Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

DevSecOps Engineer

Koniag

Koniag Data Solutions, LLC, a Koniag Government Services company , is seeking a DevSecOps Engineer to support KDS and our government customer in Washington, DC. This position requires the candidate to be able to obtain a Public Trust.

We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.

Koniag Data Solutions, a Koniag Government Services company, is seeking an experienced DevSecOps Engineer to support the implementation, operation, and continuous improvement of DevSecOps practices, pipelines, and tools in support of the U.S. Small Business Administration (SBA). The ideal candidate is a mid to senior-level engineering professional with solid hands-on experience in DevSecOps methodologies, CI/CD pipeline development, security automation, and cloud technologies, and a demonstrated ability to integrate security practices into software development and operations workflows within a federal government environment. This individual will play a key role in building, maintaining, and improving SBA's DevSecOps capabilities, contributing to the secure and efficient delivery of software and infrastructure solutions that support SBA's mission and operational objectives.

The DevSecOps Engineer will support the design, implementation, operation, and continuous improvement of DevSecOps pipelines, tools, and practices at the SBA, working closely with development teams, security teams, operations staff, and program managers to integrate security throughout the software development lifecycle and enable the reliable, secure delivery of software and infrastructure solutions in support of SBA's mission.


Principal responsibilities will include but are not limited to:
  • Design, build, implement, and maintain CI/CD pipelines and DevSecOps toolchain components for SBA, ensuring pipelines are automated, secure, and aligned with SBA's software delivery requirements and security policies.
  • Integrate security tools and automation into CI/CD pipelines including static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), container security scanning, and infrastructure as code (IaC) security scanning to support the continuous identification and remediation of security vulnerabilities throughout the SDLC.
  • Implement and maintain infrastructure as code (IaC) practices and tools to support automated, repeatable, and auditable provisioning and management of SBA's IT infrastructure and cloud environments.
  • Collaborate with SBA's development, security, and operations teams to implement and enforce DevSecOps standards, coding best practices, security requirements, and quality gates within CI/CD pipelines.
  • Support the containerization and orchestration of SBA applications, ensuring container images are properly secured, scanned, and managed in accordance with SBA security requirements and federal guidelines.
  • Monitor and analyze the performance, reliability, and security of CI/CD pipelines and DevSecOps toolchain components, identifying and implementing improvements to enhance pipeline efficiency and overall effectiveness.
  • Support the planning and execution of cloud migration and modernization initiatives, applying DevSecOps principles and practices to support the secure migration of SBA workloads to cloud environments.
  • Develop and maintain DevSecOps documentation including pipeline configurations, technical runbooks, architecture documentation, and standard operating procedures to support SBA's DevSecOps program.
  • Collaborate with SBA's ISSO and security teams to ensure DevSecOps pipelines and practices support the maintenance of system Authorization to Operate (ATO) requirements, including supporting the automation of security control testing and evidence collection activities.
  • Participate in code reviews, architecture reviews, and security reviews for pipeline components and infrastructure as code artifacts, ensuring they meet SBA's quality and security standards.
  • Support the implementation and management of source code management practices, repository security configurations, and branching strategies to ensure the integrity and security of SBA's software development environment.
  • Assist in the evaluation and implementation of new DevSecOps tools, technologies, and practices to enhance SBA's software delivery capabilities and security posture.
  • Provide technical support and guidance to development and operations teams on DevSecOps tools, practices, and security requirements, helping to build organizational capability and support for DevSecOps principles.
  • Participate in incident response activities related to CI/CD pipeline issues, security events within the DevSecOps environment, and application deployment failures, supporting timely identification and resolution of issues.
  • Stay current on DevSecOps technology developments, federal policy guidance, and industry best practices, applying this knowledge to continuously improve SBA's DevSecOps capabilities and practices.
Education and Experience:

