DevSecOps Engineer
Koniag
Koniag Data Solutions, LLC, a Koniag Government Services company , is seeking a DevSecOps Engineer to support KDS and our government customer in Washington, DC. This position requires the candidate to be able to obtain a Public Trust.
We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more. Koniag Data Solutions, a Koniag Government Services company, is seeking an experienced DevSecOps Engineer to support the implementation, operation, and continuous improvement of DevSecOps practices, pipelines, and tools in support of the U.S. Small Business Administration (SBA). The ideal candidate is a mid to senior-level engineering professional with solid hands-on experience in DevSecOps methodologies, CI/CD pipeline development, security automation, and cloud technologies, and a demonstrated ability to integrate security practices into software development and operations workflows within a federal government environment. This individual will play a key role in building, maintaining, and improving SBA's DevSecOps capabilities, contributing to the secure and efficient delivery of software and infrastructure solutions that support SBA's mission and operational objectives. The DevSecOps Engineer will support the design, implementation, operation, and continuous improvement of DevSecOps pipelines, tools, and practices at the SBA, working closely with development teams, security teams, operations staff, and program managers to integrate security throughout the software development lifecycle and enable the reliable, secure delivery of software and infrastructure solutions in support of SBA's mission.Principal responsibilities will include but are not limited to:
- Design, build, implement, and maintain CI/CD pipelines and DevSecOps toolchain components for SBA, ensuring pipelines are automated, secure, and aligned with SBA's software delivery requirements and security policies.
- Integrate security tools and automation into CI/CD pipelines including static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), container security scanning, and infrastructure as code (IaC) security scanning to support the continuous identification and remediation of security vulnerabilities throughout the SDLC.
- Implement and maintain infrastructure as code (IaC) practices and tools to support automated, repeatable, and auditable provisioning and management of SBA's IT infrastructure and cloud environments.
- Collaborate with SBA's development, security, and operations teams to implement and enforce DevSecOps standards, coding best practices, security requirements, and quality gates within CI/CD pipelines.
- Support the containerization and orchestration of SBA applications, ensuring container images are properly secured, scanned, and managed in accordance with SBA security requirements and federal guidelines.
- Monitor and analyze the performance, reliability, and security of CI/CD pipelines and DevSecOps toolchain components, identifying and implementing improvements to enhance pipeline efficiency and overall effectiveness.
- Support the planning and execution of cloud migration and modernization initiatives, applying DevSecOps principles and practices to support the secure migration of SBA workloads to cloud environments.
- Develop and maintain DevSecOps documentation including pipeline configurations, technical runbooks, architecture documentation, and standard operating procedures to support SBA's DevSecOps program.
- Collaborate with SBA's ISSO and security teams to ensure DevSecOps pipelines and practices support the maintenance of system Authorization to Operate (ATO) requirements, including supporting the automation of security control testing and evidence collection activities.
- Participate in code reviews, architecture reviews, and security reviews for pipeline components and infrastructure as code artifacts, ensuring they meet SBA's quality and security standards.
- Support the implementation and management of source code management practices, repository security configurations, and branching strategies to ensure the integrity and security of SBA's software development environment.
- Assist in the evaluation and implementation of new DevSecOps tools, technologies, and practices to enhance SBA's software delivery capabilities and security posture.
- Provide technical support and guidance to development and operations teams on DevSecOps tools, practices, and security requirements, helping to build organizational capability and support for DevSecOps principles.
- Participate in incident response activities related to CI/CD pipeline issues, security events within the DevSecOps environment, and application deployment failures, supporting timely identification and resolution of issues.
- Stay current on DevSecOps technology developments, federal policy guidance, and industry best practices, applying this knowledge to continuously improve SBA's DevSecOps capabilities and practices.
- Bachelor's degree in Computer Science, Software Engineering, Information Technology, Cybersecurity, or a related field from an accredited college or university, OR equivalent combination of education and relevant work experience.
- 4-6 years of progressive experience in software engineering, systems engineering, or DevOps/DevSecOps, with demonstrated hands-on experience designing, implementing, and managing CI/CD pipelines and DevSecOps practices in a federal government or enterprise environment.
- Demonstrated hands-on experience with CI/CD tools and platforms such as Jenkins, GitLab CI/CD, GitHub Actions, or similar, and container technologies such as Docker and Kubernetes.
- Demonstrated experience integrating security tools and automation into CI/CD pipelines including SAST, DAST, SCA, and container security scanning solutions.
