DevSecOps Engineer
Koniag
Koniag Data Solutions, LLC, a Koniag Government Services company , is seeking a DevSecOps Engineer to support KDS and our government customer in Washington, DC. This position requires the candidate to be able to obtain a Public Trust.
Benefits include medical, dental, and vision insurance, 401(k) retirement plan, paid time off, paid parental leave, life and disability insurance, flexible spending accounts, commuter benefits, and tuition reimbursement. Koniag Data Solutions, a Koniag Government Services company, is seeking an experienced DevSecOps Engineer to support the implementation, operation, and continuous improvement of DevSecOps practices, pipelines, and tools in support of the U.S. Small Business Administration (SBA). The ideal candidate is a mid to senior-level engineering professional with solid hands-on experience in DevSecOps methodologies, CI/CD pipeline development, security automation, and cloud technologies, and a demonstrated ability to integrate security practices into software development and operations workflows within a federal government environment. This individual will play a key role in building, maintaining, and improving SBA's DevSecOps capabilities, contributing to the secure and efficient delivery of software and infrastructure solutions that support SBA's mission and operational objectives. The DevSecOps Engineer will support the design, implementation, operation, and continuous improvement of DevSecOps pipelines, tools, and practices at the SBA, working closely with development teams, security teams, operations staff, and program managers to integrate security throughout the software development lifecycle and enable the reliable, secure delivery of software and infrastructure solutions in support of SBA's mission.Principal responsibilities will include but are not limited to:
- Design, build, implement, and maintain CI/CD pipelines and DevSecOps toolchain components for SBA, ensuring pipelines are automated, secure, and aligned with SBA's software delivery requirements and security policies.
- Integrate security tools and automation into CI/CD pipelines including static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), container security scanning, and infrastructure as code (IaC) security scanning to support the continuous identification and remediation of security vulnerabilities throughout the SDLC.
- Implement and maintain infrastructure as code (IaC) practices and tools to support automated, repeatable, and auditable provisioning and management of SBA's IT infrastructure and cloud environments.
- Collaborate with SBA's development, security, and operations teams to implement and enforce DevSecOps standards, coding best practices, security requirements, and quality gates within CI/CD pipelines.
- Support the containerization and orchestration of SBA applications, ensuring container images are properly secured, scanned, and managed in accordance with SBA security requirements and federal guidelines.
- Monitor and analyze the performance, reliability, and security of CI/CD pipelines and DevSecOps toolchain components, identifying and implementing improvements to enhance pipeline efficiency and overall effectiveness.
- Support the planning and execution of cloud migration and modernization initiatives, applying DevSecOps principles and practices to support the secure migration of SBA workloads to cloud environments.
- Develop and maintain DevSecOps documentation including pipeline configurations, technical runbooks, architecture documentation, and standard operating procedures to support SBA's DevSecOps program.
- Collaborate with SBA's ISSO and security teams to ensure DevSecOps pipelines and practices support the maintenance of system Authorization to Operate (ATO) requirements, including supporting the automation of security control testing and evidence collection activities.
- Participate in code reviews, architecture reviews, and security reviews for pipeline components and infrastructure as code artifacts, ensuring they meet SBA's quality and security standards.
- Support the implementation and management of source code management practices, repository security configurations, and branching strategies to ensure the integrity and security of SBA's software development environment.
- Assist in the evaluation and implementation of new DevSecOps tools, technologies, and practices to enhance SBA's software delivery capabilities and security posture.
- Provide technical support and guidance to development and operations teams on DevSecOps tools, practices, and security requirements, helping to build organizational capability and support for DevSecOps principles.
- Participate in incident response activities related to CI/CD pipeline issues, security events within the DevSecOps environment, and application deployment failures, supporting timely identification and resolution of issues.
- Stay current on DevSecOps technology developments, federal policy guidance, and industry best practices, applying this knowledge to continuously improve SBA's DevSecOps capabilities and practices.
- Bachelor's degree in Computer Science, Software Engineering, Information Technology, Cybersecurity, or a related field from an accredited college or university, OR equivalent combination of education and relevant work experience.
- 4-6 years of progressive experience in software engineering, systems engineering, or DevOps/DevSecOps, with demonstrated hands-on experience designing, implementing, and managing CI/CD pipelines and DevSecOps practices in a federal government or enterprise environment.
- Demonstrated hands-on experience with CI/CD tools and platforms such as Jenkins, GitLab CI/CD, GitHub Actions, or similar, and container technologies such as Docker and Kubernetes.
