Zantech
Posted 1w ago

DevSecOps / Security Engineer

Zantech
Arlington, Virginia, United States
OnsiteFull Time
Responsibilities
  • building pipelines
  • automating infrastructure
  • supporting RMF
Requirements
  • Requires 5+ years in DevSecOps, RMF, and cloud infrastructure automation
  • Bachelor's degree or equivalent experience
  • DoDM 8140.03 certification
  • Ability to obtain Secret clearance
Technical tools mentioned
JenkinsGitLab CI/CDAnsibleAWSMicrosoft AzureTerraformCloudFormationNessusOpenSCAPSplunkELK StackDockerKubernetesSASTDASTeMASS

Job description

Are you looking for your next challenge? Are you ready to work with a performance-based small company? At Zantech, we are a dynamic Woman Owned Small Business focused on providing complex, mission-focused solutions with a proven track record of outstanding customer performance and high employee satisfaction. We would love to talk with you regarding the next step in your career. Come join our team!

Zantech is looking for a talented DevSecOps / Security Engineer to contribute to the success of our upcoming Technical Infrastructure and Platform Support project for an On-Site role based out of Arlington, VA.

The DevSecOps / Security Engineer will play a crucial role in providing:

  • Technical Infrastructure and Platform Support
  • Cybersecurity and Information Assurance (RMF, continuous ATO, Compliance-as-Code)

The DevSecOps / Security Engineer serves as the lead technical engineer for automation, CI/CD, and security posture of the cloud infrastructure, directly executing Technical Infrastructure and Platform Support requirements and supporting continuous Authority to Operate (ATO) under the DoD Risk Management Framework.

Responsibilities include, but will not be limited to:

  • Build and maintain secure, automated CI/CD pipelines and zero-downtime deployment processes
  • Automate infrastructure provisioning and configuration management via Infrastructure as Code
  • Support the RMF process: System Security Plan, Security Assessment Report, and POA&M development and continuous monitoring
  • Apply and automate DISA STIGs; run vulnerability scanning and manage remediation
  • Integrate SAST/DAST testing and auto-generate compliance-as-code artifacts (e.g., Ports/Protocols/Services, topology diagrams) for eMASS

Required Experience or Knowledge of the following technologies/functions:

  • 5 years in DevSecOps, including designing, implementing, and maintaining CI/CD pipelines and automating software deployment (Jenkins, GitLab CI/CD, or Ansible)
  • 5 years supporting the Risk Management Framework (RMF) for DoD or federal systems, including DISA STIGs, vulnerability assessments, and patching/remediation
  • 5 years automating cloud infrastructure and platform provisioning (AWS, Azure) using Infrastructure as Code (Terraform or CloudFormation).
  • Skills Required:
    •  CI/CD pipeline design and secure software deployment automation
    • Infrastructure as Code (Terraform, Ansible, CloudFormation)
    • Security scanning and monitoring/logging integration (Nessus, OpenSCAP, Splunk, ELK Stack)
    • Containerization and orchestration in microservices architectures (Docker, Kubernetes)
    • SAST/DAST integration directly into the CI/CD pipeline
    • RMF process support, DISA STIG application, and continuous ATO / eMASS artifact automation

Required Education/Certifications:

  • Education Required:
    • Bachelor's degree in computer science, engineering, or equivalent, and 5+ years of experience   OR
    •  AA with 7+ years of experience is an accepted substitute
  • Education Preferred: 
    • Bachelor's degree in Computer Science, Cybersecurity, or a related field
  • Certifications Required:
  • Current DoDM 8140.03-qualifying certification for the assigned cyberspace work role, e.g., Security+ or CySA+)
  • Certifications Preferred:
    • CISSP, AWS/Azure security specialty certification, Certified Kubernetes Security Specialist (CKS)

Required Security Clearance:

  • US Citizenship and the ability to obtain and maintain an active Secret or higher clearance, per contract requirements.

Outstanding Performance…Always!”

Our corporate motto represents our commitment to build long-term relationships with both our clients and our employees by providing the highest quality service in everything we do. We strive for excellence for our clients and for each other. We embrace the opportunity to hire individuals with new talents and fresh perspectives. Zantech offers competitive compensation, strong benefits, and a vacation package, as well as a fast-paced and exciting work environment. Come join our team!

About Zantech

Women-owned federal IT contractor providing cybersecurity, cloud, software, AI, and digital-modernization services to U.S. government agencies.

Similar jobs

DevSecOps Security Engineer roles near Arlington, Virginia
3mo
Save
Mark Applied
Hide
Mid-Level DevSecOps SME / Cloud Security Engineer (ISSE)
Colorado Springs or Herndon
$130k-$140k/yr HybridFull Time
Dark Wolf Solutions
Dark Wolf Solutions: Private IT consultancy delivering cybersecurity, software, cloud, data, and mission-engineering services to defense and intelligence customers.
5+ YOE5+ years IT security/DevSecOps; Kubernetes/Docker; cloud experience (AWS/GCP); customer engagement; security docs; TS/SCI clearance; IAT Level 2; CS/Cyber degree.
Kubernetes, Docker, Istio, ArgoCD, GitLab CI/CD, SonarQube, Snyk, OWASP ZAP, Grafana, Loki, Prometheus, Tempo