Job Requirements
Fort Meade, MD Chambersburg, PA
Top Secret Polygraph not specified
Senior Level Career (10+ yrs experience)
$140,000 - $165,000
Job Description
DevSecOps Engineer
Fort Meade, MD OR Chambersburg, PA (Onsite 4 days a week - REQUIRED)
The DevSecOps Engineer provides security engineering expertise to Mission Partners, system owners, ISSMs/ISSOs, architects, and software development teams throughout the SDLC. The position integrates cybersecurity requirements and controls directly into Agile development and CI/CD processes, enabling development teams to identify and address security issues earlier in the lifecycle and securely move applications and capabilities from concept through production.
Essential Duties and Responsibilities:
• Embed cybersecurity engineering into Agile software development and modernization activities.
• Integrate security requirements and controls throughout the SDLC and CI/CD pipelines.
• Apply DevSecOps and shift-left security principles to identify and remediate vulnerabilities earlier in development.
• Implement and support automated security testing within CI/CD workflows.
• Participate with development teams in requirements discussions, design activities, sprint planning, and other lifecycle events.
• Translate RMF, NIST SP 800-53, DoD cybersecurity policy, STIGs, SRGs, and related security requirements into actionable development and engineering tasks.
• Collaborate with developers, architects, system owners, ISSMs, and ISSOs to develop achievable technical security controls before formal assessment.
• Provide threat-informed security engineering guidance for legacy, modernized, and cloud-native applications.
• Support secure development involving APIs, microservices, containerized workloads, and other modern application architectures as applicable.
• Help development teams remediate security vulnerabilities while preserving mission functionality and delivery objectives.
• Provide engineering recommendations for technical controls such as authentication, encryption, network segmentation, and application security.
• Communicate security findings, technical risks, recommended remediation, and implementation approaches to technical and Government stakeholders.
• Manage security-engineering activities across multiple concurrent projects and development sprints.
Required Skills, Qualifications and Experience:
• Bachelor’s degree and 10+ years of related experience.
• DoD 8140 Work Role 652 – Security Architect Certification requirement (must have at least one of the following): Security X/CASP+CE, CCSP, Cloud+, CISSP, CSSLP, CISM, CISSP-ISSAP, CISSP-ISSIP, CSSLP, and GSEC.
• Must have and maintain a current DoD Top Secret clearance.
• Must reside within a commutable distance of Fort Meade, MD or Chambersburg, PA in order to work a hybrid onsite schedule (4 days onsite weekly).
• Demonstrated experience integrating cybersecurity into Agile SDLC environments.
• Demonstrated hands-on experience with CI/CD pipelines.
• Practical experience implementing DevSecOps and shift-left security practices.
• Experience using automated security testing tools within software development processes.
• Knowledge of RMF, NIST SP 800-37, and NIST SP 800-53.
• Knowledge and practical application of DoD STIGs and SRGs.
• Ability to convert security/compliance requirements into specific technical development tasks and controls.
• Understanding of modern application architectures and cloud-native development.
• Ability to collaborate effectively with cybersecurity, engineering, architecture, and software-development teams.
• Strong written and verbal communication skills.
• Ability to manage multiple development efforts and sprints in a high-tempo environment.
Fort Meade, MD OR Chambersburg, PA (Onsite 4 days a week - REQUIRED)
The DevSecOps Engineer provides security engineering expertise to Mission Partners, system owners, ISSMs/ISSOs, architects, and software development teams throughout the SDLC. The position integrates cybersecurity requirements and controls directly into Agile development and CI/CD processes, enabling development teams to identify and address security issues earlier in the lifecycle and securely move applications and capabilities from concept through production.
Essential Duties and Responsibilities:
• Embed cybersecurity engineering into Agile software development and modernization activities.
• Integrate security requirements and controls throughout the SDLC and CI/CD pipelines.
• Apply DevSecOps and shift-left security principles to identify and remediate vulnerabilities earlier in development.
• Implement and support automated security testing within CI/CD workflows.
• Participate with development teams in requirements discussions, design activities, sprint planning, and other lifecycle events.
• Translate RMF, NIST SP 800-53, DoD cybersecurity policy, STIGs, SRGs, and related security requirements into actionable development and engineering tasks.
• Collaborate with developers, architects, system owners, ISSMs, and ISSOs to develop achievable technical security controls before formal assessment.
• Provide threat-informed security engineering guidance for legacy, modernized, and cloud-native applications.
• Support secure development involving APIs, microservices, containerized workloads, and other modern application architectures as applicable.
• Help development teams remediate security vulnerabilities while preserving mission functionality and delivery objectives.
• Provide engineering recommendations for technical controls such as authentication, encryption, network segmentation, and application security.
• Communicate security findings, technical risks, recommended remediation, and implementation approaches to technical and Government stakeholders.
• Manage security-engineering activities across multiple concurrent projects and development sprints.
Required Skills, Qualifications and Experience:
• Bachelor’s degree and 10+ years of related experience.
• DoD 8140 Work Role 652 – Security Architect Certification requirement (must have at least one of the following): Security X/CASP+CE, CCSP, Cloud+, CISSP, CSSLP, CISM, CISSP-ISSAP, CISSP-ISSIP, CSSLP, and GSEC.
• Must have and maintain a current DoD Top Secret clearance.
• Must reside within a commutable distance of Fort Meade, MD or Chambersburg, PA in order to work a hybrid onsite schedule (4 days onsite weekly).
• Demonstrated experience integrating cybersecurity into Agile SDLC environments.
• Demonstrated hands-on experience with CI/CD pipelines.
• Practical experience implementing DevSecOps and shift-left security practices.
• Experience using automated security testing tools within software development processes.
• Knowledge of RMF, NIST SP 800-37, and NIST SP 800-53.
• Knowledge and practical application of DoD STIGs and SRGs.
• Ability to convert security/compliance requirements into specific technical development tasks and controls.
• Understanding of modern application architectures and cloud-native development.
• Ability to collaborate effectively with cybersecurity, engineering, architecture, and software-development teams.
• Strong written and verbal communication skills.
• Ability to manage multiple development efforts and sprints in a high-tempo environment.
group id: RTL73977