- Demonstrated experience integrating security tools and automation into CI/CD pipelines including SAST, DAST, SCA, and container security scanning solutions.
- One or more of the following certifications: CompTIA Security+, Certified Kubernetes Administrator (CKA), AWS Certified Developer, Microsoft Certified: Azure Developer Associate, or equivalent DevSecOps or cloud engineering certification.
- Bachelor's or Master's degree in Computer Science, Software Engineering, Information Technology, or a related field.
- Prior experience supporting DevSecOps implementation activities at a federal civilian agency, preferably the SBA or a similar organization.
- Certified Kubernetes Administrator (CKA), AWS Certified DevOps Engineer, Microsoft Certified: DevOps Engineer Expert, or other relevant advanced DevSecOps or cloud engineering certifications.
- Solid knowledge of DevSecOps principles, methodologies, and best practices and their application to the design, implementation, and operation of secure, automated software delivery pipelines in a federal government or enterprise environment.
- Demonstrated hands-on experience with CI/CD tools and platforms including Jenkins, GitLab CI/CD, GitHub Actions, CircleCI, or similar, and the ability to design, build, and maintain CI/CD pipeline configurations.
- Solid experience with containerization and container orchestration technologies including Docker and Kubernetes, including experience with container security practices and image scanning in an operational environment.
- Experience with infrastructure as code (IaC) tools and practices including Terraform, Ansible, AWS CloudFormation, or similar, and their application to automated infrastructure provisioning and management.
- Experience integrating security automation into CI/CD pipelines including SAST tools such as SonarQube or Checkmarx, DAST tools such as OWASP ZAP or Burp Suite, SCA tools such as Black Duck or Snyk, and container security scanning tools such as Twistlock, Aqua Security, or Anchore.
- Solid experience with cloud platforms and services including AWS, Microsoft Azure, or Google Cloud Platform, and the application of cloud-native DevSecOps practices and tools within federal environments.
- Proficient experience with source code management and collaboration platforms including Git, GitHub, GitLab, or Bitbucket, including familiarity with branching strategies, code review processes, and repository security practices.
- Foundational understanding of federal cybersecurity frameworks, requirements, and guidance including NIST SP 800-53, FISMA, and FedRAMP, and their relevance to DevSecOps practices and pipeline security in a federal environment.
- Experience with monitoring, logging, and observability tools and platforms such as ELK Stack, Prometheus, Grafana, Splunk, or similar, and their integration into DevSecOps pipelines and operations.
- Solid experience with scripting and programming languages including Python, Bash, PowerShell, or similar, and their application to pipeline automation, toolchain integration, and infrastructure management tasks.
- Effective written and oral communication skills in English, with the ability to clearly communicate DevSecOps concepts, pipeline configurations, and technical findings to both technical and non-technical stakeholders.
- Ability to work both independently and collaboratively in a team environment, demonstrating flexibility and responsiveness to changing priorities and requirements in a fast-paced federal IT environment.
- Ability to obtain and maintain a Public Trust clearance as required by the SBA.
- Prior experience supporting DevSecOps implementation and operations at the SBA or a similar federal civilian agency.
- Familiarity with SBA's IT environment, development platforms, and mission areas, including an understanding of the challenges and opportunities associated with implementing DevSecOps within the SBA environment.
- Experience with artifact management and software supply chain security tools and practices including JFrog Artifactory, Nexus Repository, or similar, and their integration into secure software delivery pipelines.
- Knowledge of service mesh technologies such as Istio or Linkerd and their application to securing microservices architectures within a DevSecOps context.
- Familiarity with GitOps practices and tools such as ArgoCD or Flux and their application to automated, auditable infrastructure and application deployments.
- Knowledge of the NIST Secure Software Development Framework (SSDF) and its relevance to DevSecOps implementation in a federal government environment.
- Experience supporting ATO processes and continuous monitoring programs, including contributing to the automation of security control testing and evidence collection within CI/CD pipelines.
- Familiarity with software bill of materials (SBOM) concepts and tools and their relevance to software supply chain security and federal compliance requirements.
- Certified Kubernetes Administrator (CKA), Certified Kubernetes Security Specialist (CKS), AWS Certified DevOps Engineer, Microsoft Certified: DevOps Engineer Expert, or other relevant advanced DevSecOps or cloud certifications.
- Experience with Red Hat OpenShift and its application to container orchestration and DevSecOps practices in federal IT environments.
