SAIC
Posted 3d ago

DevSecOps Engineer

SAIC
Arlington or Rosslyn
HybridFull Time
Responsibilities
  • designing pipelines
  • implementing controls
  • automating processes
Requirements
  • Bachelor's with 5+ years or master's with 3+ years, or equivalent experience
  • DevSecOps, CI/CD
  • Cloud security
  • Infrastructure as code
  • Automated security testing
  • Compliance
  • US citizenship, and active secret clearance required
Technical tools mentioned
TerraformCloudFormationAnsibleKubernetesCI/CD

Job description

SAIC has an opportunity for a DevSecOps Engineer to integrate security into the software development and delivery lifecycle. This role will design, implement, and operate secure CI/CD pipelines, cloud infrastructure, automation, and security controls that enable development teams to deliver reliable software quickly and safely. The ideal candidate combines hands-on engineering expertise with a strong understanding of application security, cloud security, infrastructure as code, and modern software delivery practices. This role partners closely with software engineers, platform teams, architects, cybersecurity teams, and compliance stakeholders.

This role requires 1 day each week onsite in Rosslyn, VA.

Key Responsibilities: 

  • Design, implement, and maintain secure CI/CD pipelines across development, test, and production environments.
  • Embed automated security testing into the software development lifecycle, including static application security testing, dynamic testing, software composition analysis, container scanning, and secrets detection.
  • Develop and manage infrastructure as code using tools such as Terraform, CloudFormation, or Ansible.
  • Implement security controls across cloud platforms, containers, Kubernetes, APIs, and enterprise applications.
  • Establish and enforce policy-as-code, secure configuration standards, and deployment guardrails.
  • Integrate vulnerability management findings into engineering workflows and support timely remediation.
  • Partner with development teams to identify security risks, perform threat modeling, and improve secure coding practices.
  • Automate security, compliance, and operational processes to improve consistency and reduce manual effort.
  • Monitor pipeline, infrastructure, and application security events; support investigation and remediation of security incidents.
  • Maintain technical documentation, runbooks, architecture diagrams, and control evidence.
  • Contribute to security architecture reviews, technology evaluations, and continuous improvement initiatives.
  • Support compliance with applicable organizational policies, contractual requirements, and regulatory frameworks.
     

Qualifications

Required Education & Experience:

  • Bachelors and 5+ years or more experience; Masters and 3+ years; may accept additional experience in lieu of degree.
  • Demonstrated experience integrating security into CI/CD pipelines and cloud infrastructure.
  • Proficiency with infrastructure as code tools such as Terraform, CloudFormation, or Ansible.
  • Strong understanding of application security, cloud security, and secure software delivery practices.
  • Ability to implement and manage automated security testing within the software development lifecycle.
  • Experience collaborating with cross-functional teams including developers, architects, and cybersecurity professionals.
  • Familiarity with regulatory compliance frameworks and organizational security policies.
     

Required Clearance:

  • US Citizenship.
  • Active secret clearance. 

Company

SAIC® is a premier mission integrator focused on advancing the power of technology and innovation to serve and protect our world. Our robust portfolio of offerings across the defense, space, intelligence, and civilian markets includes secure high-end solutions in mission IT, enterprise IT, engineering services, and professional services. We integrate emerging technology, rapidly and securely, into mission critical operations that modernize and enable critical national imperatives.


We are approximately 23,000 strong; driven by mission, united by purpose, and inspired by opportunities. SAIC is an Equal Opportunity Employer. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $7.3 billion. For more information, visit saic.com. For ongoing news, please visit our newsroom.

About SAIC

Provides government and defense clients with technology and engineering services.

