DevSecOps Engineer
$165k - $195kRumble
DevSecOps Engineer
Rumble Cloud is seeking a DevSecOps Engineer to embed security throughout the software development lifecycle for our cloud platform and customer-facing services. This is a hands-on engineering role that owns our Secure Software Development Lifecycle (SSDLC) end to end: you'll design it, operate it, partner with engineering teams to remediate vulnerabilities, and continuously harden the CI/CD pipelines that ship Rumble Cloud to production.
Our platform is built on OpenStack and Ceph, and this role sits at the intersection of application security, platform engineering, and developer enablement. You should be comfortable reviewing pipeline configurations, triaging SAST, DAST, SCA, and container scanning findings with developers, and driving practical security improvements across Python, Go, and TypeScript codebases without becoming a bottleneck to delivery.
You'll work closely with application, platform, and infrastructure teams, with architectural guidance from our Software Architect, to make security a core part of how we build and ship software. That includes defining secure coding standards, integrating automated security tooling into CI/CD, improving software supply chain integrity, supporting audit readiness, and helping engineers make sound, scalable security decisions in a fast-moving cloud environment.
Responsibilities
- Own the SSDLC end to end, including secure coding standards, threat modeling, security gates, policy-as-code, and documentation suitable for audits, in partnership with the Software Architect in an advisory capacity.
- Drive vulnerability identification, triage, and remediation across Python, Go, and TypeScript/React codebases, partnering directly with engineers to prioritize and fix issues effectively.
- Design, harden, and optimize CI/CD pipelines using tools such as GitHub Actions, GitLab CI, Jenkins, or similar systems, ensuring security controls are integrated cleanly into developer workflows.
- Integrate and operate security tooling across the software delivery lifecycle, including SAST, DAST, SCA, secret scanning, container scanning, and dependency analysis.
- Implement secure software supply chain practices such as signed artifacts, SBOM generation, provenance controls, and related guardrails for build and release processes.
- Manage secrets, credentials, and signing keys used by build and deployment pipelines, applying least-privilege access, rotation, and secure storage practices.
- Partner with engineering teams to review code, assess risk, and recommend practical remediation approaches that improve security without unnecessarily slowing delivery.
- Support security incident response and post-incident follow-up for application and platform issues, helping identify root causes and drive durable fixes.
- Contribute to audit readiness and evidence collection for frameworks such as ISO 27001, SOC 2, PCI DSS, or FedRAMP, especially where CI/CD controls and engineering practices are in scope.
- Mentor engineers on secure development practices and help establish a culture where security is built into design, implementation, and release processes from the start.
Qualifications
- Experience in a DevSecOps, application security, or product security role, including designing and operating a Secure Software Development Lifecycle (SSDLC).
- Hands-on experience with CI/CD systems such as GitHub Actions, GitLab CI, Jenkins, or similar, including pipeline design, optimization, and hardening.
- Strong knowledge of application security tooling including SAST, DAST, SCA, and container scanning, along with a practical understanding of the OWASP Top 10.
- Ability to read and review code in at least one of Python, Go, or TypeScript and to work directly with developers on remediation.
- Experience with Docker and Kubernetes, secrets management systems such as Vault, and authentication patterns such as OAuth2 and OpenID Connect.
- Strong communication and collaboration skills, with the ability to influence engineering teams and drive secure practices without direct authority.
Preferred Qualifications
- Security certifications such as CSSLP, OSCP, GWAPT, CISSP, or equivalent.
- Experience with software supply chain security practices and tooling, including SLSA, Sigstore/cosign, and SBOM generation or validation.
- Familiarity with OpenStack, Ceph, or other large-scale open-source infrastructure platforms.
- Experience supporting audits or compliance initiatives such as ISO 27001, SOC 2, PCI DSS, or FedRAMP, including evidence collection tied to CI/CD and engineering controls.
- Experience with threat modeling methodologies such as STRIDE or PASTA, and with IaC security scanning across Terraform, Ansible, and Kubernetes manifests.
- Familiarity with multi-tenant SaaS or public cloud environments, and experience operating Rocky Linux or Ubuntu in production.
Annual Compensation Range:
$165,000 - $195,000 USD base + benefits + equity (If based in the United States)
$122,000 - $158,000 CAD base + benefits + equity (If based in Canada)
Note: The salary range listed for this position is a good faith estimate based on experience, qualifications, and internal compensation structure. The actual salary offered varies depending on the candidate's skill level and experience. This posting refers to an active vacancy within the organization.