Required:
  • Bachelor's degree in Computer Science, Software Engineering, Information Technology, Cybersecurity, or a related field from an accredited college or university, OR equivalent combination of education and relevant work experience.
  • 4-6 years of progressive experience in software engineering, systems engineering, or DevOps/DevSecOps, with demonstrated hands-on experience designing, implementing, and managing CI/CD pipelines and DevSecOps practices in a federal government or enterprise environment.
  • Demonstrated hands-on experience with CI/CD tools and platforms such as Jenkins, GitLab CI/CD, GitHub Actions, or similar, and container technologies such as Docker and Kubernetes.
  • Demonstrated experience integrating security tools and automation into CI/CD pipelines including SAST, DAST, SCA, and container security scanning solutions.
  • One or more of the following certifications: CompTIA Security+, Certified Kubernetes Administrator (CKA), AWS Certified Developer, Microsoft Certified: Azure Developer Associate, or equivalent DevSecOps or cloud engineering certification.
Desired:
  • Bachelor's or Master's degree in Computer Science, Software Engineering, Information Technology, or a related field.
  • Prior experience supporting DevSecOps implementation activities at a federal civilian agency, preferably the SBA or a similar organization.
  • Certified Kubernetes Administrator (CKA), AWS Certified DevOps Engineer, Microsoft Certified: DevOps Engineer Expert, or other relevant advanced DevSecOps or cloud engineering certifications.
Required Skills and Competencies:
  • Solid knowledge of DevSecOps principles, methodologies, and best practices and their application to the design, implementation, and operation of secure, automated software delivery pipelines in a federal government or enterprise environment.
  • Demonstrated hands-on experience with CI/CD tools and platforms including Jenkins, GitLab CI/CD, GitHub Actions, CircleCI, or similar, and the ability to design, build, and maintain CI/CD pipeline configurations.
  • Solid experience with containerization and container orchestration technologies including Docker and Kubernetes, including experience with container security practices and image scanning in an operational environment.
  • Experience with infrastructure as code (IaC) tools and practices including Terraform, Ansible, AWS CloudFormation, or similar, and their application to automated infrastructure provisioning and management.
  • Experience integrating security automation into CI/CD pipelines including SAST tools such as SonarQube or Checkmarx, DAST tools such as OWASP ZAP or Burp Suite, SCA tools such as Black Duck or Snyk, and container security scanning tools such as Twistlock, Aqua Security, or Anchore.
  • Solid experience with cloud platforms and services including AWS, Microsoft Azure, or Google Cloud Platform, and the application of cloud-native DevSecOps practices and tools within federal environments.
  • Proficient experience with source code management and collaboration platforms including Git, GitHub, GitLab, or Bitbucket, including familiarity with branching strategies, code review processes, and repository security practices.
  • Foundational understanding of federal cybersecurity frameworks, requirements, and guidance including NIST SP 800-53, FISMA, and FedRAMP, and their relevance to DevSecOps practices and pipeline security in a federal environment.
  • Experience with monitoring, logging, and observability tools and platforms such as ELK Stack, Prometheus, Grafana, Splunk, or similar, and their integration into DevSecOps pipelines and operations.
  • Solid experience with scripting and programming languages including Python, Bash, PowerShell, or similar, and their application to pipeline automation, toolchain integration, and infrastructure management tasks.
  • Effective written and oral communication skills in English, with the ability to clearly communicate DevSecOps concepts, pipeline configurations, and technical findings to both technical and non-technical stakeholders.
  • Ability to work both independently and collaboratively in a team environment, demonstrating flexibility and responsiveness to changing priorities and requirements in a fast-paced federal IT environment.
  • Ability to obtain and maintain a Public Trust clearance as required by the SBA.
Desired Skills and Competencies:
  • Prior experience supporting DevSecOps implementation and operations at the SBA or a similar federal civilian agency.
  • Familiarity with SBA's IT environment, development platforms, and mission areas, including an understanding of the challenges and opportunities associated with implementing DevSecOps within the SBA environment.
  • Experience with artifact management and software supply chain security tools and practices including JFrog Artifactory, Nexus Repository, or similar, and their integration into secure software delivery pipelines.
  • Knowledge of service mesh technologies such as Istio or Linkerd and their application to securing microservices architectures within a DevSecOps context.
  • Familiarity with GitOps practices and tools such as ArgoCD or Flux and their application to automated, auditable infrastructure and application deployments.
  • Knowledge of the NIST Secure Software Development Framework (SSDF) and its relevance to DevSecOps implementation in a federal government environment.
  • Experience supporting ATO processes and continuous monitoring programs, including contributing to the automation of security control testing and evidence collection within CI/CD pipelines.
  • Familiarity with software bill of materials (SBOM) concepts and tools and their relevance to software supply chain security and federal compliance requirements.
  • Certified Kubernetes Administrator (CKA), Certified Kubernetes Security Specialist (CKS), AWS Certified DevOps Engineer, Microsoft Certified: DevOps Engineer Expert, or other relevant advanced DevSecOps or cloud certifications.
  • Experience with Red Hat OpenShift and its application to container orchestration and DevSecOps practices in federal IT environments.
  • Basic familiarity with chaos engineering concepts and tools and their application to improving the resilience and reliability of DevSecOps pipelines and application deployments
  • Experience contributing to the development of DevSecOps training materials and delivering technical knowledge-sharing sessions for development and operations team members.

