Job Requirements
Fairfax, VA
Secret Polygraph Unspecified
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries
Job Description
DEVOPS ENGINEER PRINCIPAL
GDIT is looking for a Engineer - AWS (DevSecOps Champion) a senior technical role supporting DOJ Homeland Security Task Force (HSTF) / National Coordination Center (NCC). This role leads secure CI/CD and DevSecOps practices for AWS-based solutions, designing and governing pipelines and automation that embed security, compliance, and risk management into the delivery lifecycle for mission-critical systems.
Responsibilities
Basic Qualifications
Preferred Qualifications
OWN YOUR OPPORTUNITY
Explore a career in software development at GDIT and you'll find endless opportunities to grow alongside colleagues who share your dedication to advancing innovation.
GDIT is looking for a Engineer - AWS (DevSecOps Champion) a senior technical role supporting DOJ Homeland Security Task Force (HSTF) / National Coordination Center (NCC). This role leads secure CI/CD and DevSecOps practices for AWS-based solutions, designing and governing pipelines and automation that embed security, compliance, and risk management into the delivery lifecycle for mission-critical systems.
Responsibilities
- Define and enforce secure CI/CD and DevSecOps standards, patterns, and guardrails for AWS-hosted applications, in alignment with GDIT Cyber Security Policy, Cyber Security Handbook, and Cloud/Security standards.
- Design, build, and maintain CI/CD pipelines (e.g., AWS CodePipeline/CodeBuild, Jenkins, GitLab CI, GitHub Actions, Azure DevOps) with integrated security scanning, compliance checks, approvals, and testing.
- Lead infrastructure-as-code (IaC) implementations (CloudFormation, Terraform) with embedded security and configuration baselines, supporting secure provisioning of AWS environments.
- Automate secure environment provisioning, configuration, and deployments across development, test, and production AWS accounts, in line with cyber and IT risk management requirements.
- Implement monitoring, logging, and alerting (CloudWatch, CloudTrail, centralized logging) to support secure, observable, and auditable delivery pipelines.
- Integrate identity and access management, encryption, secrets management, vulnerability scanning, and compliance controls into CI/CD workflows as part of DevSecOps practices.
- Ensure CI/CD pipelines and AWS solutions comply with applicable contractual and regulatory requirements (e.g., NIST 800-53/171, CMMC, FedRAMP, ISO 27001) and internal cyber standards.
- Collaborate with application development, cloud platform, cyber security, IT risk, and operations teams to ensure architectures are "DevSecOps-ready" and align with secure development standards.
- Provide technical leadership, coaching, and documentation for project teams adopting DevSecOps and secure CI/CD practices; develop reusable secure pipeline templates and patterns.
- Support proposals, technical reviews, and risk assessments where secure CI/CD, cloud security, and DevSecOps capabilities are required, including input to labor category mapping and staffing.
Basic Qualifications
- Bachelor's degree in Computer Science, Information Systems, Engineering, Cyber Security, or related field; or equivalent experience.
- Typically 8+ years of relevant IT experience, with significant experience in DevOps/DevSecOps and CI/CD for production systems.
- Hands-on experience with AWS services (e.g., EC2, ECS/EKS, S3, IAM, VPC, CloudWatch/CloudTrail) in security-sensitive or regulated environments.
- Proven experience designing and operating CI/CD pipelines using one or more modern platforms (AWS CodePipeline/CodeBuild, Jenkins, GitLab CI, GitHub Actions, Azure DevOps).
- Strong experience with infrastructure-as-code (e.g. CloudFormation, Terraform) and secure configuration management and automation.
- Demonstrated experience promoting signed builds into an air-gapped, classified, or otherwise network-isolated target environment, including artifact transfer procedures and post-deployment verification.
- Experience with containers and orchestration (e.g. Docker, ECS, EKS, Kubernetes) including security aspects (image scanning, runtime security, least privilege).
- Demonstrated experience integrating security testing, vulnerability scanning, and compliance checks into CI/CD workflows (DevSecOps).
- Experience working under formal security and risk frameworks (e.g., NIST 800-53/171, CMMC, FedRAMP, ISO 27001, customer-specific cyber requirements).
- Strong communication and collaboration skills, with ability to work across cyber, risk, engineering, and program management teams.
Preferred Qualifications
- AWS certifications (e.g., AWS Certified DevOps Engineer - Professional, AWS Certified Security - Specialty, AWS Solutions Architect).
- Security/DevSecOps certifications.
- Experience supporting or implementing secure cloud architectures.
- Experience in enterprise DevSecOps or security transformation initiatives, or in a cloud/cyber center of excellence.
- Experience with multi-account AWS Organizations, landing zones, and centralized security/governance services.
OWN YOUR OPPORTUNITY
Explore a career in software development at GDIT and you'll find endless opportunities to grow alongside colleagues who share your dedication to advancing innovation.
group id: 90979310