- One or more of the following certifications: CompTIA Security+, Certified Kubernetes Administrator (CKA), AWS Certified Developer, Microsoft Certified: Azure Developer Associate, or equivalent DevSecOps or cloud engineering certification.
- Bachelor's or Master's degree in Computer Science, Software Engineering, Information Technology, or a related field.
- Prior experience supporting DevSecOps implementation activities at a federal civilian agency, preferably the SBA or a similar organization.
- Certified Kubernetes Administrator (CKA), AWS Certified DevOps Engineer, Microsoft Certified: DevOps Engineer Expert, or other relevant advanced DevSecOps or cloud engineering certifications.
- Solid knowledge of DevSecOps principles, methodologies, and best practices and their application to the design, implementation, and operation of secure, automated software delivery pipelines in a federal government or enterprise environment.
- Demonstrated hands-on experience with CI/CD tools and platforms including Jenkins, GitLab CI/CD, GitHub Actions, CircleCI, or similar, and the ability to design, build, and maintain CI/CD pipeline configurations.
- Solid experience with containerization and container orchestration technologies including Docker and Kubernetes, including experience with container security practices and image scanning in an operational environment.
- Experience with infrastructure as code (IaC) tools and practices including Terraform, Ansible, AWS CloudFormation, or similar, and their application to automated infrastructure provisioning and management.
- Experience integrating security automation into CI/CD pipelines including SAST tools such as SonarQube or Checkmarx, DAST tools such as OWASP ZAP or Burp Suite, SCA tools such as Black Duck or Snyk, and container security scanning tools such as Twistlock, Aqua Security, or Anchore.
- Solid experience with cloud platforms and services including AWS, Microsoft Azure, or Google Cloud Platform, and the application of cloud-native DevSecOps practices and tools within federal environments.
- Proficient experience with source code management and collaboration platforms including Git, GitHub, GitLab, or Bitbucket, including familiarity with branching strategies, code review processes, and repository security practices.
- Foundational understanding of federal cybersecurity frameworks, requirements, and guidance including NIST SP 800-53, FISMA, and FedRAMP, and their relevance to DevSecOps practices and pipeline security in a federal environment.
- Experience with monitoring, logging, and observability tools and platforms such as ELK Stack, Prometheus, Grafana, Splunk, or similar, and their integration into DevSecOps pipelines and operations.
- Solid experience with scripting and programming languages including Python, Bash, PowerShell, or similar, and their application to pipeline automation, toolchain integration, and infrastructure management tasks.
- Effective written and oral communication skills in English, with the ability to clearly communicate DevSecOps concepts, pipeline configurations, and technical findings to both technical and non-technical stakeholders.
- Ability to work both independently and collaboratively in a team environment, demonstrating flexibility and responsiveness to changing priorities and requirements in a fast-paced federal IT environment.
- Ability to obtain and maintain a Public Trust clearance as required by the SBA.
- Prior experience supporting DevSecOps implementation and operations at the SBA or a similar federal civilian agency.
- Familiarity with SBA's IT environment, development platforms, and mission areas, including an understanding of the challenges and opportunities associated with implementing DevSecOps within the SBA environment.
- Experience with artifact management and software supply chain security tools and practices including JFrog Artifactory, Nexus Repository, or similar, and their integration into secure software delivery pipelines.
- Knowledge of service mesh technologies such as Istio or Linkerd and their application to securing microservices architectures within a DevSecOps context.
- Familiarity with GitOps practices and tools such as ArgoCD or Flux and their application to automated, auditable infrastructure and application deployments.
- Knowledge of the NIST Secure Software Development Framework (SSDF) and its relevance to DevSecOps implementation in a federal government environment.
- Experience supporting ATO processes and continuous monitoring programs, including contributing to the automation of security control testing and evidence collection within CI/CD pipelines.
- Familiarity with software bill of materials (SBOM) concepts and tools and their relevance to software supply chain security and federal compliance requirements.
- Certified Kubernetes Administrator (CKA), Certified Kubernetes Security Specialist (CKS), AWS Certified DevOps Engineer, Microsoft Certified: DevOps Engineer Expert, or other relevant advanced DevSecOps or cloud certifications.
- Experience with Red Hat OpenShift and its application to container orchestration and DevSecOps practices in federal IT environments.
