KBR
Posted 1d ago

IT Lead – DevSecOps Engineer

KBR
Chantilly, Virginia, United States
OnsiteFull Time
Responsibilities
  • leading governance
  • modernizing pipelines
  • managing migrations
Requirements
  • Bachelor's degree or equivalent experience
  • 7+ years in DevOps
  • DevSecOps, or software engineering, and 2+ years in technical leadership. Requires enterprise CI/CD
  • Repository migration
  • Testing
  • OpenShift/Kubernetes, cloud, and security expertise
Technical tools mentioned
Azure DevOpsGitHubGitHub ActionsSonarQubeSonatypeFortifyKatalonOpenShiftSoftware Composition Analysis (SCA)KubernetesMicrosoft AzureOWASP Top 10PowerShellPythonBashGitHub Advanced SecurityOpen Policy AgentAzure PolicyCISSPCSSLPCEHNISTISO 27001SOC 2

Job description

Title:

IT Lead – DevSecOps Engineer

At KBR, we deliver science, technology, and engineering solutions that help governments and companies around the world accomplish their most critical missions and objectives. Our team is committed to innovation, collaboration, and delivering impactful solutions that drive business value.

The Lead DevSecOps Engineer provides technical leadership and strategic direction for integrating security practices across the software development lifecycle, enabling secure, scalable, and compliant application delivery. This role serves as the enterprise leader for DevSecOps platforms and practices, owning the strategy, governance, modernization, and continuous evolution of the DevSecOps toolchain, including Azure DevOps, GitHub, SonarQube, Sonatype, Fortify, Katalon, and OpenShift. The position drives repository and pipeline migrations, strengthens security and quality controls, reduces delivery risk, and advances enterprise capabilities that improve developer experience and support business-critical technology initiatives.

Trinzic is being established as an independent public company through the planned separation of KBR's Mission Technology Solutions business, which is expected to be completed on January 4, 2027. This role offers a rare opportunity to join the organization during a pivotal period of growth and transformation, helping build and support technology strategies, platforms, and practices that will position the company for long-term success while serving critical government and commercial missions around the world.

Key Responsibilities

DevSecOps Leadership & Governance

  • Lead the design, implementation, and continuous improvement of secure CI/CD pipelines using Azure DevOps and GitHub Actions.
  • Define, implement, and enforce enterprise-wide code quality and application security standards using SonarQube and Fortify.
  • Establish and maintain DevSecOps governance, including security gates, policies, standards, and compliance controls.
  • Partner with architecture, cybersecurity, infrastructure, and application development teams to embed security throughout the software development lifecycle.
  • Provide technical leadership, mentorship, and guidance to engineering and DevOps teams on secure development and DevSecOps best practices.

Security, Quality & Platform Enablement

  • Oversee Software Composition Analysis (SCA) practices using Sonatype to identify and manage open-source software risks.
  • Lead the development, adoption, and standardization of automated testing frameworks utilizing Katalon or comparable platforms.
  • Drive container platform security, governance, and operational best practices within OpenShift environments.
  • Oversee vulnerability management activities, including identification, prioritization, remediation planning, and risk reduction efforts.
  • Develop and maintain reusable pipeline templates, automation frameworks, and standardized DevSecOps components.

Migration & Platform Transformation

  • Lead enterprise repository migrations between development platforms, including Azure DevOps and GitHub, ensuring governance, traceability, and minimal operational disruption.
  • Architect and oversee CI/CD pipeline modernization initiatives aligned with enterprise standards and strategic objectives.
  • Drive DevSecOps toolchain rationalization and consolidation efforts to improve efficiency, reduce technical debt, and standardize engineering practices.
  • Establish migration frameworks, playbooks, and implementation standards to support scalable adoption across the enterprise.

Tool Lifecycle Management & Continuous Modernization

  • Own lifecycle management activities for DevSecOps platforms, including upgrades, patching, integrations, and roadmap planning.
  • Evaluate, pilot, and deploy emerging technologies and capabilities that advance organizational DevSecOps maturity.
  • Ensure platform stability, scalability, performance, and security throughout transformation and modernization initiatives.
  • Provide strategic recommendations on DevSecOps tooling investments, architecture decisions, and long-term roadmap development.
  • Ensure compliance with internal governance requirements, security policies, and applicable regulatory frameworks while driving continuous improvement in automation and developer experience.

