DevSecOps Engineer (Mid-Level)
Remote - Full-Time
- Clearance Required: Public Trust / Suitability (HHS/CMS)
- Experience: 3–6 years
Position Summary
The Mid-Level DevSecOps Engineer will manage, secure, and optimize the automated deployment pipelines and cloud infrastructure housing the program's data staging areas. This role ensures that continuous integration and continuous delivery (CI/CD) environments strictly adhere to federal supply chain security standards, privacy guidelines (HIX SORN), and federal information systems requirements.
Key Responsibilities:
- Pipeline Security: Embed automated security scanning tools (SAST/DAST) into CI/CD workflows to proactively mitigate vulnerabilities, such as those governed by supply chain security act orders.
- Infrastructure Availability: Support infrastructure hosting environments for multi-module applications, ensuring baseline stability across all option periods.
- Access & Identity Controls: Partner with development teams to ensure identity management systems correctly provision user roles securely over public internet boundaries.
- Supply Chain Compliance: Conduct regular audits of system components and third-party dependencies to verify compliance with FAR 52.204-24/25 and FASCSA orders.
- Data Security Monitoring: Maintain configurations aligned with the HIX SORN 09-70-0560 guidelines to safeguard records retrieved by personal identifiers.
Required Qualifications:
- Bachelor’s degree in Computer Engineering, Cyber Security, Cloud Computing, or related field.
- 3+ years of experience managing automated build, test, and deploy pipelines (e.g., Jenkins, GitLab CI, GitHub Actions).
- Hands-on experience with cloud infrastructure provisioning (AWS preferred) using Infrastructure as Code (Terraform, CloudFormation).
- Proficiency with containerization tools (Docker, Kubernetes) and configuration management platform strategies.
- Solid knowledge of system security monitoring tools and log management.
Preferred Qualifications:
- Possession of relevant certifications (e.g., AWS Certified DevOps Engineer, CompTIA Security+, or Certified DevSecOps Professional).
- Experience implementing security controls under the Federal Acquisition Supply Chain Security Act (FASCSA).
- Familiarity with NARA-compliant records schedules and data disposition rules.
Company Description
Our mission is to empower our clients to achieve sustainable success through efficient, cost-effective, and scalable solutions that drive significant performance improvements. We believe in delivering value-driven results and fostering a culture that attracts and retains top talent to provide scalable, adaptable services.