- Basic familiarity with chaos engineering concepts and tools and their application to improving the resilience and reliability of DevSecOps pipelines and application deployments
- Experience contributing to the development of DevSecOps training materials and delivering technical knowledge-sharing sessions for development and operations team members.
Our Equal Employment Opportunity Policy The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment. The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or apply for a position on our website, please get in touch with Heaven Wood via e-mail at View email address on click.appcast.io or by calling View phone number on click.appcast.io to request accommodations. Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the DevSecOps Engineer in Washington DC vacancy
- ...We are seeking a highly skilled SecDevOps Engineer to lead the design, automation, and maintenance of secure cloud infrastructure and CI/CD pipelines within multi-cloud environments. This role focuses on implementing Zero Trust architectures, continuous security monitoring...SuggestedFull timeRemote work
$120k - $125k
...Conviso Inc is hiring Secret Cleared DevSecOps Engineer. This is a 100% Remote set-up position & comes with benefits, 401K & some accrued PTO. Role: DevSecOps Engineer Active Secret Clearance is needed Remote Role Certification : DoD 8570 IAT II (i.e. Security+...SuggestedRemote work$77.6k - $176k
DevSecOps Engineer, SeniorThe Opportunity:DevOps engineering requires a specific mix of development, engineering, and communication skills. As a DevOps engineer, you know that these skills create efficiency and effectiveness—so you can quickly deliver the best solutions...SuggestedFull timeContract workPart timeWork at officeLocal areaRemote work$77.6k - $176k
DevSecOps EngineerThe Opportunity:Modern engineering teams rely on secure, automated delivery pipelines and cloud-hosted DevSecOps platforms to deliver software quickly, reliably, and securely. As a DevSecOps Engineer, you will design, build, harden, and operate CI/CD...SuggestedFull timeContract workPart timeWork at officeLocal areaRemote work$150k - $185k
OverviewAs a Senior DevSecOps Engineer, you will work with our growing DevSecOps practice delivering features to support cloud and application development. We are looking for candidates with 5-7 years experience with cloud platform services and DevSecOps practices such...Suggested- ...Position Title: Senior DevSecOps & Software Engineer Location: Pentagon, Arlington, Virginia Category: Funded Schedule (FT/PT): Full Time Travel Required: May require occasional domestic travel Shift: Day Remote Type: In-Office Clearance...Full timeTemporary workWork at officeLocal areaRemote workFlexible hoursShift work
$150k - $180k
As a REMOTE DevSecOps Engineer with MTSI, you will be responsible for aiding in the solutioning, implementing, and sustaining cloud-native and traditional infrastructure, tools, and technologies. You will be responsible for ensuring security posture meets any requirements...Contract workRemote work$185k - $210k
The DevSecOps Engineer III designs, implements, and sustains secure, automated CI/CD pipelines and infrastructure across hybrid on‐premises and cloud environments. This role integrates security controls directly into DevOps workflows, enabling continuous compliance, monitoring...Full timeLocal area$131.3k - $237.35k
...the mission-critical systems that keep our nation secure.Your opportunity to lead transformation.Join the core engineering team building the new USCG DevSecOps platform that will be used by hundreds of mission-application developers across the Coast Guard. If you are an...Full time$87.1k - $157.45k
...self-starter for this technically sophisticated and challenging engineering position, developing a variety of naval training and... ...Simulation Systems for our US Navy customers. You will administer DevSecOps and Configuration Management (CM) practices, tools and techniques...Full timeInterim roleWork at officeLocal areaRemote work$87.1k - $157.45k
...The Geospatial Analyst Solutions Directorate, part of the National Solutions Business Area, is currently seeking a Mid-Level DevSecOps Engineer on the Maru Program. The successful candidate will play a critical role in the integration of security into all stages of the...Full timeContract workShift work$161k - $221k
...excellence.This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk.Staff DevSecOps Engineer (TS/SCI)Secure Every Identity, from AI to HumanIdentity is the key to unlocking the potential of AI. Okta secures AI by building...Permanent employmentLocal areaWorldwideFlexible hours- ...practical, accessible and performant.About This PositionDevSecOps Engineers at BLEN play a pivotal role in our modernization program,... ...and ensure the security and reliability of our solutions. Our DevSecOps team collaborates closely with development, operations, and security...
