Job Requirements
Crystal City, VA
Secret Polygraph not specified
Mid Level Career (5+ yrs experience)
Salary not specified
Join Premium to unlock estimated salaries
Job Description
JOB DESCRIPTION
DevSecOps Engineer (Mid-Level)
Position Overview
We are seeking a Mid-Level DevSecOps Engineer with 3 to 5 years of experience to integrate automated
security practices directly into our software development lifecycle (SDLC). In this role, you will act as a
bridge between development, security, and operations teams to ensure our cloud infrastructure and
applications are secure by design. Your primary focus will be implementing "shift-left" security,
automating security testing, and maintaining secure, resilient CI/CD pipelines.
Key Responsibilities
• Pipeline Automation: Embed and maintain automated security gates (SAST, DAST, SCA) within our
existing CI/CD pipelines.
• Vulnerability Triage: Analyze vulnerability scan results, eliminate false positives, and collaborate
with developers to remediate real risks.
• Infrastructure as Code: Write and secure cloud infrastructure using IaC frameworks while enforcing
policy-as-code rules.
• Secret Management: Implement and manage secure secret, token, and credential storage systems
across all deployment environments.
• Compliance & Monitoring: Monitor cloud infrastructure for compliance drift, track audit logs, and
configure security alerts.
• Threat Modeling: Participate in architectural security reviews and assist development teams with
basic threat modeling.
Required Qualifications
• Experience: 3–5 years of professional experience in DevOps, Cloud Engineering, or AppSec roles.
• Cloud Infrastructure: Solid hands-on experience managing infrastructure with at least one major
cloud provider (AWS, Azure, or GCP).
• Containers & Orchestration: Proven ability to build, secure, and debug Docker containers and
Kubernetes workloads.
• IaC Tools: Practical experience writing reusable, secure code with tools like Terraform, OpenTofu, or
CloudFormation.
• Security Tooling: Active experience using vulnerability scanners such as Snyk, SonarQube, Aqua
Security, Checkmarx, or Trivy.
,• Automation & Scripting: Competency in writing automation scripts using Python, Bash, or Go.
• CI/CD Platforms: Familiarity with configuring automation pipelines using GitHub Actions, GitLab CI,
or Jenkins.
Preferred Qualifications
• Certifications: Holder of (or working toward) certifications like Certified Kubernetes Security
Specialist (CKS) or AWS Certified Security - Specialty.
• Network Security: Basic understanding of VPC architecture, IAM roles, firewalls, and WAF
configurations.
DevSecOps Engineer (Mid-Level)
Position Overview
We are seeking a Mid-Level DevSecOps Engineer with 3 to 5 years of experience to integrate automated
security practices directly into our software development lifecycle (SDLC). In this role, you will act as a
bridge between development, security, and operations teams to ensure our cloud infrastructure and
applications are secure by design. Your primary focus will be implementing "shift-left" security,
automating security testing, and maintaining secure, resilient CI/CD pipelines.
Key Responsibilities
• Pipeline Automation: Embed and maintain automated security gates (SAST, DAST, SCA) within our
existing CI/CD pipelines.
• Vulnerability Triage: Analyze vulnerability scan results, eliminate false positives, and collaborate
with developers to remediate real risks.
• Infrastructure as Code: Write and secure cloud infrastructure using IaC frameworks while enforcing
policy-as-code rules.
• Secret Management: Implement and manage secure secret, token, and credential storage systems
across all deployment environments.
• Compliance & Monitoring: Monitor cloud infrastructure for compliance drift, track audit logs, and
configure security alerts.
• Threat Modeling: Participate in architectural security reviews and assist development teams with
basic threat modeling.
Required Qualifications
• Experience: 3–5 years of professional experience in DevOps, Cloud Engineering, or AppSec roles.
• Cloud Infrastructure: Solid hands-on experience managing infrastructure with at least one major
cloud provider (AWS, Azure, or GCP).
• Containers & Orchestration: Proven ability to build, secure, and debug Docker containers and
Kubernetes workloads.
• IaC Tools: Practical experience writing reusable, secure code with tools like Terraform, OpenTofu, or
CloudFormation.
• Security Tooling: Active experience using vulnerability scanners such as Snyk, SonarQube, Aqua
Security, Checkmarx, or Trivy.
,• Automation & Scripting: Competency in writing automation scripts using Python, Bash, or Go.
• CI/CD Platforms: Familiarity with configuring automation pipelines using GitHub Actions, GitLab CI,
or Jenkins.
Preferred Qualifications
• Certifications: Holder of (or working toward) certifications like Certified Kubernetes Security
Specialist (CKS) or AWS Certified Security - Specialty.
• Network Security: Basic understanding of VPC architecture, IAM roles, firewalls, and WAF
configurations.
group id: 91098134