Our Equal Employment Opportunity Policy

The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.

The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or apply for a position on our website, please get in touch with Heaven Wood via e-mail at View email address on click.appcast.io or by calling View phone number on click.appcast.io to request accommodations.

Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit

Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the DevSecOps Engineer in Washington DC vacancy
  • $99k - $225k

    DevSecOps Engineer and SMEThe Opportunity:DevOps engineering requires a specific mix of development, engineering, and communication skills. As a DevOps engineer, you know that these skills create efficiency and effectiveness—so you can quickly deliver the best solutions... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Alexandria, VA
    4 days ago
  • $125k

    Computer Technologies Consultants (CTC) is seeking a DevSecOps Engineer to support the Congressional Budget Office (CBO) in Washington, DC. With offices in Washington DC and San Diego, CA, CTC is a leading technology company providing lifecycle IT, data analytics, cloud... 
    Suggested
    Full time
    Contract work
    For contractors
    Work at office
    Local area
    Remote work

    Computer Technologies Consultants (CTC)

    Washington DC
    17 hours ago
  • $170k - $193k

    As a Sr. DevSecOps Engineer II, you’ll design, implement, and sustain secure, automated CI/CD pipelines and infrastructure across hybrid on‐premises and cloud environments. This role integrates security controls directly into DevOps workflows, enabling continuous compliance... 
    Suggested
    Full time
    Local area

    MetroStar Systems

    Washington DC
    2 days ago
  • $62k - $141k

    DevSecOps EngineerThe Opportunity:As a DevOps engineer, you know how to set up cloud environments and provision computer networking, storage, and virtual networks, ultimately, how to “harness the cloud.” We’re looking for a DevOps infrastructure engineer like you to support... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Arlington, VA
    1 day ago
  • $107.93k - $188k

     ...Join Deloitte’s Government & Public Services practice as a DevSecOps-focused Senior Consultant, Enterprise Security. In this role,...  ...scanning, and secrets detectionSupporting cloud and platform engineering teams with secure configuration, infrastructure as code, container... 
    Suggested
    Local area

    Deloitte

    Rosslyn, VA
    1 day ago
  • $77.6k - $176k

    DevSecOps EngineerThe Opportunity:Modern engineering teams rely on secure, automated delivery pipelines and cloud-hosted DevSecOps platforms to deliver software quickly, reliably, and securely. As a DevSecOps Engineer, you will design, build, harden, and operate CI/CD... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Washington DC
    3 days ago
  • $180k - $200k

     ...sponsorship or working under a temporary visa status (e.g., H-1B, L-1, F-1, OPT, CPT, etc.) are not eligible for this role.As a Senior DevSecOps Engineer, you will play a crucial role in integrating security practices into the DevOps pipeline. You will be responsible for... 
    Permanent employment
    Temporary work
    H1b
    Visa sponsorship
    Work visa

    Privateer Space

    Washington DC
    3 days ago
  •  ...Senior DevSecOps Engineer We are seeking a highly skilled and motivated Senior DevSecOps Engineer to join our team in a hybrid capacity, supporting a key Randstad client in the DC area. In this critical role, you will be responsible for leading the integration of security... 

