CaVU Consulting
Posted 1mo ago

DevSecOps Engineer / AWS Cloud Engineer (Serverless, CI/CD, IaC, ECS Fargate) | San Diego, CA

CaVU Consulting
San Diego, California, United States
$145k-$230k/yrOnsiteFull Time
Responsibilities
  • designing architecture
  • building automation
  • embedding security
Requirements
  • Hands-on AWS DevSecOps experience with serverless
  • CI/CD (GitLab)
  • IaC (CloudFormation)
  • ECS/Fargate
  • MySQL/RDS
  • Scripting (Python/Bash)
  • Security+ and AWS Cloud Practitioner certs, and ability to obtain TS clearance
Technical tools mentioned
AWS LambdaAPI GatewayAWS Step FunctionsDockerAmazon ECSFargateAWS CloudFormationGitLab CI/CDMySQLAmazon RDSPythonBashIAMVPCKMSCloudWatchCloudTrailAWS Secrets ManagerSSM Parameter StoreAWS CDKTerraformOpenTelemetryX-RayJWTOAuthWAF

Job description

DevSecOps Engineer / AWS Cloud Engineer (Serverless, CI/CD, IaC, ECS Fargate)| San Diego, CA

 

Team CaVU

Our name is derived from the aviation acronym “Ceiling and Visibility Unlimited”. Team CaVU embodies this positive vibe as we bring creative, powerful and innovative solutions to clients and partners. CaVU is the provider of choice for our clients, crafting best-value support across a wide spectrum of functional areas. We are defined by integrity, technical excellence and commitment to our clients, people and partners. We consistently make a lasting, positive impact on our community—we make things better!

 

Job Description:

We are seeking a highly skilled AWS Cloud / DevSecOps Engineer to design, build, and maintain secure, scalable, highly automated cloud-native environments on AWS. This role will lead the engineering of production-grade serverless APIs, event-driven workflows, and containerized services, while embedding security and operational excellence into every stage of the delivery lifecycle (infrastructure, pipelines, runtime, and monitoring). You will partner closely with application engineers (frontend and backend), architects, and security stakeholders to deliver mission-critical systems with strong reliability, performance, and governance.



Key Responsibilities

Cloud architecture & delivery

  • Design and implement cloud-native architectures on AWS, emphasizing serverless-first patterns where appropriate.
  • Build and maintain production-ready serverless APIs using AWS Lambda, API Gateway, and related integration patterns (authorizers, throttling, request validation, WAF integration as needed).
  • Create event-driven workflows and orchestration using AWS Step Functions, including retries, error handling, idempotency, and observability.
  • Design and maintain containerized workloads using Docker and Amazon ECS on Fargate, including task definitions, scaling, service discovery, and secure networking.

Infrastructure as Code (IaC) & environment management

  • Develop and manage infrastructure using AWS CloudFormation (and/or complementary IaC practices as applicable), ensuring reusability, composability, and environment parity (dev/test/prod).
  • Implement guardrails for consistent provisioning: tagging standards, baseline security controls, secrets handling, and standardized logging/monitoring.
  • Manage VPC, subnets, routing, security groups, NACLs, endpoints, and connectivity patterns for secure, least-privilege architectures.

CI/CD & automation (DevSecOps)

  • Build and maintain GitLab CI/CD pipelines for automated testing, security checks, deployments, and rollbacks across multiple environments.
  • Automate release workflows for serverless and container platforms (blue/green or canary strategies where applicable).
  • Implement pipeline-integrated security controls (e.g., dependency scanning, container scanning, IaC scanning, policy-as-code where applicable) and ensure audit-ready traceability.

Security engineering (built-in, not bolted-on)

  • Architect secure AWS environments leveraging IAM (least privilege, role-based access, permission boundaries where useful), encryption (KMS), and secure secrets management.
  • Implement logging and detection best practices using services such as CloudWatch Logs/Metrics/Alarms, CloudTrail, and centralized log aggregation patterns.
  • Ensure secure configuration and operational readiness: patching/immutability strategies, secure image practices, runtime hardening, and incident response readiness.

Data & persistence

  • Design and maintain MySQL / Amazon RDS environments, including backups, parameter tuning, maintenance windows, read replicas (if needed), and secure connectivity.
  • Support application teams with data-access patterns, migrations, and reliability considerations (connection management for serverless, pooling/proxy patterns where applicable).

