MatrixSpace
Posted 1d ago

DevSecOps Engineer

MatrixSpace
Burlington, Massachusetts, United States
$125k-$150k/yrHybridFull Time
Responsibilities
  • securing infrastructure
  • automating deployments
  • maintaining compliance
Requirements
  • Requires 3–6 years in security engineering
  • Cloud security
  • DevSecOps, or related fields
  • AWS, Linux, IAM, CI/CD
  • Infrastructure as code
  • Security frameworks
  • Vulnerability remediation, and strong collaboration skills
Technical tools mentioned
AWSLinuxIAMTerraformPulumiPythonCI/CDInfrastructure as CodeFedRAMPNIST 800-53NIST 800-171CMMCRMFAWS GovCloudFIPS 140DISA STIGs

Job description

Help build, operate, and secure the cloud infrastructure that enables MatrixSpace to deliver trusted technology to U.S. government customers.

MatrixSpace develops AI-enabled radar and sensing systems that help people understand what's happening in the world around them. By combining advanced radar, edge computing, and AI, we deliver situational awareness in environments where traditional sensing solutions struggle.

We're looking for a hands-on DevSecOps Engineer to join our Release Engineering team. You’ll work across DevOps, cloud infrastructure, security, and compliance, to build secure AWS environments, improve deployment and release workflows, and support FedRAMP and other government security requirements.

If you're technically curious, security-minded, and comfortable moving between DevOps engineering and security/compliance work, we'd love to talk.

What You'll Do

  • Build, operate, assess, and secure AWS environments against established security baselines, FedRAMP requirements, and other applicable security standards.
  • Partner with Software Engineering and AI teams to incorporate security and compliance requirements into system architecture, CI/CD, deployment, and operational workflows.
  • Support FedRAMP authorization and continuous monitoring activities, including evidence collection, control maintenance, audit preparation, Plans of Action and Milestones (POA&Ms), and remediation tracking.
  • Perform and support security architecture reviews, risk and gap assessments, vulnerability management, and system hardening, including applicable DISA STIGs.
  • Implement security controls across networking, Linux systems, IAM, encryption, logging, and security monitoring.
  • Build and maintain Infrastructure as Code, CI/CD, deployment, and release automation using tools such as Terraform, Pulumi, and Python, incorporating security and compliance into repeatable infrastructure deployments.
  • Maintain required security documentation, system diagrams, asset inventories, and control implementation details.
  • Work with engineering teams, external assessors, compliance partners, and 3PAOs to support assessments, audits, evidence requests, and ongoing authorization requirements.
  • Contribute to broader Release Engineering initiatives, including CI/CD pipelines, deployment automation, release workflows, cloud infrastructure, developer tooling, and platform reliability.

What We're Looking For

This position requires working directly or indirectly with the US Government in restricted environments. Candidates must be legally authorized to work in the United States without employer sponsorship and may be required to obtain and maintain a U.S. government security clearance in the future.

Required

  • 3-6 years of experience in security engineering, cloud security, DevSecOps, infrastructure security, or a related technical field.
  • Hands-on AWS experience, including networking, Linux, IAM, encryption, logging, vulnerability management, and security monitoring.
  • Experience working with one or more security frameworks such as FedRAMP, NIST 800-53, NIST 800-171, CMMC, RMF, or similar standards.
  • Experience translating security and compliance requirements into practical technical controls alongside engineering teams.
  • Hands-on experience with DevOps practices, Infrastructure as Code, source control, CI/CD pipelines, and automated deployment workflows.
  • Knowledge of system hardening vulnerability remediation, secure configurations, and security control lifecycle management.
  • Strong problem-solving, communication, and cross-functional collaboration skills.

Someone Who Will Thrive in This Role

  • Enjoys being hands-on with infrastructure, automation, security, and release engineering.
  • Can move comfortably between technical implementation, compliance requirements, documentation, and conversations with engineers and assessors.
  • Take ownership of issues from identification through remediation and closure.
  • Prefers building security into engineering workflows rather than treating it as a separate audit function.
  • Is curious about how complex systems work and looks for ways to make security and compliance more automated, repeatable, and scalable.

Bonus Points

  • Direct experience supporting a FedRAMP authorization, particularly within a FedRAMP High environment.
  • Familiarity with AWS GovCloud and NIST 800-53 Experience working directly with external assessors, compliance partners, or a Third-Party Assessment Organization (3PAO).
  • Understanding FIPS 140, encryption and key management, secure system boundaries, and requirements associated with Controlled Unclassified Information (CUI).
  • Experience hardening Linux operating systems using DISA STIGs or similar security configuration standards.
  • Experience with Infrastructure as Code technologies such as Terraform or Pulumi, and/or Python automation.

At MatrixSpace, Release Engineering plays a key role in building the infrastructure, automation, and security foundation behind the systems we deliver to our government customers. You'll help build and operate our cloud platform, improve how we deploy and release software, and ensure security and compliance are built into our infrastructure from the start. If you enjoy working across DevOps, cloud security, and regulated environments, we'd love to hear from you.


About MatrixSpace

AI-powered radar systems for airspace safety and drone detection.