    Samprasoft

    Washington DC
    3 days ago
  •  ...growth, and winning ideas. Military Veterans Encouraged to Apply. Job Description: We are seeking a highly skilled DevSecOps Engineer to support the U.S. Department of Veterans Affairs (VA) under the T4NG2 contract vehicle. This role will be part of an agile... 
    Contract work
    For contractors
    Remote work

    Network Designs

    Washington DC
    4 days ago
  •  ...DevSecOps Engineer Seeking a DevSecOps Engineer to integrate security into the software development and delivery lifecycle. This role will design, implement, and operate secure CI/CD pipelines, cloud infrastructure, automation, and security controls that enable development... 

    InstantServe LLC

    Arlington, VA
    4 days ago
  • $220k - $230k

     ...GovCIO is currently hiring a DevSecOps Engineer with an active Secret clearance to integrate security practices into software development and infrastructure operations by automating secure delivery pipelines, compliance controls, vulnerability management, and deployment... 
    Currently hiring
    Remote work

    Govcio LLC

    Arlington, VA
    1 day ago
  •  ...DevSecOps Engineer At Ardent, we hire people who want more than a job — they want to serve a mission that matters. Our teams support the federal government's most critical national security and defense priorities, helping protect the nation, strengthen resilience,... 
    Local area
    Remote work
    Flexible hours
    Shift work

    Ardent Services

    Washington DC
    4 days ago
  •  ...Devsecops Pipeline Engineer We are adding a DevSecOps Pipeline Engineer to a Platform Engineering team support the Defense Manpower Data Center (DMDC). This Platform Engineering team owns and operates the Kubernetes clusters running on OCI, as well as the developer... 

    Mount Indie

    Washington DC
    3 days ago
  • $110k - $149k

     ...Description DevSecOps Engineer Xcelerate Solutions is seeking a DevSecOps Engineer to support CyberPRIMES cybersecurity, privacy, records and information management, and related enterprise support for DHRA, including DMDC and OUSD(P&R). Come join our award-winning... 

    VMD Corp

    Alexandria, VA
    5 days ago
  • $140k - $155k

     ...to their community while being profitable. We're an award-winning IT solutions provider to the Federal government seeking a DevSecOps Engineer to join our project team. This Position Description (PD) is for an experienced DevSecOps Engineer to help design, develop... 
    Full time
    For contractors
    Remote work

    TCG

    Washington DC
    17 hours ago
  •  ...is our specialty, we also focus on ICAM, Zero Trust, digital engineering and transformation, and enterprise AI and intelligent automation...  ...and share in the many benefits and opportunities we offer. DevSecOps Engineer Responsibilities and Duties: Design, implement,... 
    For contractors

    Electrosoft

    Arlington, VA
    3 days ago
  • $62k - $141k

     ...Job Number: R0242809 DevSecOps Engineer The Opportunity: As a DevOps engineer, you know how to set up cloud environments and provision computer networking, storage, and virtual networks, ultimately, how to "harness the cloud." We're looking for a DevOps infrastructure... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Arlington, VA
    1 day ago
  • $120k - $140k

     ...DevSecOps Engineer(REMOTE) ROLE  We need an experienced DevSecOps Engineer at the U.S. Securities and Exchange Commission (SEC). The SEC's Division of Corporation Finance reviews public company filings to ensure investors are provided with the material information... 
    Full time
    Contract work
    Work at office
    Remote work
    Relocation
    Relocation package

    West 4th Strategy

    Washington DC
    3 days ago
  • $220k - $230k

     ...Arlington, Virginia Secret Hybrid schedule Information Technology Overview GovCIO is currently hiring a DevSecOps Engineer with an active Secret clearance to integrate security practices into software development and infrastructure operations by automating... 
    Full time
    Currently hiring
    Remote work
    Flexible hours

    GovCIO

    Arlington, VA
    2 days ago
  •  ...team thrives on turning tricky problems into solutions that are practical, accessible and performant. About This Position DevSecOps Engineers at BLEN play a pivotal role in our modernization program, implementing and maintaining robust Continuous Integration/... 