- Basic familiarity with chaos engineering concepts and tools and their application to improving the resilience and reliability of DevSecOps pipelines and application deployments
- Experience contributing to the development of DevSecOps training materials and delivering technical knowledge-sharing sessions for development and operations team members.
Our Equal Employment Opportunity Policy The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment. The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or apply for a position on our website, please get in touch with Heaven Wood via e-mail at View email address on click.appcast.io or by calling View phone number on click.appcast.io to request accommodations. Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352
Vacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the DevSecOps Engineer in Washington DC vacancy
- ...Needs to be local No restrictions on visa Job Title: Senior DevSecOps Engineer Location: Washington, DC Job Description We are seeking a highly skilled and motivated Senior DevSecOps Engineer to join our team in a hybrid capacity...SuggestedLocal area
- ...T-Rex Solutions is seeking a Senior DevSecOps Engineer to support our FDIC customer. This role is primarily remote with potential for occasional meetings at FDIC HQ in Arlington, VA as needed. Responsibilities: DevSecOps Engineering and Automation Design,...SuggestedWork experience placementImmediate startRemote workShift work
$95k - $105k
...DevSecOps Engineer Camp Springs, MD We are a technology solutions firm headquartered in Bellevue, Washington, with a strong presence across the United States. Unified by a shared passion for solving complicated problems, our people are our greatest asset. We use...SuggestedPermanent employmentTemporary workH1bRemote workVisa sponsorshipFlexible hours2 days per week1 day per week- ...DevSecOps Engineer Patrick SFB, FL or Arlington, VA 540 is seeking a DevSecOps Engineer to support our partnership with Google and the Department of War in advancing mission-critical capabilities for a global data processing platform. This platform leverages Machine...SuggestedTemporary workWork at officeLocal areaFlexible hours
$114.6k - $190.2k
...with MANTECH! ***This is for a future opportunity*** MANTECH seeks motivated, career, and customer-oriented DevSecOps Engineer for a new initiative within the National Capital Region. This effort supports the rapid design, deployment, operation, and...SuggestedHourly payContract workTemporary workWork experience placementWork at officeLocal areaRemote work$125k
...Computer Technologies Consultants (CTC) is seeking a DevSecOps Engineer to support the Congressional Budget Office (CBO) in Washington, DC. With offices in Washington DC and San Diego, CA, CTC is a leading technology company providing lifecycle IT, data analytics...Full timeContract workFor contractorsWork at officeLocal areaRemote work- Security Monitoring & Incident Response Monitor access and security events across infrastructure and applications. Lead incident response and forensic investigations for cybersecurity events. Manage and update role-based access matrices and privileged access controls...
- ...resonate. Our work spans Infrastructure, Software Development, DevSecOps, Cybersecurity, Experience and Design, Organizational Change... ...destination. Job Description The Sr. DevSecOps Engineer will lead the design, implementation, and operation of secure,...Contract workRemote work
$165k - $195k
...DevSecOps Engineer Rumble Cloud is seeking a DevSecOps Engineer to embed security throughout the software development lifecycle for our cloud platform and customer-facing services. This is a hands-on engineering role that owns our Secure Software Development Lifecycle...$220k - $230k
...Arlington, Virginia Secret Hybrid schedule Information Technology Overview GovCIO is currently hiring a DevSecOps Engineer with an active Secret clearance to integrate security practices into software development and infrastructure operations by automating...Full timeCurrently hiringRemote workFlexible hours$135k - $170k
...Senior DevSecOps Engineer Stand Together is a philanthropic community that helps America's boldest changemakers tackle the root causes of our country's biggest problems, from education to the economy, broken communities, and toxic division, among dozens of other pressing...Immediate startFlexible hours- ...DevSecOps Engineer This position is part of a proposal submission and is contingent upon contract award. Location: Arlington, VA (Hybrid) Clearance: DHS Suitability Description: Integrate security into all stages of the software development lifecycle...Contract work
- ...DevSecOps Engineer The DevSecOps Engineer is an individual contributor role overseeing the development, implementation, and maintenance of our DevOps processes and tools in a hybrid cloud platform, AWS only. (No Azure experience accepted). The successful candidate...
