user avatar

Cloud DevSecOps Engineer

Stratias LLC

Posted yesterday

Job Requirements

Remote Scott AFB, IL
Secret Polygraph not specified
Early Career (2+ yrs experience)
$95,000 - $105,000

Job Description

About Stratias
Stratias is a mission-focused digital transformation firm that helps the Department of Defense modernize critical systems at speed and scale. We specialize in program modernization through application rationalization, code refactoring, cloud migration, data pipelining, and SaaS integration. Our teams combine Agile delivery, DevSecOps practices, and deep mission expertise to drive results for the Air Force and across the defense enterprise.

Why Join Us
At Stratias, you won’t be a small cog in a massive machine—you’ll be a core part of a fast-growing team that’s helping shape the future of defense IT. We hire subject-matter experts who understand both the technology and the mission. You’ll get the freedom to innovate, the support of a collaborative team, and benefits designed for real work-life balance.

About this Role
The Cloud DevSecOps Engineer will support the U.S. Transportation Command's Joint Transportation Management System (JTMS) Program Management Office, a major DoD ERP modernization effort fielding and sustaining commercial logistics and transportation software across the Joint Deployment and Distribution Enterprise. The ideal candidate brings 5+ years of experience building and securing CI/CD pipelines with hands-on AWS and Kubernetes expertise. This role embeds security scanning, container orchestration, and DevSecOps best practices directly into JTMS's development and deployment lifecycle. Candidates must possess an active Secret Clearance.

Responsibilities:

CI/CD Pipeline Development & Management:
Design, build, and maintain automated CI/CD pipelines using GitLab CI/CD
Implement automated build, test, deployment, and rollback processes with quality gates and approval workflows
Optimize pipeline performance and reliability

Security Integration & Automation:
Embed security scanning tools into CI/CD pipelines (SAST, DAST, SCA, container scanning)
Implement and maintain security tools (SonarQube, Fortify, OWASP)
Monitor and remediate vulnerabilities in code, dependencies, and infrastructure

Container & Orchestration Management:
Build and secure container images following best practices
Develop and maintain Kubernetes manifests, operators, and security policies (network policies, RBAC)
Implement security monitoring, logging, and alerting solutions (Splunk, ELK Stack, Prometheus/Grafana)
Develop automated incident response workflows and security/pipeline dashboards

Collaboration & Enablement:
Partner with development teams on secure coding practices and vulnerability remediation
Provide DevSecOps training and guidance on tools, practices, and security requirements
Collaborate with Security, Operations, and Architecture teams on security initiatives
Participate in security-focused code reviews

Qualifications

Required:

Education and Clearance requirements:
5 years of experience in related field
Bachelor’s Degree or equivalent experience
Secret Clearance
Security+ Certification

Experience & Core Skills:
3-5 years in software development, DevOps, or security engineering
2+ years implementing and managing production CI/CD pipelines
Understanding of SDLC and agile methodologies
Proficiency in programming/scripting languages (Python, Go, Java, JavaScript, Bash)
Experience with Git version control and branching strategies

Technical Skills – DevOps:
Hands-on experience with GitLab CI/CD
Proficiency with Infrastructure as Code tools (Terraform, Ansible, CloudFormation)
Experience with container technologies (Docker, Kubernetes, OpenShift)
Familiarity with artifact repositories (Artifactory, Nexus, Docker Registry)

Technical Skills – Security:
Experience with application security testing tools (SAST, DAST, SCA, IAST)
Knowledge of container/Kubernetes security best practices and frameworks (OWASP, NIST)

Technical Skills - Cloud & Infrastructure:
Expert knowledge of AWS platforms and security services (EC2, CloudWatch, CloudTrail, S3, IAM, EKS, WAF & Shield, ECS)
Understanding of cloud-native services, serverless architecture, and networking (VPC, subnets, firewalls, load balancers, service mesh)
Knowledge of identity and access management (IAM, RBAC, SSO, SAML)

Soft Skills:
Strong problem-solving and communication abilities
Collaborative across development, security, and operations teams
Self-motivated with ability to manage multiple priorities
Security-first mindset with pragmatic risk management approach

Desired:

Security certifications (CISSP, CEH, GIAC, CSSLP)
AWS Cloud certifications
DevOps/Container certifications (CKA, CKAD, CKS, Docker Certified Associate)
group id: 91170810

Similar Jobs


Job Category
IT - Software
Clearance Level
Secret
Employer
Stratias LLC