Required Qualifications

  • Hands-on expertise building serverless solutions with AWS Lambda, API Gateway, and Step Functions in production.
  • Strong experience with AWS CloudFormation for provisioning and managing environments.
  • Strong CI/CD experience, specifically building and operating GitLab CI/CD pipelines.
  • Strong container expertise with Docker and running workloads on ECS Fargate (services, tasks, scaling, networking).
  • Demonstrated experience architecting secure AWS environments using IAM, VPC/networking, encryption, and logging/auditing best practices.
  • Experience designing/operating MySQL / Amazon RDS in production.
  • Strong scripting/automation skills (e.g., Python and/or Bash) to streamline workflows and reduce toil.
  • Ability to collaborate effectively with frontend/backend engineering teams and translate requirements into secure, automated platform capabilities.
  • Security+ or higher certification
  • AWS Cloud Practitioner certification or higher
  • TS security clearance or the ability to obtain one

Preferred Qualifications (Nice to Have)

  • Familiarity with AWS CDK or Terraform (even if CloudFormation remains primary).
  • Experience with API security patterns: OAuth/OIDC integration, JWT authorizers, rate limiting/throttling, WAF, mTLS (where required).
  • Experience with secrets management (e.g., AWS Secrets Manager / SSM Parameter Store) and key management (KMS).
  • Observability stack experience beyond basics: structured logging, tracing (e.g., X-Ray/OpenTelemetry patterns), metrics-driven alerting.
  • Experience implementing policy-as-code and governance (e.g., SCPs/Organizations, config rules, control frameworks).
  • Experience with performance/cost optimization for serverless and Fargate workloads.
  • Prior experience in regulated environments requiring audit evidence and secure SDLC controls.

Core Skills & Competencies

  • DevSecOps mindset: security and automation as first-class design principles.
  • Systems thinking: understands tradeoffs across reliability, latency, cost, and security.
  • Engineering rigor: version control, reviews, testing, change management, and documentation.
  • Operational ownership: can carry systems from build → run with strong on-call hygiene.
  • Clear communication: able to explain architecture decisions to technical and non-technical stakeholders.

 

Comprehensive Compensation & Benefits Package:

Salary at CaVU is determined by various factors, including but not limited to location, education, training, certificates, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The expected salary range for this position is $145,000.00 - $175,000. To drive fair pay practices for employees, CaVU conducts regular comparisons across our employee groups and the industry. The above salary range represents a general guideline; however, CaVU considers a number of factors when determining salary offers such as the scope and responsibilities of the position and the candidate's experience, education, skills and current market conditions.

 

At CaVU, our offerings include:

  • 100% company-paid health, dental, and vision (to include individual, employee + significant other, or family)
  • 401K match with immediate vesting the date of hire with CaVU
  • Employer paid $100,000 life insurance policy
  • 11 paid holidays
  • 10 days of vacation with graduating accruals every two years and 5 days of sick leave 
  • Access to corporate discounts on retail/travel/entertainment
  • Highly competitive compensation and opportunities for bonuses

 

EEO Commitment

CaVU is proud to be an equal opportunity employer, seeking to create a welcoming and diverse environment. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, ancestry, physical or mental disability, medical condition, marital status, genetics, age, or veteran status or any other applicable legally protected status or characteristic.


About CaVU Consulting

Government technical services and engineering for defense operations.

