1

Secret Cleared Devsecops Engineer Jobs in Michigan

Systems Engineer - Active Secret Clearance Required We are seeking a detail-oriented Systems Engineer to support a cleared program, focusing on requirements management, traceability, and compliance ...

Systems Engineer - Active Secret Clearance Required We are seeking a detail-oriented Systems Engineer to support a cleared program, focusing on requirements management, traceability, and compliance ...

Senior Software Architect

Warren, MI

$121K - $165K/yr

Implement DevSecOps and ground vehicle safety and cybersecurity best practices. * Create ... Qualifications: * Active DoD Secret clearance required. * Bachelor's degree in Engineering or ...

Senior Software Architect

Warren, MI · On-site

$121K - $165K/yr

Required : • Active DoD Secret clearance required. • Bachelor's degree in Engineering or ... DevSecOps and ground vehicle cybersecurity best practices. • Experience in managing data ...

Senior Software Architect

Warren, MI · On-site

$121K - $165K/yr

Implement DevSecOps and ground vehicle safety and cybersecurity best practices. * Create ... Active DoD Secret clearance required. * Bachelor's degree in Engineering or Information Technology ...

Senior Software Architect

Warren, MI · On-site

$121K - $164K/yr

Implement DevSecOps and ground vehicle safety and cybersecurity best practices. * Create ... Active DoD Secret clearance required. * Bachelor's degree in Engineering or Information Technology ...

next page

Showing results 1-20

Secret Cleared Devsecops Engineer information

What is a Secret Cleared DevSecOps Engineer?

A Secret Cleared DevSecOps Engineer is an IT professional who integrates security practices into the software development and operations (DevOps) process while holding a 'Secret' level security clearance, typically required for working on sensitive government or defense projects. These engineers are responsible for automating security measures, ensuring compliance with security policies, and maintaining secure development pipelines. Their clearance allows them to access classified information necessary for their work, making them essential for secure government or defense software development environments.

What are the key skills and qualifications needed to thrive as a Secret Cleared DevSecOps Engineer, and why are they important?

To thrive as a Secret Cleared DevSecOps Engineer, you need expertise in software development, security best practices, automation, and experience with cloud infrastructure, typically supported by a relevant degree and an active Secret security clearance. Proficiency with CI/CD tools like Jenkins, Kubernetes, Docker, security scanning tools, and configuration management systems such as Ansible or Terraform is essential. Strong problem-solving, collaboration, and communication skills are crucial for integrating security seamlessly into development and operations processes. These skills ensure the delivery of secure, reliable systems that meet stringent government standards and safeguard sensitive information.

What are some common challenges faced by Secret Cleared DevSecOps Engineers when integrating security into CI/CD pipelines?

Secret Cleared DevSecOps Engineers often encounter challenges such as balancing rapid deployment with stringent security controls, ensuring compliance with government regulations, and managing sensitive data securely within automated pipelines. They must collaborate closely with development, operations, and security teams to identify vulnerabilities early and automate security testing without slowing down delivery. Additionally, maintaining security documentation and audit trails for classified projects adds another layer of complexity to the role.

What is the difference between Secret Cleared Devsecops Engineer vs Cybersecurity Analyst?

AspectSecret Cleared Devsecops EngineerCybersecurity Analyst
CertificationsSecurity+, CISSP, DevSecOps certificationsSecurity+, CEH, CISSP
Work EnvironmentDevOps teams, software development, cloud platformsSecurity operations centers, threat analysis, incident response
Employer & Industry UsageGovernment agencies, defense contractors, tech firmsCorporations, government agencies, consulting firms

The Secret Cleared Devsecops Engineer focuses on integrating security into the development and deployment processes within DevOps environments, often requiring security clearances. In contrast, a Cybersecurity Analyst primarily monitors and responds to security threats, with less emphasis on development processes. Both roles require security certifications and may work in similar industries, but their core responsibilities and daily tasks differ significantly.