Year founded
2019
Employees
50
Organization type
Private
Latest investment
Raised $20.00M Series B (2025) — led by Raptor Group
Headquarters
US

Similar jobs

DevSecOps Engineer roles near Burlington, Massachusetts
2d
Save
Mark Applied
Hide
InfraSec Engineer
Boston or Washington, D.C.
HybridFull Time
Air Space Intelligence
Air Space Intelligence: Provides predictive AI software for aviation and defense operations.
Experience with FedRAMP or DoD controls, cloud security, AWS GovCloud, Azure GCCH or Platform One, Python or Rust, Terraform or Terragrunt, Helm, Kubernetes, and security automation; clearance required or obtainable.
AWS GovCloud, Azure GCCH, Platform One, Python, Rust, Terragrunt, Terraform, Helm, Kubernetes, AWS EKS, OWASP Top 10, SANS Top 25, SOC 2, NIST CSF, FedRAMP
4d
Save
Mark Applied
Hide
Senior Engineer
Arlington or Rome or Hanscom Air Force Base or Tacoma or McLean
$110k-$180k/yr HybridFull Time
Raft
Raft: Builds AI and data platforms for U.S. national defense.
3+ YOERequires 3+ years of relevant experience, 3+ years with Docker and Kubernetes, cloud and CI/CD expertise, streaming-platform experience, Infrastructure as Code knowledge, and ability to obtain Security+ certification within 90 days.
Kafka, Kafka Streams, Pinot, Java, Scala, Kubernetes, Docker, AWS, Prometheus, Grafana, Fluent Bit, Kibana, Loki, Terraform, Ansible, GitLab Runners, Helm Charts, Maven, Gradle, NPM, Yarn, Istio, Python, Go
1w
Save
Mark Applied
Hide
Staff DevSecOps Engineer (Portfolio)
Palo Alto or New York City or Pittsburgh or Seattle or Colorado or Austin or Boston
$180k-$280k/yr OnsiteFull Time
Section 32
Section 32: A venture capital firm investing across frontier technologies to accelerate discovery and commercialization.
Experienced DevSecOps engineer to embed security into the software development and deployment lifecycle and support growth of portfolio companies.
2w
Save
Mark Applied
Hide
Senior Staff DevSecOps Engineer
Somerville, Massachusetts, United States
$170k-$213k/yr OnsiteFull Time
Form Energy
Form Energy: Developing multi-day batteries for grid-scale energy storage.
9+ YOE9+ years in application security/DevSecOps, secure-SDLC and CI/CD hardening experience, scripting skills (Python/JavaScript/TypeScript/PowerShell), cloud and identity security knowledge, SAST/DAST/SCA experience.
Python, JavaScript, TypeScript, PowerShell, REST APIs, JSON, SAST, DAST, SCA, Git, Microsoft Azure, Google Cloud, AWS, Workato, Boomi, MuleSoft, Zapier
3mo
Save
Mark Applied
Hide
Career Level DevSecOps Engineer - Nashua, New Hampshire, United States
Nashua, New Hampshire, United States
$125k-$180k/yr HybridFull Time
Jacobs
JacobsNYSE: J: Global provider of professional engineering and technical services.
10+ YOEDevSecOps engineer with strong CI/CD, security integration, and virtualization experience; US citizen and eligible for DoD clearance; Bachelor’s degree and 10+ years of experience.
Azure DevOps, Git, MSBuild, Docker, Hyper-V, VMware, SBOMs, OWASP, Trivy, NETAnalyzers, Fortify, Kubernetes
3mo
Save
Mark Applied
Hide
Senior DevSecOps Engineer
Cambridge, Massachusetts, United States
$82k-$220k/yr OnsiteFull Time
Draper
Draper: Designs and develops advanced guidance and navigation technologies.
5+ YOE5-10 years software engineering; bachelor in CS; master preferred; strong GitLab CI/CD, Python/Bash, C/C++; cross-compilation (Yocto/Buildroot); RTOS (VxWorks/FreeRTOS/Zephyr); containers, Kubernetes; IaC (Terraform/Ansible); software supply chain security; Linux hardening; PKI/TLS; government security clearance desired.
GitLab CI/CD, Python, Bash, C/C++, Yocto, Buildroot, VxWorks, FreeRTOS, Zephyr, Docker, Podman, Kubernetes, Terraform, Ansible, SBOM, artifact signing, PKI/TLS
2w
Save
Mark Applied
Hide
Senior Innovation DevSecOps Engineer
Washington or New York City or Santa Monica or Los Angeles or Palo Alto or Chicago or Boston or Colorado or Seattle or San Francisco or San Diego or Reston
OnsiteFull Time
Cooley
Cooley: Global law firm providing legal services to high-growth industries.
5+ YOE5+ years DevSecOps/platform engineering experience with Terraform on AWS, CI/CD (GitHub Actions), security tooling (Snyk), Datadog, EMR/SIEM familiarity, and strong communication and problem-solving skills.
Microsoft Office, iManage, Terraform, AWS, GitHub Actions, Snyk, Datadog, SAST, DAST
1mo
Save
Mark Applied
Hide
DevSecOps / Platform Engineer (Boston preferred)
Boston, Massachusetts, United States
HybridFull Time
RightMove Health
RightMove Health: Virtual triage and physical therapy for musculoskeletal health.
Experienced platform/DevSecOps engineer with strong AWS (serverless) skills, infrastructure-as-code, CI/CD, observability, and security tooling (SAST/DAST/SCA); able to operate autonomously and improve developer experience.
AWS, AWS AppSync, AWS Lambda, API Gateway, Terraform, CloudFormation, CDK, TypeScript, Serverless Framework, SAST, DAST, SCA, container scanning, AWS Security Hub, AWS GuardDuty, AWS Config, Okta, AWS IAM Identity Center