Similar jobs

DevSecOps Engineer roles near Arlington, Virginia
6h
Save
Mark Applied
Hide
Sr. DevSecOps
Washington, District of Columbia, United States
OnsiteFull Time
VIA
VIA: Provides secure decentralized identity and data privacy software solutions.
5+ YOERequires Secret clearance eligibility, Security+ certification, 5+ years with a bachelor's degree or 8+ years of DevOps/cloud experience, Azure DevOps, Kubernetes, Helm, Docker, IaC, scripting, and classified-environment experience.
Microsoft Azure, Azure DevOps, Azure DevOps Pipelines, Kubernetes, Helm, Docker, Python, Nessus, SonarQube, Aqua Security, SQL, NoSQL, Elasticsearch, OpenSearch, Linux, Databricks, Spark, Hadoop, Power BI, Tableau, STIGs, Risk Management Framework (RMF)
13h
Save
Mark Applied
Hide
DevOps Engineer 3
Reston, Virginia, United States
OnsiteFull Time
Base-2 Solutions
Base-2 Solutions: Delivers engineering and technology services for national security.
10+ YOERequires 10+ years of DevSecOps experience, active Top Secret/SCI with CI Polygraph, DoD IAT Level II certification, CI/CD, containerization, IaC, Linux, scripting, and AWS expertise.
GitLab CI/CD, Jenkins, Docker, Terraform, CloudFormation, Ansible, Python, Bash, Linux, RHEL, Oracle Linux, AWS, Amazon EC2, Amazon S3, IAM, Amazon RDS, Artifactory, SonarQube, Prisma Cloud, Azure, GCP
22h
Save
Mark Applied
Hide
Junior DevSecOps Engineer – AWS
Reston or Washington
HybridContract
BizTech Fusion
BizTech Fusion: An IT professional services and consulting firm delivering technology solutions to public- and private-sector clients.
3+ YOERequires 3+ years of DevOps/DevSecOps experience, AWS, CodePipeline, CodeBuild, CDK or CloudFormation, scripting, security integration, U.S. citizenship, clearance eligibility, and active AWS DevOps or Security certification.
AWS, AWS CodePipeline, AWS CodeBuild, AWS CDK, CloudFormation, SAST, DAST, SCA, Python, Bash, FedRAMP, NIST, Agile, Scrum
23h
Save
Mark Applied
Hide
IT Lead – DevSecOps Engineer
Chantilly, Virginia, United States
OnsiteFull Time
KBR
KBRNYSE: KBR: Provides engineering, technology, and professional services for global markets.
7+ YOE2+ MgmtBachelor's degree or equivalent experience, 7+ years in DevOps, DevSecOps, or software engineering, and 2+ years in technical leadership. Requires enterprise CI/CD, repository migration, testing, OpenShift/Kubernetes, cloud, and security expertise.
Azure DevOps, GitHub, GitHub Actions, SonarQube, Sonatype, Fortify, Katalon, OpenShift, Software Composition Analysis (SCA), Kubernetes, Microsoft Azure, OWASP Top 10, PowerShell, Python, Bash, GitHub Advanced Security, Open Policy Agent, Azure Policy, CISSP, CSSLP, CEH, NIST, ISO 27001, SOC 2
1d
Save
Mark Applied
Hide
Mid-level DevSecOps Engineer
Arlington, Virginia, United States
$100k-$140k/yr OnsiteFull Time
Decision Technologies
Decision Technologies: Provides engineering and technical support for defense programs.
3+ YOERequires strong knowledge of containers, Terraform, Kubernetes, DoD cloud networks, firewalls, and security requirements; eligibility for a DoD Secret clearance. Python or SQL and DoD software experience preferred.
Terraform, Kubernetes, Python, SQL
1d
Save
Mark Applied
Hide
DevSecOps Engineer - Leesburg
Leesburg or Washington
$155k-$205k/yr HybridFull Time
Fortreum
Fortreum: Provides cybersecurity compliance and technical auditing services for regulated industries.
7+ YOERequires 7+ years in DevOps, platform engineering, or SRE; AWS and Terraform expertise; production Kubernetes experience; regulated compliance experience; scripting; U.S. citizenship; and ability to obtain Top Secret clearance.
AWS, Azure, GCP, Terraform, Kubernetes, EKS, Helm, ArgoCD, NIST 800-53, OSCAL, GitHub, JIRA, Splunk, Snyk, Python, Bash, Security+, AWS Certified Security, CYSA+, CISSP, LLM, MCP
2d
Save
Mark Applied
Hide
Sr. DevSecOps Engineer I
Washington, District of Columbia, United States
$170k-$220k/yr OnsiteFull Time
M9 Solutions
M9 Solutions: Provides IT modernization and technology services to federal agencies.
5+ YOERequires active TS/SCI clearance, BA/BS in an IT-related field or equivalent experience, DoD 8140 certification, and 5+ years of DevSecOps experience with enterprise CI/CD and security platforms.
.NET, CI/CD
2d
Save
Mark Applied
Hide
Senior DevSecOps Engineer
Chantilly or Herndon
$150k-$170k/yr OnsiteFull Time
Dark Wolf Solutions
Dark Wolf Solutions: Provides cybersecurity and software development services to defense agencies.
7+ YOEBachelor's degree and 7+ years building CI/CD pipelines, including 3+ years in infrastructure automation. Requires US citizenship, active TS/SCI clearance with Full-Scope Polygraph, and expertise in DevSecOps tools and cloud platforms.
Jenkins, GitLab CI/CD, Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Kubernetes, Open Policy Agent (OPA), Kyverno, Falco, HashiCorp Vault, AWS Secrets Manager, ArgoCD, Flux, Prometheus, Grafana, ELK, OpenSearch, OpenTelemetry, Python, Go, Bash, C/C++, Docker, Podman, AWS, Azure, GCP, SonarQube, Snyk, Trivy, OWASP ZAP, Git, Jira, Linux, Agile, Scrum