Similar jobs

DevSecOps Engineer roles near San Diego, California
3d
Save
Mark Applied
Hide
DevSecOps Engineer, Engineering & Operations
San Diego, California, United States
$131k-$164k/yr OnsiteFull Time
California Coast Credit Union
California Coast Credit Union: Provides member-owned banking and diverse financial services to members.
5+ YOEBachelor's degree or equivalent experience and 5–7 years of infrastructure engineering experience; requires DevOps, cloud, infrastructure automation, IaC, CI/CD, security, and regulated-environment expertise.
Terraform, Ansible, VMware Aria, ARM, Bicep, PowerShell, Python, Bash, Azure DevOps, GitLab, Jenkins, GitHub Actions, Bitbucket, Windows Server, Linux, VMware vSphere, Microsoft Azure, Microsoft Entra ID, Active Directory, Docker, Kubernetes, Helm, OpenShift, VMware NSX, Horizon VDI, Jira, Jira Service Management, Confluence, ServiceNow
1w
Save
Mark Applied
Hide
Senior DevSecOps Engineer
San Diego, California, United States
$112k-$179k/yr HybridFull Time
Peraton
Peraton: Provides advanced technology and mission support for government agencies.
8+ YOESecret-cleared (or able to obtain) U.S. citizen with strong Kubernetes and containerization skills, 5+ years container/CI/CD/IaC/Linux/scripting experience and CompTIA Security+ (or obtain within 45 days). Must live in San Diego area.
Kubernetes, Docker, Podman, Buildah, OpenShift, Helm, GitLab, Jenkins, AWS Code Build, Terraform, Ansible, CloudFormation, RHEL, CentOS, Ubuntu, Bash, Python, PowerShell, AWS, Azure, Java, TypeScript, React, SQL, JIRA, Confluence, Bitbucket
1w
Save
Mark Applied
Hide
Senior DevSecOps Engineer
San Diego, California, United States
$112k-$179k/yr HybridFull Time
Peraton
Peraton: National security and mission-critical government technology services provider.
8+ YOEU.S. citizen with Secret clearance (or ability to obtain), CompTIA Security+ or obtain within 45 days, strong Kubernetes and containerization experience, 8+ years with BS (or equivalent with higher degree), CI/CD, IaC, Linux, and scripting skills.
Kubernetes, OpenShift, Helm, Docker, Podman, Buildah, GitLab, Jenkins, AWS Code Build, Terraform, Ansible, CloudFormation, RHEL, CentOS, Ubuntu, Bash, Python, PowerShell, AWS, Azure, Java, TypeScript, React, SQL, JIRA, Confluence, Bitbucket
1w
Save
Mark Applied
Hide
Multi-Domain DevSecOps Engineer
San Diego, California, United States
$133k-$226k/yr HybridFull Time
BAE Systems
BAE SystemsLondon Stock Exchange: BA: Provides advanced defense, aerospace, and security technology solutions.
Proven DevSecOps experience, TS/SCI clearance, cloud and on-premises infrastructure expertise, containerization, CI/CD, scripting (Python/Bash/PowerShell), automation tooling, and Linux administration.
AWS GC, Kubernetes, Docker, Rancher, Docker Swarm, Python, Bash, PowerShell, Ansible, Puppet, Chef, GitLab, Nagios, Prometheus, ELK stack, Linux/Unix
2w
Save
Mark Applied
Hide
Senior DevSecOps Engineer
Poway, California, United States
$98k-$171k/yr OnsiteFull Time
General Atomics Aeronautical Systems
General Atomics Aeronautical Systems: Designs and manufactures unmanned aircraft and radar systems.
3+ YOEDesign and productionize AI/ML systems, CI/CD, automation, and data pipelines; experience with cloud, containers, infrastructure-as-code, and scripting; ability to obtain DoD clearance.
GIT, SVN, MLFlow, DVC, S3, Jenkins, Gitlab, RedHat, Puppet, Ansible, Terraform, RPMs, Yum, Pypi, pip, Artifactory, VMWare, VirtualBox, QEMU, Docker, Podman, Vagrant, Packer, Kubernetes, Apache, NGINX, VDI, DAAS, AWS, Azure, Python, Bash, Powershell, C#, C, Java, scikit-learn, Keras, PyTorch, Tensorflow
1mo
Save
Mark Applied
Hide
Principal DevSecOps Engineer
San Diego, California, United States
$155k-$200k/yr OnsiteFull Time
Fuse Integration
Fuse Integration: Developing tactical communication and networking systems for defense.
12+ YOE3+ MgmtB.S. in engineering, 12+ years DevSecOps/software engineering experience with 3+ years technical leadership; expertise in C++, Python, Bash, Kubernetes, Linux, STIG compliance, GitLab CI, Ansible, and cloud (AWS/Azure). US citizenship required.
C++, Python, Bash, Kubernetes, SELinux, SBOM, GitLab CI, Ansible, Podman, Docker, RPM, Jira, GitLab, vCenter, vSphere, ESXi, GNS3, AWS, Azure, govcloud, Kickstart, Subiquity, SAST, DAST, SCA
1mo
Save
Mark Applied
Hide
DevSecOps Lead (Onsite)
San Diego, California, United States
$133k-$226k/yr OnsiteFull Time
BAE Systems
BAE SystemsLondon Stock Exchange: BA: Provides advanced defense, aerospace, and security technology solutions.
Requires active Secret clearance and U.S. person; experience leading DevSecOps activities including on-premises/cloud infrastructure, CI/CD, containerization, automation (Ansible/Puppet/Chef), scripting (Python/Bash/PowerShell), GitLab, and Linux/Unix administration.
Ansible, Puppet, Chef, Kubernetes, Docker, Rancher, Docker Swarm, Python, Bash, PowerShell, GitLab, Nagios, Prometheus, ELK stack, Linux/Unix, AWS GC
1mo
Save
Mark Applied
Hide
DevSecOps Engineer
El Segundo or Los Angeles or Washington or San Francisco or San Diego or Seattle or London
$110k-$160k/yr OnsiteFull Time
CHAOS Industries
CHAOS Industries: Develops advanced radar and sensing systems for modern defense.
4+ YOERequires active Secret clearance, 4+ years DevOps/DevSecOps experience, proficiency with CI/CD security, cloud (AWS GovCloud/Azure Government), container security, IaC, scripting (Python/Bash/Go), and automated compliance tooling.
GitHub Actions, GitLab CI, Jenkins, ACAS, Nessus, OPA, Conftest, Docker, Kubernetes, Terraform, CloudFormation, Ansible, Secrets Manager, SonarQube, Checkmarx, Snyk, OWASP ZAP, Black Duck, Gatekeeper, Kyverno, Sigstore, Cosign, Python, Bash, Go, AWS GovCloud, Azure Government