the development and maintenance of Extract-Transform-Load (ETL) processes and data normalization routines supporting security dashboards and visualization outputs.
  • Contribute to the testing and validation of automation tools and scripts prior to production deployment, supporting quality assurance activities under senior engineer guidance.

Documentation & Reporting
  • Assist with the preparation and maintenance of technical documentation, project plans, recommendation documents, hardware/software review reports, procedure documents, and system diagrams in support of cybersecurity engineering activities.
  • Prepare and maintain weekly and monthly status reports, enterprise ticketing system reports, and other recurring reporting deliverables in accordance with established formats and submission schedules.
  • Ensure all documentation is peer-reviewed for accuracy, grammar, and formatting consistency prior to submission, and that all deliverables are uploaded to the designated SharePoint or GRC repository.
  • Respond to documentation requests and ad hoc reporting requirements within established timelines as directed by senior staff and program leadership.

Security & Compliance
  • Complete all required annual cybersecurity awareness training within established deadlines and maintain all required certifications as current and unexpired throughout the period of performance.
  • Ensure all work products are Section 508 accessibility compliant where required, government-owned, and free of proprietary or company-specific markings or restrictions.
  • Adhere to all applicable Federal security, privacy, and compliance requirements, including FISMA, NIST SP 800-53, NIST SP 800-160, OMB Circular A-130, and agency-specific cybersecurity policies, in the performance of all assigned duties.

Education and Experience:
Required:
  • Bachelor's degree in Computer Science, Software Engineering, Cybersecurity, Information Technology, Information Systems, or a related field from an accredited college or university. Equivalent combination of education and directly relevant work experience may be considered in lieu of a degree.
  • Minimum of 1-2 years of experience in software development, DevOps, DevSecOps, application security, or a closely related technical field, including internship, academic project, or entry-level professional experience in a federal government IT environment or federal contractor setting.
  • Demonstrated foundational knowledge of secure software development lifecycle (SDLC) principles, CI/CD pipeline concepts, and application security testing methodologies obtained through cour

Koniag logo

About Koniag

Sourced by ZipRecruiter

Industry

Investment management and consulting services

Company size

501 - 1,000 Employees

Headquarters location

Kodiak, AK, US

Year founded

1972

Social media