user avatar

DevSecOps Engineer - Public Trust

Zachary Piper Solutions, LLC

Posted today

Job Requirements

Gaithersburg, MD
Public Trust Polygraph Unspecified
Career Level not specified
$140,000 - $150,000

Job Description

Zachary Piper Solutions is seeking a DevSecOps Security Engineer to support a government customer focused on building and operating automated security controls across modern CI/CD and containerized environments. This is a hybrid position requiring 3 days onsite and 2 days remote for candidates within commuting distance of Gaithersburg, MD; Eagan, MN; or Egg Harbor Township, NJ.

Responsibilities for the DevSecOps Security Engineer Include:

  • Implement automated security controls across CI/CD pipelines, including SAST, DAST, software composition analysis, container scanning, and IaC scanning.
  • Manage security gates, artifact signing, provenance verification, and SBOMs (CycloneDX/SPDX).
  • Identify and remediate container vulnerabilities while developing hardened/minimal base images.
  • Implement Kubernetes security controls including RBAC, network policies, pod security, admission controls, and security contexts.
  • Support secrets management, mTLS, service mesh policies, and Linux/container hardening.
  • Develop policy-as-code and infrastructure guardrails using OPA/Rego, Kyverno, or similar technologies.
  • Partner with platform and application teams on vulnerability remediation, incident response, and root cause analysis.
  • Produce automated security evidence supporting authorization and continuous monitoring requirements.

Qualifications for the DevSecOps Security Engineer Include:

  • 4+ years of relevant DevSecOps, cybersecurity, cloud security, or security engineering experience.
  • Bachelor's degree in Cybersecurity, Computer Science, IT, or related field; additional relevant experience may be considered.
  • Hands-on experience integrating SAST, DAST, SCA, and container scanning into CI/CD pipelines.
  • Experience securing Kubernetes and containerized environments, including RBAC, network policies, and hardened images.
  • Experience with vulnerability management tools such as Nessus, Trivy, Grype, or Qualys and CVE remediation.
  • Experience with GitLab CI, GitHub Actions, Jenkins, or similar CI/CD platforms.
  • Experience with secrets management and automation using Python, Bash, or Go.
  • Working knowledge of NIST 800-53 and AWS or Azure cloud security.
  • Ability to obtain and maintain a Public Trust and meet government background investigation requirements.

Compensation for the DevSecOps Security Engineer Includes:

  • Salary Range: $140,000 - $150,000 depending on experience.
  • Comprehensive Benefits: Medical, Dental, Vision, 401(k), PTO, and Paid Holidays.

Keywords:

DevSecOps Security Engineer, DevSecOps Engineer, Senior DevSecOps Engineer, Security Engineer, Cloud Security Engineer, Application Security Engineer, Platform Security Engineer, Kubernetes Security Engineer, Container Security Engineer, Cybersecurity Engineer, DevOps Security, Cloud Security, Application Security, Platform Security, Kubernetes Security, Container Security, CI/CD Security, Pipeline Security, Security Automation, Security Engineering, Secure CI/CD, Secure SDLC, SSDLC, DevSecOps Pipeline, SAST, DAST, SCA, Software Composition Analysis, Infrastructure as Code, IaC, IaC Security, Container Scanning, Vulnerability Scanning, Vulnerability Management, Vulnerability Remediation, CVE, CVE Remediation, SBOM, Software Bill of Materials, CycloneDX, SPDX, Software Supply Chain Security, Supply Chain Security, Artifact Signing, Code Signing, Sigstore, Cosign, SLSA, Trivy, Grype, Nessus, Qualys, Kubernetes, K8s, OpenShift, Docker, Containers, Pod Security, Kubernetes RBAC, Network Policies, Admission Control, OPA, Open Policy Agent, Rego, Kyverno, Policy as Code, HashiCorp Vault, Secrets Management, mTLS, Mutual TLS, Service Mesh, Istio, Linkerd, Linux Hardening, Container Hardening, GitLab, GitLab CI, GitHub Actions, Jenkins, GitOps, ArgoCD, Flux, Terraform, CloudFormation, Python, Bash, Go, AWS, Azure, AWS Security, Azure Security, Cloud Infrastructure, NIST 800-53, NIST, Continuous Monitoring, Security Controls, Security Compliance, FIPS 140-3, Security+, CySA+, CKA, CKS, Public Trust, FAA, Federal Government, Government IT
group id: 10430981
job ad image
Find Zachary Piper Solutions, LLC on Social Media
Recruiters
user avatar
About Us
Zachary Piper Solutions is a National Security focused technology services and consulting firm with a top-secret facility clearance. We support mission-critical initiatives on behalf of the Intelligence Community, Department of Defense, Department of Homeland Security, Department of Justice, Department of State, and a variety of Civilian Agencies. ZPS is dedicated to help protect government networks against cyber threats and to maximize the wide-spectrum of intelligence and security-related technologies. Our dedicated support and proven experience drive results in support of our client’s mission objectives.
job ad2 image

Zachary Piper Solutions, LLC Jobs


Clearance Level
Public Trust