$97k - $192k
...The DevSecOps Engineer will maintain and operate the WDP DevSecOps factory and its associated automated pipelines. This person will integrate security into every phase of the software lifecycle, manage the continuous integration and continuous deployment (CI/CD) processes...Full timeContract workTemporary workWork at officeVisa sponsorshipWork visa$130k - $160k
...Overview Na Ali‘i is seeking a DevSecOps Engineer to support the secure delivery and operation of a software solution for a Department of the Navy organization and serve as a team member of Nakupuna Labs, the in-house innovation team. The ideal candidate has advanced...Contract work$120k - $160k
...Description SAIC has an opportunity for a DevSecOps Engineer to integrate security into the software development and delivery lifecycle. This role will design, implement, and operate secure CI/CD pipelines, cloud infrastructure, automation, and security controls that...1 day per week- ...DevSecOps Engineer This position is part of a proposal submission and is contingent upon contract award. Location: Arlington, VA (Hybrid) Clearance: DHS Suitability Description: Integrate security into all stages of the software development lifecycle...Contract work
- ...DevSecOps Engineer# DevSecOps EngineerWashington DC, DC 20032## OverviewPosition TypeFull Time## Description**Knight Federal Solutions is a trusted provider to industry leading prime contractors, the Department of Defense and the Intelligence Community. We have established...For contractors
- ...Primary Responsibility The DevSecOps Engineer shall serve as the lead technical engineer responsible for designing, implementing, securing, automating, and sustaining the cloud infrastructure supporting the Office of Naval Research (ONR) Data & Analytics environment...Contract workWork at office
- ...PTO, and Paid Holidays Soft Tech Consulting is seeking a highly motivated, self-directed individual to fill the role of a DevSecOps Engineer, who will maintain multiple client-managed cloud application stacks (Tomcat, Drupal, React, Node.js, Nginx, etc.) running as...Temporary work
$140k - $145k
...TS/SCI willingness to take a polygraph exam Must be a U.S. Citizen Job Summary Castalia Systems is seeking a Senior DevSecOps Engineer to work closely with your clients to understand their questions and needs and then dig into their data-rich environments to find...Contract workWork experience placementWork at officeLocal area$145.56k - $170.26k
...Devsecops Engineer The DevSecOps Engineer serves as the lead technical engineer responsible for the automation, continuous integration/continuous deployment (CI/CD), and security posture of the cloud infrastructure for the Office of Naval Research (ONR) Comptroller...Temporary workWork at officeImmediate startFlexible hoursShift work- Security Monitoring & Incident Response Monitor access and security events across infrastructure and applications. Lead incident response and forensic investigations for cybersecurity events. Manage and update role-based access matrices and privileged access controls...
- ...DevSecOps Engineer The DevSecOps Engineer implements, automates, and maintains secure cloud infrastructure and CI/CD pipelines. You will build and manage infrastructure-as-code solutions, deploy and secure cloud environments, integrate security controls into development...For contractorsFlexible hours
$120k - $145k
...DevSecOps Engineer Location: Crystal City, VA Hybrid, periodic onsite presence (approximately 1-2 days/month) The Role You'll be at the forefront of delivering DevSecOps for solutions that directly impact our clients' law enforcement mission. You'll work with...Flexible hours$81k - $162.4k
...drive positive, lasting change that moves missions and the government forward! **The work: ** We are seeking a mid-level DevSecOps Engineer who will maintain multiple client-managed cloud application stacks (Tomcat, Drupal, React, Node.js, Nginx, etc.) running as Linux...Live inWork at officeLocal area- ...Entarian is seeking a highly skilled Software Developer with deep DevSecOps expertise to support the design, integration, testing,... ...secure enterprise environments. The ideal candidate brings strong engineering discipline, a security‑first mindset, and experience operating...Shift work
$140k - $155k
...to their community while being profitable. We're an award-winning IT solutions provider to the Federal government seeking a DevSecOps Engineer to join our project team. This Position Description (PD) is for an experienced DevSecOps Engineer to help design, develop...Full timeFor contractors$160k - $180k
...Full-Time/Part-Time Full-Time Description RiVidium Inc. is seeking a highly qualified DevSecOps Engineer to support a federal client. This position is contingent upon contract award and funding approval. As such, this job posting is intended to identify...Full timeContract workPart time- ...Senior DevSecOps Engineer We are seeking a highly skilled and motivated Senior DevSecOps Engineer to join our team in a hybrid capacity, supporting a key Randstad client in the DC area. In this critical role, you will be responsible for leading the integration of security...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to DevSecOps Engineer. Be the first to apply!