What are popular job titles related to Secret Cleared Devsecops Engineer jobs in Michigan? For Secret Cleared Devsecops Engineer jobs in Michigan, the most frequently searched job titles are:
What job categories do people searching Secret Cleared Devsecops Engineer jobs in Michigan look for? The top searched job categories for Secret Cleared Devsecops Engineer jobs in Michigan are:
What cities in Michigan are hiring for Secret Cleared Devsecops Engineer jobs? Cities in Michigan with the most Secret Cleared Devsecops Engineer job openings:
Infographic showing various Secret Cleared Devsecops Engineer job openings in Michigan as of June 2026, with employment types broken down into 100% Full Time. Highlights an 79% In-person, 3% Hybrid, and 18% Remote job distribution.
Security Software Engineer On-site

Security Software Engineer On-site

Eccalon LLC

Detroit, MI

Full-time

Posted 25 days ago


Job description

Job Description

We are seeking a Security Software Engineer to build and harden software systems supporting DoD programs operating under CMMC/NIST 800-171/FedRAMP compliance requirements. You will embed security across the SDLC—from design and code review through CI/CD and cloud deployment—working alongside engineering, DevSecOps, and IT teams in a regulated, cloud-native environment (AWS Commercial and GovCloud, Azure GCC High).

Responsibilities

  • Core Engineering & Secure Development
    • Design and develop secure software with a security-first mindset baked into every phase of the SDLC.
    • Apply secure coding standards, threat modeling, and vulnerability mitigation aligned to NIST 800-53 and CMMC Level 2/3 controls.
    • Conduct architecture reviews and code hardening to address OWASP Top 10 and DoD STIGs.
    • Automate security gates in CI/CD pipelines (SAST, DAST, dependency scanning, secrets detection).
  • Security Architecture & Controls
    • Design secure system and API architectures for multi-tenant cloud environments, including GCC High and FedRAMP-authorized platforms.
    • Implement IAM controls, JIT provisioning, SSO/SAML/OIDC flows, and least-privilege authorization frameworks (e.g., Cognito, Azure AD).
    • Instrument applications with security logging and monitoring that satisfies audit and continuous monitoring requirements (AU/SI control families).
  • Vulnerability Management & Response
    • Lead code reviews, SAST/DAST scans, and targeted penetration testing; document findings against control frameworks.
    • Triage and remediate vulnerabilities within POA&M timelines; maintain artifact evidence for compliance assessments.
    • Support incident response for application-layer events; contribute to after-action reports and corrective action plans.
  • Cross-functional Collaboration
    • Serve as the embedded security champion for engineering squads, raising the security bar through mentorship and code review culture.
    • Develop and deliver security training and runbooks tailored to engineering and DevOps team members.
    • Collaborate with DevOps/SRE to enforce secure IaC, WAF rules, network controls, and runtime monitoring across AWS and Azure environments.

Required Qualifications

  • Bachelor’s degree in Computer Science, Engineering, or related field—or equivalent experience.
  • 3+ years of software engineering experience with a strong focus on security.
  • Proficiency in one or more programming languages (e.g., JavaScript/TypeScript, Python, Go, C#).
  • Experience with secure coding practices and frameworks.
  • Strong understanding of application security principles, including:
    • OWASP Top 10
    • Secure API/REST design
    • Cryptography fundamentals
    • Authentication/authorization patterns
  • Experience with code scanning tools (SAST/DAST), threat modeling, and penetration testing.
  • Familiarity with NIST 800-171, CMMC, or FedRAMP security control requirements and evidence collection.
  • Hands-on experience with AWS and/or Azure security services (IAM, WAF, Security Hub, Defender, Sentinel); GCC High or GovCloud experience a plus.

Preferred Qualifications

  • Experience with container security (Docker, ECS).
  • Working knowledge of Zero Trust Architecture principles.
  • Experience building DevSecOps pipelines in regulated environments; familiarity with tools like Prisma, Checkov, Snyk, or Aqua.
  • Relevant certifications (any of the following):
    • CISSP, CSSLP, or CASP+
    • OSCP
    • CEH
    • GIAC (GWAPT, GSEC, GWEB) or CCP/CCA (UK Cyber Essentials equivalent)
  • Experience securing microservices or event-driven architectures on ECS; background in federal or cleared environments preferred.

Eccalon logo

About Eccalon

Sourced by ZipRecruiter

We are a cross-functional collective of innovative minds that leverages technology to tackle the most challenging problems of this generation for clients, the nation, and the world. Eccalon fosters creativity, curiosity, and imagination across all departments and divisions to pioneer new ideas, products, and services. We advance innovation.​

Industry

Guided missile and space vehicle manufacturing

Company size

11 - 50 Employees

Headquarters location

Hanover, MD, US

Year founded

2017