Basic Qualifications

Education & Experience

  • Bachelor's degree in Computer Science, Information Security, or a related discipline; equivalent combination of education and experience will be considered.
  • Minimum 7 years of experience in DevOps, DevSecOps, software engineering, or related technical disciplines.
  • Minimum 2 years of experience in a technical lead, architect, or comparable leadership role.
  • Proven experience leading enterprise repository migrations and CI/CD pipeline transformations across development platforms.
  • Experience implementing and supporting enterprise-scale automated testing frameworks.
  • Experience working with containerized platforms such as OpenShift or Kubernetes.
  • Experience supporting cloud-based environments, preferably Microsoft Azure.

Technical Expertise

  • Deep expertise with CI/CD platforms and software delivery tooling, including Azure DevOps and GitHub.
  • Strong knowledge of application security, code quality, and software composition analysis tools, including SonarQube, Fortify, and Sonatype.
  • Strong understanding of secure software development practices and common application security vulnerabilities, including OWASP Top 10 risks.
  • Experience designing and implementing enterprise DevSecOps governance frameworks and security controls.
  • Proficiency in scripting or programming languages such as PowerShell, Python, Bash, or similar technologies.

Skills & Capabilities

  • Demonstrated ability to lead complex technical initiatives across multiple stakeholder groups.
  • Strong analytical, problem-solving, and decision-making capabilities.
  • Excellent communication and collaboration skills with the ability to influence technical and non-technical audiences.
  • Ability to balance strategic planning with hands-on technical execution.
  • Strong focus on continuous improvement, automation, operational excellence, and risk management.

Preferred Qualifications

  • Experience with GitHub Advanced Security and enterprise repository governance models.
  • Experience leading large-scale DevSecOps transformations within global organizations.
  • Familiarity with policy-as-code frameworks and technologies such as Open Policy Agent or Azure Policy.
  • Professional security certifications such as CISSP, CSSLP, CEH, or equivalent.
  • Knowledge of regulatory and compliance frameworks, including NIST, ISO 27001, and SOC 2.

Belong, Connect and Grow at KBR

At KBR, we are passionate about our people and our Zero Harm culture.  These inform all that we do and are at the heart of our commitment to, and ongoing journey toward being a People First company.  That commitment is central to our team of team’s philosophy and fosters an environment where everyone can Belong, Connect and Grow. We Deliver – Together. 

KBR is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, disability, sex, sexual orientation, gender identity or expression, age, national origin, veteran status, genetic information, union status and/or beliefs, or any other characteristic protected by federal, state, or local law.

About KBR

Provides engineering, technology, and professional services for global markets.