Why Our Team Loves Working Here:
- We are making a significant financial impact for our video creator community; we're proud of their success stories
- We enjoy challenging the status quo and going head-to-head against Big Tech
- We aren't afraid to try new things; we act fast and want to win
- We pay competitive salaries and provide great benefits
EEO Statement: Rumble is an equal opportunity employer. We promote an equal playing field where everyone has the same opportunities regardless of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability status, or any other applicable characteristics protected by law. Rumble is an active participant in the e-verify program.
Physical demands of the position: While performing the duties of this job, the employee is regularly required to sit for prolonged periods of time while using a computer and/or keyboard. The employee is required to communicate verbally and hear. The employee is required to walk, reach with hands and arms, balance, and stoop or kneel. The employee may occasionally be required to lift and/or move up to 15 pounds. Specific vision abilities required by this job include clarity of vision at approximately 20 inches or less (i.e., working with small objects or reading small print), including the use of computers.
$98k - $163k
Job Family: Systems Engineering Travel Required: Up to 10% Clearance Required: Active Top Secret (TS) What You Will Do: Guidehouse is seeking a skilled DevSecOps Engineer to support a large-scale federal technology program operating within secure and classified...SuggestedFull timeTemporary workFlexible hours$114.6k - $190.2k
...with MANTECH! ***This is for a future opportunity*** MANTECH seeks motivated, career, and customer-oriented DevSecOps Engineer for a new initiative within the National Capital Region. This effort supports the rapid design, deployment, operation, and...SuggestedHourly payContract workTemporary workWork experience placementWork at officeLocal areaRemote work$100k
...Koniag Data Solutions, LLC, a Koniag Government Services company , is seeking a DevSecOps Engineer to support KDS and our government customer in Washington, DC. This position requires the candidate to be able to obtain a Public Trust. We offer competitive compensation...SuggestedWork experience placementLocal areaFlexible hours- ...The DevSecOps Engineer an individual contributor role overseeing the development, implementation, and maintenance of our DevOps processes and tools in a hybrid cloud platform, AWS only. (No Azure experience accepted). The successful candidate will be able to install,...Suggested
- ...DevSecOps Engineer About Essnova Solutions Essnova Solutions is a fast-growing federal contractor delivering innovative technology, cybersecurity, cloud, and digital transformation solutions to Federal Government customers. We are seeking a DevSecOps Engineer to...SuggestedFor contractors
- Peregrine Advisors Job Post Peregrine Advisors is a firm founded on a simple conviction: the best solutions come from the people closest to the problem, given real ownership and the tools to deliver. We are a data and technology innovation hub and a Benefit Corporation...Work at officeImmediate start
$155k - $185k
...DevSecOps Engineer Dark Wolf is seeking a DevSecOps Engineer to accelerate the secure delivery of mission-critical software by embedding DevSecOps practices directly into the development pipeline. The focus for this individual will be on automating deployment and security...Full timeFor contractorsWork experience placement- ...DevSecOps Engineer The DevSecOps Engineer serves as the lead technical engineer responsible for the automation, continuous integration/continuous deployment (CI/CD), and security posture of the cloud infrastructure for the Office of Naval Research (ONR) Comptroller...Temporary workWork at officeImmediate startFlexible hours
$95k - $105k
...new solutions. We guarantee you won't find a better place to work and thrive than at Blueprint. We are looking for a DevSecOps Engineer to join us as we build cutting-edge technology solutions! This is your opportunity to be part of a team that is committed to...Permanent employmentTemporary workH1bRemote workVisa sponsorshipFlexible hours2 days per week1 day per week$170k - $220k
...Position Status Title : Senior DevSecOps Engineer Location: Washington , DC (100% Onsite) Position Status: Full Time (Direct Hire) Clearance Requirements: Active TS/SCI Pay Rate: $170K-$220K (Depends on qualification) Position Description: We are seeking...Full time- ...DevSecOps Engineer This position is part of a proposal submission and is contingent upon contract award. Location: Arlington, VA (Hybrid) Clearance: DHS Suitability Description: Integrate security into all stages of the software development lifecycle...Contract work
- ...Needs to be local No restrictions on visa Job Title: Senior DevSecOps Engineer Location: Washington, DC Job Description We are seeking a highly skilled and motivated Senior DevSecOps Engineer to join our team in a hybrid capacity...Local area
- ...DevSecOps Engineer Patrick SFB, FL or Arlington, VA 540 is seeking a DevSecOps Engineer to support our partnership with Google and the Department of War in advancing mission-critical capabilities for a global data processing platform. This platform leverages Machine...Temporary workWork at officeLocal areaFlexible hours
- ...DevSecOps Engineer Edgewater Federal Solutions is seeking a DevSecOps Engineer to support a hybrid cloud infrastructure environment backed by established DevSecOps practices, security baselines, and federal compliance frameworks. The engineer will augment existing...Permanent employmentWork at officeRemote work
- ...Overview The DevSecOps Engineer supports the planning, analysis, and implementation activities required to migrate federal government applications into the CyberArk Privileged Access Management (PAM) platform. This role is responsible for providing technical insight...Shift work
- ...development and deployment workflows. Automate infrastructure provisioning, configuration, and application deployment using modern DevSecOps tools. Collaborate with development, QA, security, and operations teams to ensure security is embedded throughout the SDLC....
