Devsecops Engineer

tier one

๐Ÿ“ Remote๐ŸŒ Remote๐Ÿ• 2d ago๐Ÿ”— himalayas

Job Description

### Overview * [Tier One Technologies](https://himalayas.app/companies/tier-one-technologies) is seeking a DevSecOps Engineer to strengthen software development lifecycle by embedding security practices into every stage of delivery for our US Government client. * This remote contract-to-hire position will be originated in Falls Church, VA. * SELECTED CANDIDATES WITHOUT REQUIRED CLEARANCE WILL BE SUBJECT TO A FEDERAL GOVERNMENT BACKGROUND INVESTIGATION TO RECEIVE IT. ### Responsibilities * Working across development, operations, and security teams to ensure applications and infrastructure are secure, compliant, and resilient, while maintaining speed and efficiency in deployment. * Lead the evolution of the software delivery lifecycle by embedding security into every stage of the CI/CD pipeline. * Integrate existing automation frameworks with AI-based solutions to improve coverage, reliability, and efficiency. * Ensure that all AI scripts and programs are fully executable on postal-issued laptops within approved security and environment constraints. * Perform Static and Dynamic Application Security Testing (SAST/DAST), integrated into pipelines. * Collaborate with software developers and IT staff to oversee code releases and deployments. * Design and implement scalable cloud architecture using platforms such as AWS, Google Cloud Platform, or Azure. * Manage containerization technologies such as Docker and orchestration tools like Kubernetes. * Utilize Infrastructure as Code (IaC) tools like Ansible for automated provisioning of infrastructure. * Ensure system reliability through monitoring, logging, and alerting using tools like Jenkins and Git. * Develop RESTful APIs and microservices to facilitate communication between applications. * Maintain databases including MySQL, PostgreSQL, Oracle, and Microsoft SQL Server. * Participate in Agile development processes to improve software delivery cycles. * Troubleshoot issues across the application stack from front-end to back-end services. * Manage and secure cloud environments (AWS, Azure, GCP) and containerized workloads (Docker, Kubernetes). * Implement Infrastructure as Code (IaC) with secure configurations using Terraform, Ansible, or CloudFormation. * Monitor and respond to security incidents, leveraging SIEM tools and observability platforms. * Ensure compliance with industry standards and regulations (ISO 27001, NIST, GDPR, HIPAA, PCI DSS). * Provide training and guidance to teams on DevSecOps best practices. ### Qualifications * Bachelorโ€™s degree in Computer Science, Cybersecurity, or related field. * 13+ years of overall IT experience. * 10+ years of experience managing software releases across DEV, SIT, CAT/UAT, and PROD environments, supporting major and minor releases, patches, upgrades, and production deployments. * 10+ years of experience providing release support, code promotion, deployment monitoring, and production data fixes to ensure application stability and successful software delivery. * 5+ years of experience designing, implementing, and maintaining secure CI/CD pipelines with integrated automated security testing and compliance controls. * 3+ years of experience leveraging GitHub Copilot and other AI-enabled tools to automate manual processes, improve developer productivity, and streamline software delivery workflows. * 3+ years of experience implementing and enforcing Secure Coding Standards throughout the software development lifecycle. * Strong knowledge of integrating application security testing tools, including SAST, DAST, and Software Composition Analysis (SCA), into CI/CD pipelines and development workflows. * Proven ability to collaborate with development teams to promote secure coding practices and remediate security vulnerabilities early in the SDLC. * Hands-on experience with Jenkins, GitLab CI/CD, Azure DevOps, and/or CircleCI to automate builds, deployments, testing, and embedded security validation. * Deep knowledge of cloud security services and best practices across AWS, Microsoft Azure, and Google Cloud Platform (GCP). * Hands-on experience securing containerized applications and orchestration platforms, including Docker and Kubernetes. * Proficiency in Python and Java for developing automation scripts, security tooling, and CI/CD pipeline integrations. * Familiarity with Terraform, Ansible, or CloudFormation, with emphasis on secure configurations. * Excellent communication skills. * Be able to pass a drug screening, criminal history, and credit checks. * Must be a US Citizen or have permanent residence status (Green Card). * Must be able to obtain a Position of Public Trust Clearance. * Must have lived in the United States for the past 5 years. * Cannot have more than 6 months travel outside the United States within the last five years. Military Service excluded. (Exception does not include military family members.) Originally posted on [Himalayas](https://himalayas.app)
Devsecops Engineer at tier one | MergeJobs | MergeJobs