Similar jobs

DevSecOps Engineer roles near Chantilly, Virginia
8h
Save
Mark Applied
Hide
Sr. DevSecOps
Washington, District of Columbia, United States
OnsiteFull Time
VIA
VIA: Provides secure decentralized identity and data privacy software solutions.
5+ YOERequires Secret clearance eligibility, Security+ certification, 5+ years with a bachelor's degree or 8+ years of DevOps/cloud experience, Azure DevOps, Kubernetes, Helm, Docker, IaC, scripting, and classified-environment experience.
Microsoft Azure, Azure DevOps, Azure DevOps Pipelines, Kubernetes, Helm, Docker, Python, Nessus, SonarQube, Aqua Security, SQL, NoSQL, Elasticsearch, OpenSearch, Linux, Databricks, Spark, Hadoop, Power BI, Tableau, STIGs, Risk Management Framework (RMF)
15h
Save
Mark Applied
Hide
DevOps Engineer 3
Reston, Virginia, United States
OnsiteFull Time
Base-2 Solutions
Base-2 Solutions: Delivers engineering and technology services for national security.
10+ YOERequires 10+ years of DevSecOps experience, active Top Secret/SCI with CI Polygraph, DoD IAT Level II certification, CI/CD, containerization, IaC, Linux, scripting, and AWS expertise.
GitLab CI/CD, Jenkins, Docker, Terraform, CloudFormation, Ansible, Python, Bash, Linux, RHEL, Oracle Linux, AWS, Amazon EC2, Amazon S3, IAM, Amazon RDS, Artifactory, SonarQube, Prisma Cloud, Azure, GCP
1d
Save
Mark Applied
Hide
Junior DevSecOps Engineer – AWS
Reston or Washington
HybridContract
BizTech Fusion
BizTech Fusion: An IT professional services and consulting firm delivering technology solutions to public- and private-sector clients.
3+ YOERequires 3+ years of DevOps/DevSecOps experience, AWS, CodePipeline, CodeBuild, CDK or CloudFormation, scripting, security integration, U.S. citizenship, clearance eligibility, and active AWS DevOps or Security certification.
AWS, AWS CodePipeline, AWS CodeBuild, AWS CDK, CloudFormation, SAST, DAST, SCA, Python, Bash, FedRAMP, NIST, Agile, Scrum
1d
Save
Mark Applied
Hide
DevSecOps Engineer
Herndon or California or Colorado or Hawaii or New Jersey or Washington, DC
$145k-$215k/yr OnsiteFull Time
Vantor
Vantor: Providing AI-powered spatial intelligence and high-resolution Earth observation.
14+ YOEU.S. citizenship, active TS/SCI with CI poly, bachelor's degree and 14 years technical support experience or equivalent, strong Linux and DevSecOps experience, and willingness to work in a SCIF.
OpenShift, Kubernetes, Ansible, Chef, ArgoCD, GitLab, SonarQube, Cucumber, JMeter, Cypress.io, Linux, REST APIs, ElasticSearch, Accumulo, Spark, Hive, Hadoop, RedHat, AWS, C2S, Infrastructure as Code, IaaS, PaaS, GIS, TCPED
1d
Save
Mark Applied
Hide
DevSecOps Engineer
Herndon, Virginia, United States
$145k-$215k/yr OnsiteFull Time
Maxar Intelligence
Maxar Intelligence: Providing satellite imagery and geospatial intelligence for global security.
14+ YOEBachelor’s degree and 14 years of technical support experience, or equivalent experience; active TS/SCI with CI poly clearance; strong Linux and DevSecOps experience; U.S. citizenship required.
OpenShift, Kubernetes, Ansible, Chef, ArgoCD, GitLab, SonarQube, Cucumber, JMeter, Cypress.io, Linux, REST APIs, ElasticSearch, Accumulo, Spark, Hive, Hadoop, Red Hat, AWS, C2S
1d
Save
Mark Applied
Hide
Mid-level DevSecOps Engineer
Arlington, Virginia, United States
$100k-$140k/yr OnsiteFull Time
Decision Technologies
Decision Technologies: Provides engineering and technical support for defense programs.
3+ YOERequires strong knowledge of containers, Terraform, Kubernetes, DoD cloud networks, firewalls, and security requirements; eligibility for a DoD Secret clearance. Python or SQL and DoD software experience preferred.
Terraform, Kubernetes, Python, SQL
1d
Save
Mark Applied
Hide
DevSecOps Engineer - Leesburg
Leesburg or Washington
$155k-$205k/yr HybridFull Time
Fortreum
Fortreum: Provides cybersecurity compliance and technical auditing services for regulated industries.
7+ YOERequires 7+ years in DevOps, platform engineering, or SRE; AWS and Terraform expertise; production Kubernetes experience; regulated compliance experience; scripting; U.S. citizenship; and ability to obtain Top Secret clearance.
AWS, Azure, GCP, Terraform, Kubernetes, EKS, Helm, ArgoCD, NIST 800-53, OSCAL, GitHub, JIRA, Splunk, Snyk, Python, Bash, Security+, AWS Certified Security, CYSA+, CISSP, LLM, MCP
2d
Save
Mark Applied
Hide
Sr. DevSecOps Engineer I
Washington, District of Columbia, United States
$170k-$220k/yr OnsiteFull Time
M9 Solutions
M9 Solutions: Provides IT modernization and technology services to federal agencies.
5+ YOERequires active TS/SCI clearance, BA/BS in an IT-related field or equivalent experience, DoD 8140 certification, and 5+ years of DevSecOps experience with enterprise CI/CD and security platforms.
.NET, CI/CD