- ...Role: Senior DevSecOps Engineer Location: Hybrid (US) Type: Full-Time About the Team: Join an innovative organization modernizing its cloud platform and engineering practices. You'll play a key role in building secure, scalable infrastructure while partnering...Full time
$74k - $150k
...automated testing, and data analysis for complex, mission-critical systems in the U.S. Department of Defense (DoD), is seeking a DevSecOps Engineer to join our team based out of our Arlington, VA location. The DevSecOps team is central to this mission,...Full timeWork at officeImmediate start- ...DevSecOps Engineer Randstad is seeking a skilled DevSecOps Engineer to support a key client in Washington, DC. This role will focus on building secure, scalable, and efficient CI/CD pipelines with an emphasis on automation, security tooling integration, and developer...
$106.3k - $136k
...elderly, and defend national interests on the battlefield. Our engineers, designers, and strategists cut through complexity to create... ...Role Overview: We are seeking a hands-on DevSecOps Engineer to join a cross-functional, entrepreneurial, collaborative...Full timeFor contractorsRemote work- ...This engineer will be responsible for designing, building, and maintaining secure cloud infrastructure and deployment pipelines supporting... ...8+ years in DevOps, SRE, Platform Engineering, or DevSecOps 5+ years focused on DevSecOps Strong Kubernetes administration...
- ...DevSecOps Engineer At Ardent, we hire people who want more than a job — they want to serve a mission that matters. Our teams support the federal government's most critical national security and defense priorities, helping protect the nation, strengthen resilience,...Local areaRemote workFlexible hoursShift work
- ...DevSecOps Engineer About Essnova Solutions Essnova Solutions is a fast-growing federal contractor delivering innovative technology, cybersecurity, cloud, and digital transformation solutions to Federal Government customers. We are seeking a DevSecOps Engineer to...For contractors
$145k - $160k
Senior DevSecOps Engineer Job number: 881 This is a remote position. Ad Hoc is a technology company that empowers organizations to deliver scalable, impactful digital services. Using modern, agile methods, our team creates products that meet people's needs...Remote workFlexible hoursShift work$155k - $185k
...DevSecOps Engineer Dark Wolf is seeking a DevSecOps Engineer to accelerate the secure delivery of mission-critical software by embedding DevSecOps practices directly into the development pipeline. The focus for this individual will be on automating deployment and security...Full timeFor contractorsWork experience placement- ...DevSecOps Engineer The DevSecOps Engineer serves as the lead technical engineer responsible for the automation, continuous integration/continuous deployment (CI/CD), and security posture of the cloud infrastructure for the Office of Naval Research (ONR) Comptroller...Temporary workWork at officeImmediate startFlexible hours
- ...DevSecOps Engineer Position Summary Softtek Government Solutions (SGS) is seeking a Mid-Level DevSecOps Engineer to support the Congressional Budget Office (CBO) DevSecOps Engineering Services task order. CBO maintains a hybrid cloud infrastructure environment...Work at officeLocal areaRemote workShift work
$220k - $230k
...GovCIO is currently hiring a DevSecOps Engineer with an active Secret clearance to integrate security practices into software development and infrastructure operations by automating secure delivery pipelines, compliance controls, vulnerability management, and deployment...Currently hiringRemote work$120k - $140k
...DevSecOps Engineer(REMOTE) ROLE We need an experienced DevSecOps Engineer at the U.S. Securities and Exchange Commission (SEC). The SEC's Division of Corporation Finance reviews public company filings to ensure investors are provided with the material information...Full timeContract workWork at officeRemote workRelocationRelocation package$62k - $141k
...Job Number: R0242809 DevSecOps Engineer The Opportunity: As a DevOps engineer, you know how to set up cloud environments and provision computer networking, storage, and virtual networks, ultimately, how to "harness the cloud." We're looking for a DevOps infrastructure...Full timeContract workPart timeWork at officeLocal areaRemote work$212.5k - $287.5k
...Lead DevSecOps Systems Engineer Help us simplify the complex as a Lead DevSecOps Systems Engineer at GDIT, where we tailor advanced cloud solutions to critical client missions. In this role, your priority will be engineering seamless, secure platform experiences for...Remote workFlexible hours- ...Job Title: Junior DevSecOps Engineer Company: BLN24 About Us: We find strength in teamwork-a better you is a better us. BLN24 is an award-winning Management Consulting Firm that supports the U.S. Federal Government in successfully achieving their mission and goals. Our...Remote work
- ...BLN24 in McLean, Virginia is seeking a Junior DevSecOps Engineer to assist in modernizing a mission-critical forecasting system. The role involves building and maintaining GitLab CI/CD pipelines, managing AWS infrastructure, and working with Docker and Kubernetes for...Remote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to DevSecOps Engineer. Be the first to apply!

