Skip to content

Jobgether

DevSecOps Engineer

Compensation
$161K–$176K / yr
From job posting
Location
US
Arrangement
Remote
Employment type
Full-time
Posted
2 October 2026 (today)

Checked todayApplications go to the employer, never to RoleSprint

About this role

Accountabilities: • Embed Guardrails-as-Code and automated security controls across CI/CD pipelines, including SAST, DAST, SBOM generation, vulnerability scanning, and policy gates.

• Manage secrets, cryptographic code signing, artifact integrity, hardened container images, and automated configuration drift detection.

• Triage, track, and remediate security vulnerabilities within defined deadlines, ensuring critical and high-risk findings are addressed before production.

• Automate security evidence collection to support Continuous Assessment and Authorization (ATO), NIST RMF activities, and VA/FedRAMP compliance.

• Implement Zero Trust principles, identity and access controls, logging, encryption, network segmentation, and cloud security measures across AWS, Azure, and VA Enterprise Cloud environments.

• Mentor development teams on secure coding and security design practices, including the review and validation of AI-generated code and test scripts.

• Support security incident response through component isolation, forensic activities, rapid reporting, and after-hours escalation rotations.

• Contribute to DevSecOps strategies for proposals, security performance metrics, technical interviews, reusable pipeline security templates, cybersecurity communities, and corporate quality initiatives.

Requirements:

• 7+ years of experience in IT security or DevSecOps, including at least 4 years integrating continuous security controls into CI/CD pipelines within federal Agile/SAFe environments.

• 3+ years of hands-on experience with pipeline security automation, including SAST/DAST, container scanning, secrets management, and SBOM generation using standards such as SPDX or CycloneDX.

• Strong experience automating infrastructure hardening and configuration compliance with tools such as Ansible and Terraform against DISA STIG and CIS benchmarks.

• Proven knowledge of NIST Risk Management Framework (RMF), Authority to Operate (ATO) processes, POA&Ms, and automated continuous control evidence collection.

• Extensive experience securing AWS, Azure, and VA Enterprise Cloud environments, including IAM, encryption, network segmentation, and related cloud security controls.

• Strong vulnerability management experience, with the ability to partner directly with development teams to investigate, prioritize, and resolve findings.

• Experience with security monitoring and logging platforms such as Splunk, as well as identity and access technologies including HashiCorp Vault, mutual TLS, ICAM, and PIV.

• Ability to support secure development across Java, .NET, Python, and legacy MUMPS environments, with experience embedding automated Section 508 accessibility testing into pipelines.

• Experience with VA supply chain systems, HL7/FHIR healthcare APIs, one-hour incident response requirements, or AI-generated code validation is highly preferred.

• Bachelor's degree in Cybersecurity, Computer Science, Computer Engineering, Information Systems, or a related field; a master's degree is preferred.

• Required certification: ISC2 CISSP or Security+. Additional preferred certifications include AWS Solutions Architect Associate, AWS Developer Associate, Azure Solutions Architect, Azure Developer Associate, Red Hat Certified Specialist in Ansible Automation, or Red Hat Certified Architect.

• Ability to obtain a Tier 2 / Moderate Risk Background Investigation and VA PIV credential.

Benefits:

• Suggested salary range of $161,000–$176,000, with actual compensation based on skills, qualifications, experience, and location.

• Certain positions may be eligible for additional compensation, including bonuses.

• Comprehensive healthcare benefits above industry standards.

• Remote working options for eligible employees.

• Paid time off and paid holidays.

• 401(k) matching.

• Healthcare Savings Account and Flexible Spending Account options.

• Paid life insurance and short- and long-term disability coverage.

• Training, professional development, and certification opportunities.

• Tuition reimbursement and Employee Assistance Program.

• Military leave and additional employee benefits.

• Remote position within the continental United States, with the option to work from Rockville, Maryland.

• Up to 10% travel.

• Opportunities to work on mission-driven federal technology initiatives while developing long-term career and technical expertise.

How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

Work location

  • US

Related jobs

Ready to make a decision?

This role is either worth your time or it isn’t.

Analyze the posting against your experience, see the gaps clearly, and build the right materials only if the opportunity makes sense.

Nothing is submitted automatically. You choose what happens next.

About this listing

Published on Lever under the board identifier Jobgether, which is the name the employer’s own job board carries. RoleSprint has not verified the company’s registered or trading name, so it is shown exactly as published rather than tidied up.

RoleSprint is not the employer and not a recruiter. Applications are made on the employer’s own site and never reach us; what RoleSprint does is help you decide whether a role is worth your time and prepare for it if it is.

Published 2 October 2026, last checked today. A posting stops being advertised here 90 days after the employer published it, and one the employer takes down is marked closed rather than quietly removed.

Browse all current openings

No credit card requiredStart free