- ...Role: Senior DevSecOps Engineer Location: Hybrid (US) Type: Full-Time About the Team: Join an innovative organization modernizing its cloud platform and engineering practices. You'll play a key role in building secure, scalable infrastructure while partnering...Full time
$160k - $210k
...Modern Technology Solutions, Inc. (MTSI) is searching for a Senior DevSecOps Engineer. How you will contribute to our National Security and Defense mission: As a DevSecOps Engineer with MTSI, you will be responsible for aiding in the solutioning, implementing,...Contract workRemote work$74k - $150k
...automated testing, and data analysis for complex, mission-critical systems in the U.S. Department of Defense (DoD), is seeking a DevSecOps Engineer to join our team based out of our Arlington, VA location. The DevSecOps team is central to this mission,...Full timeWork at officeImmediate start$106.3k - $136k
...elderly, and defend national interests on the battlefield. Our engineers, designers, and strategists cut through complexity to create... ...Role Overview: We are seeking a hands-on DevSecOps Engineer to join a cross-functional, entrepreneurial, collaborative...Full timeFor contractorsRemote work- ...This engineer will be responsible for designing, building, and maintaining secure cloud infrastructure and deployment pipelines supporting... ...8+ years in DevOps, SRE, Platform Engineering, or DevSecOps 5+ years focused on DevSecOps Strong Kubernetes administration...
- ...resonate. Our work spans Infrastructure, Software Development, DevSecOps, Cybersecurity, Experience and Design, Organizational Change... ...destination. Job Description The Sr. DevSecOps Engineer will lead the design, implementation, and operation of secure,...Contract workRemote work
- Security Monitoring & Incident Response Monitor access and security events across infrastructure and applications. Lead incident response and forensic investigations for cybersecurity events. Manage and update role-based access matrices and privileged access controls...
$150k - $185k
...Overview As a Senior DevSecOps Engineer , you will work with our growing DevSecOps practice delivering features to support cloud and application development. We are looking for candidates with 5-7 years of experience with cloud platform services and DevSecOps practices...$150k - $180k
..., team members, and partners, we all achieve greater success. We have an immediate need for a highly skilled Senior-level DevSecOps Engineer to support federal programs hosted on AWS GovCloud. This role requires expertise in DevSecOps best practices, cloud automation...Immediate start- ...BLN24 in McLean, Virginia is seeking a Junior DevSecOps Engineer to assist in modernizing a mission-critical forecasting system. The role involves building and maintaining GitLab CI/CD pipelines, managing AWS infrastructure, and working with Docker and Kubernetes for...Remote work
- ...Info Gain Consulting is currently seeking an exceptional DevSecOps Engineer to join our team. You will be supporting and provide invaluable support to the Congressional Budget office IT support- Sentry contract. Augment established DevSecOps engineering environment...Contract workWork at officeRemote work
$145k - $160k
Senior DevSecOps Engineer Job number: 881 This is a remote position. Ad Hoc is a technology company that empowers organizations to deliver scalable, impactful digital services. Using modern, agile methods, our team creates products that meet people's needs...Remote workFlexible hoursShift work- ...Job Title: Junior DevSecOps Engineer Company: BLN24 About Us: We find strength in teamwork-a better you is a better us. BLN24 is an award-winning Management Consulting Firm that supports the U.S. Federal Government in successfully achieving their mission and goals. Our...Remote work
- ...automated testing, and data analysis for complex, mission-critical systems in the U.S. Department of Defense (DoD), is seeking a DevSecOps Engineer to join our team based out of our Arlington, VA location. The DevSecOps team is central to this mission, integrating...Work at officeImmediate start
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to DevSecOps Engineer. Be the first to apply!

