Electrosoft Services
Posted 2w ago

DevSecOps Engineer

Electrosoft Services
Arlington, Virginia, United States
OnsiteFull Time
Responsibilities
  • designing pipelines
  • integrating security
  • conducting assessments
Requirements
  • 8+ years information security experience
  • 2+ years technical leadership
  • Bachelor\u0002s in CS/IT/cybersecurity
  • Experience with DevSecOps
  • STIG/RMF/FISMA
  • Cloud and IaC
  • Containerization, and federal compliance
Technical tools mentioned
SASTDASTSCAAzure DevOpsJenkinsGitLabGitHub ActionsMicrosoft AzureAWSGoogle Cloud Platform (GCP)TerraformAnsibleCloudFormationARM TemplatesDockerKubernetesOpenShiftSIEMSOAR

Job description

Electrosoft Services, LLC is an award-winning company that provides comprehensive technology-based solutions and services to federal customers. While cybersecurity is our specialty, we also focus on ICAM, Zero Trust, digital engineering and transformation, and enterprise AI and intelligent automation. We always seek to delight our customers, so we retain highly qualified employees and offer them meaningful work, growth opportunities, and work-life balance. What sets us apart from all other contractors is the sense of teamwork our employees feel – and the knowledge that outstanding effort is recognized and rewarded.  The camaraderie we share emanates from Lunch & Learn sessions where we explore new ideas together, fun group activities ranging from escape rooms to miniature golf, and much, much more. If we’ve described you and your dream workplace, please apply and share in the many benefits and opportunities we offer.

DevSecOps Engineer

Responsibilities and Duties:

  • Design, implement, and maintain secure DevSecOps pipelines that integrate security throughout the Software Development Lifecycle (SDLC).
  • Lead the implementation of security controls and automation solutions supporting Digital Solution Development, Automation, and Infrastructure Support initiatives.
  • Develop and maintain Continuous Integration/Continuous Delivery (CI/CD) pipelines to support rapid and secure software delivery.
  • Integrate automated security testing tools, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), and container security scanning.
  • Collaborate with application developers, architects, cybersecurity personnel, and infrastructure teams to embed security requirements into system designs and development processes.
  • Establish and enforce secure coding practices, vulnerability management procedures, and DevSecOps best practices.
  • Support cloud security architecture and automation efforts across cloud-hosted and hybrid environments.
  • Design and implement Infrastructure as Code (IaC) solutions using modern automation tools and frameworks.
  • Conduct security assessments, code reviews, architecture reviews, and risk analyses for applications and infrastructure platforms.
  • Monitor, analyze, and remediate security vulnerabilities identified through automated scanning and assessment tools.
  • Develop and maintain security baselines, secure configuration standards, and deployment templates.
  • Support containerization and orchestration technologies, including security hardening and compliance monitoring activities.
  • Lead security-related technical projects and provide technical guidance to project teams and stakeholders.
  • Collaborate with system administrators, network engineers, and developers to ensure secure deployment and operation of enterprise systems.
  • Support Authority to Operate (ATO), FISMA, NIST, FedRAMP, and other compliance-related activities as applicable.
  • Develop security automation capabilities to improve detection, response, monitoring, and reporting functions.
  • Participate in incident response, root cause analysis, and corrective action planning activities.
  • Mentor junior engineers and provide technical leadership on information security initiatives.
  • Create and maintain technical documentation, architecture diagrams, operational procedures, and security implementation guides.
  • Evaluate emerging DevSecOps, cloud, and security technologies and recommend improvements to organizational security posture.
  • Support enterprise modernization, automation, and digital transformation initiatives by ensuring security is integrated from design through deployment.
  • Develop security metrics, dashboards, and reports to communicate program health, risk posture, and compliance status to leadership.

Basic Qualifications

  • Bachelor’s Degree in Computer Science, Information Technology, Cybersecurity, Computer Engineering, or a related field.
  • Minimum of eight (8) years of progressive experience in information security, cybersecurity engineering, or related disciplines. Minimum of two (2) years of experience providing technical leadership for information security projects.
  • Experience supporting DoD information systems and Security Technical Implementation Guide (STIG) compliance programs.
  • Develop and maintain automation scripts and Infrastructure as Code (IaC) templates to enforce STIG-compliant configurations across enterprise environments.
  • Experience implementing DevSecOps practices within Agile, DevSecOps, or CI/CD environments.
  • Experience with security automation tools, vulnerability management platforms, and secure software development methodologies.
  • Knowledge of secure coding standards, application security principles, and security testing methodologies.
  • Experience with CI/CD platforms such as Azure DevOps, Jenkins, GitLab, GitHub Actions, or similar technologies.
  • Experience supporting cloud environments, including Microsoft Azure, AWS, or Google Cloud Platform (GCP).
  • Familiarity with Infrastructure as Code (IaC) technologies such as Terraform, Ansible, CloudFormation, or ARM Templates.
  • Knowledge of containerization and orchestration technologies such as Docker, Kubernetes, and OpenShift.
  • Strong understanding of NIST Cybersecurity Framework, NIST 800-53, RMF, FISMA, and related federal security standards.
  • Experience identifying, assessing, and mitigating application and infrastructure security risks.
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Excellent written, verbal, and presentation communication skills.
  • Ability to work effectively across multidisciplinary technical and business teams.
  • U.S. Citizen, and ability to get the clearance.