    BLEN Corp

    Washington DC
    1 day ago
  •  ...interview What You'll Do: - Collaborate with a team of engineers to implement Morgan Stanley specific security policies in the...  ...Sonatype - Experience with Threat Analysis. - Experience with DevSecOps, Secure SDLC. - DevOps container/orchestration tools (... 
    Work experience placement
    Local area

    3B Staffing LLC

    Arlington, VA
    2 days ago
  • $120k - $160k

     ...Job Description Description SAIC has an opportunity for a DevSecOps Engineer to integrate security into the software development and delivery lifecycle. This role will design, implement, and operate secure CI/CD pipelines, cloud infrastructure, automation... 
    2 days per week

    Science Applications International Corporation

    Arlington, VA
    2 days ago
  •  ...DevSecOps Engineer Randstad is seeking a skilled DevSecOps Engineer to support a key client in Washington, DC. This role will focus on building secure, scalable, and efficient CI/CD pipelines with an emphasis on automation, security tooling integration, and developer... 

    Samprasoft

    Washington DC
    3 days ago
  •  ...DevSecOps Engineer The DevSecOps Engineer is an individual contributor role overseeing the development, implementation, and maintenance of our DevOps processes and tools in a hybrid cloud platform, AWS only. (No Azure experience accepted). The successful candidate... 

    Software Technology Inc

    Bethesda, MD
    2 days ago
  • $160k - $180k

    Full-Time/Part-Time Full-Time Description RiVidium Inc. is seeking a highly qualified DevSecOps Engineer to support a federal client. This position is contingent upon contract award and funding approval. As such, this job posting is intended to identify qualified candidates... 
    Full time
    Contract work
    Part time

    Rividium Inc

    Washington DC
    4 days ago
  • $155k - $185k

     ...DevSecOps Engineer Dark Wolf is seeking a DevSecOps Engineer to accelerate the secure delivery of mission-critical software by embedding DevSecOps practices directly into the development pipeline. The focus for this individual will be on automating deployment and security... 
    Full time
    For contractors
    Work experience placement

    Dark Wolf Solutions

    Arlington, VA
    2 days ago
  • DevSecOps Engineer About Essnova Solutions Essnova Solutions is a fast-growing federal contractor delivering innovative technology, cybersecurity, cloud, and digital transformation solutions to Federal Government customers. We are seeking a DevSecOps Engineer to support... 
    For contractors

    Essnova Solutions

    Washington DC
    3 days ago
  •  ...DevSecOps Engineer The DevSecOps Engineer serves as the lead technical engineer responsible for the automation, continuous integration/continuous deployment (CI/CD), and security posture of the cloud infrastructure for the Office of Naval Research (ONR) Comptroller... 
    Temporary work
    Work at office
    Immediate start
    Flexible hours

    Integral Federal

    Washington DC
    1 day ago
  • Job Description: POSITION SUMMARY We are seeking an experienced DevSecOps Engineer to design, implement, and manage secure CI/CD pipelines and DevSecOps practices in support of a large-scale federal IT program. The successful candidate will integrate security throughout... 
    Permanent employment

    Avyanna Technologies

    Bethesda, MD
    23 hours ago
  •  ...DevSecOps Engineer The DevSecOps Engineer shall serve as the lead technical engineer responsible for designing, implementing, securing, automating, and sustaining the cloud infrastructure supporting the Office of Naval Research (ONR) Data & Analytics environment. The... 
    Contract work
    Work at office

    Occam Solutions

    Arlington, VA
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to DevSecOps Engineer. Be the first to apply!