 Preferred Qualifications

  • Experience supporting Department of Homeland Security (DHS) and/or Cybersecurity and Infrastructure Security Agency (CISA) programs.
  • Experience designing and implementing Zero Trust architectures and modern cloud security solutions.
  • Knowledge of Infrastructure Automation, Platform Engineering, and Site Reliability Engineering (SRE) practices.
  • Experience supporting FedRAMP, Continuous Diagnostics and Mitigation (CDM), or enterprise cybersecurity programs.
  • Hands-on experience with SIEM, SOAR, and security monitoring technologies.
  • Relevant certifications such as CISSP, CCSP, AWS Security Specialty, Azure Security Engineer Associate, GIAC certifications, Certified DevSecOps Professional, Security+, or equivalent.
  • Experience supporting enterprise modernization, application transformation, and infrastructure automation programs.

Electrosoft is an Equal Opportunity Employer/Veterans/Disabled

About Electrosoft Services

Federal cybersecurity, digital engineering, and IT solutions provider

Similar jobs

DevSecOps Engineer roles near Arlington, Virginia
8h
Save
Mark Applied
Hide
Sr. DevSecOps Engineer I
Washington, District of Columbia, United States
$170k-$220k/yr OnsiteFull Time
M9 Solutions
M9 Solutions: Provides IT modernization and technology services to federal agencies.
5+ YOERequires active TS/SCI clearance, BA/BS in an IT-related field or equivalent experience, DoD 8140 certification, and 5+ years of DevSecOps experience with enterprise CI/CD and security platforms.
.NET, CI/CD
10h
Save
Mark Applied
Hide
Senior DevSecOps Engineer
Chantilly or Herndon
$150k-$170k/yr OnsiteFull Time
Dark Wolf Solutions
Dark Wolf Solutions: Provides cybersecurity and software development services to defense agencies.
7+ YOEBachelor's degree and 7+ years building CI/CD pipelines, including 3+ years in infrastructure automation. Requires US citizenship, active TS/SCI clearance with Full-Scope Polygraph, and expertise in DevSecOps tools and cloud platforms.
Jenkins, GitLab CI/CD, Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Kubernetes, Open Policy Agent (OPA), Kyverno, Falco, HashiCorp Vault, AWS Secrets Manager, ArgoCD, Flux, Prometheus, Grafana, ELK, OpenSearch, OpenTelemetry, Python, Go, Bash, C/C++, Docker, Podman, AWS, Azure, GCP, SonarQube, Snyk, Trivy, OWASP ZAP, Git, Jira, Linux, Agile, Scrum
15h
Save
Mark Applied
Hide
DevSecOps Engineer
Chantilly, Virginia, United States
$62k-$141k/yr OnsiteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Consulting and technology services for government and commercial clients
DevSecOps, CI/CD, container, AWS or OpenShift, Kubernetes, and infrastructure/configuration-as-code experience; TS/SCI clearance, high school diploma/GED, and DoD 8570 IAT certification eligibility required.
CI/CD, Amazon Web Services (AWS), OpenShift, Kubernetes, Terraform, Ansible, EKS, AKS, Azure, Flux, Argo CD, Kustomize, Linux, UNIX
1d
Save
Mark Applied
Hide
DevSecOps Engineer – AI-Enabled Cloud Automation
Reston or Washington or Columbia
HybridContract
BizTech Fusion
BizTech Fusion: An IT professional services and consulting firm delivering technology solutions to public- and private-sector clients.
3+ YOERequires U.S. citizenship, eligibility for SEC Public Trust, 3+ years of DevOps/DevSecOps experience, AWS, IaC, CI/CD, security automation, FedRAMP/NIST, scripting, and Agile collaboration.
AWS, AWS CDK, CloudFormation, AWS CodePipeline, AWS CodeBuild, Infrastructure as Code (IaC), CI/CD, SAST, DAST, SCA, Python, Bash
1d
Save
Mark Applied
Hide
DevSecOps Engineer
Chantilly or Dayton or El Segundo or Aurora or Colorado Springs
$62k-$141k/yr OnsiteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Provides technology and management consulting services to diverse organizations.
DevSecOps, CI/CD, containerization, AWS or OpenShift, Kubernetes, Infrastructure as Code, TS/SCI clearance, high school diploma/GED, and ability to obtain DoD 8570 IAT certification.
CI/CD, Amazon Web Services (AWS), OpenShift, Kubernetes, Terraform, Ansible, EKS, AKS, Azure, Flux, Argo CD, Kustomize, Linux, UNIX
1d
Save
Mark Applied
Hide
DevSecOps Engineer
Arlington or Rosslyn
HybridFull Time
SAIC
SAICNASDAQ: SAIC: Provides government and defense clients with technology and engineering services.
5+ YOEBachelor's with 5+ years or master's with 3+ years, or equivalent experience; DevSecOps, CI/CD, cloud security, infrastructure as code, automated security testing, compliance, US citizenship, and active secret clearance required.
Terraform, CloudFormation, Ansible, Kubernetes, CI/CD
1d
Save
Mark Applied
Hide
DevSecOps Engineer
Reston, Virginia, United States
$155k-$205k/yr OnsiteFull Time
Fortreum
Fortreum: Provides cybersecurity compliance and technical auditing services for regulated industries.
7+ YOERequires 7+ years in DevOps, platform engineering, or SRE; AWS and Terraform expertise; Kubernetes production experience; compliance knowledge; scripting; U.S. citizenship; and ability to obtain Top Secret clearance.
AWS, Azure, GCP, Terraform, Kubernetes, EKS, Helm, ArgoCD, GitHub, GitOps, JIRA, Splunk, Snyk, Python, Bash, OSCAL, SAST, DAST, MCPs, LLM
1d
Save
Mark Applied
Hide
Sr. DevSecOps Engineer I (6801)
North America or Washington
$170k-$220k/yr HybridFull Time
MetroStar
MetroStar: Provides digital transformation and IT services to government agencies.
5+ YOERequires active Top Secret with current or previously held SCI access, BA/BS in IT or equivalent experience, DoD 8140 certification, and 5+ years of DevSecOps experience.
.NET, CI/CD