Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

DevSecOps Engineer

Wilcore Technologies

Job Description

Job Description

Description:

We are hiring a DevSecOps to support a pivotal federal program making a positive impact on millions of Americans’ daily lives.

This is a hands-on engineering role for someone who can combine DevSecOps expertise with practical cybersecurity and remediation experience. The DevSecOps/Security Engineer will collaborate closely with engineers, security teams, product leadership, and external stakeholders to strengthen the program’s cloud infrastructure, automate secure development practices, address security findings, and achieve and maintain an Authorization to Operate (ATO).

What You’ll Be Doing

  • Design, implement, maintain, and document secure CI/CD pipelines using modern DevSecOps practices.
  • Develop and maintain Infrastructure as Code (IaC) solutions using AWS CloudFormation.
  • Build, configure, secure, and support AWS environments and serverless computing services.
  • Integrate security controls, vulnerability scanning, and automated compliance checks throughout the software development lifecycle.
  • Establish vulnerability patching and remediation plans and work directly with engineers to resolve identified findings.
  • Develop and execute actionable Plans of Action and Milestones (POA&Ms), including priorities, owners, dependencies, target completion dates, and measurable milestones.
  • Proactively track POA&M progress, identify blockers, and communicate changes to projected remediation timelines.
  • Assess new security findings as they are identified and determine their scope, severity, ownership, dependencies, and required remediation actions.
  • Identify duplicate, overlapping, inherited, or externally owned findings to prevent unnecessary remediation efforts.
  • Determine when findings are outside the program’s control or result from externally imposed technical constraints and coordinate appropriate risk-acceptance or disposition requests.
  • Develop level-of-effort estimates for core program POA&Ms and help prioritize remediation activities based on risk, effort, dependencies, and operational impact.
  • Maintain an accurate, real-time dashboard or tracker for security findings, POA&Ms, remediation activities, risks, dependencies, owners, and target dates.
  • Conduct or support Security Impact Assessments (SIAs) for proposed system, infrastructure, application, and configuration changes.
  • Support activities required to achieve and maintain an ATO while ensuring program operations adhere to applicable federal software-development and cybersecurity requirements.
  • Help reduce the program’s administrative and operational burden associated with managing ATOs and POA&Ms through automation, documentation, and repeatable processes.
  • Implement Zero Trust best practices, including data tagging and other mechanisms that improve data tracking, classification, and sensitivity management.
  • Collaborate with DevOps engineers to establish secure, modern development and data-science environments.
  • Engage proactively with developers, infrastructure engineers, security personnel, product owners, program leadership, and external stakeholders to drive findings through resolution.
  • Create and maintain technical documentation, remediation evidence, operating procedures, implementation plans, and security-related artifacts.
  • Support and secure Linux-based development and production environments.
  • Investigate Docker containers, container images, configurations, dependencies, and potential security vulnerabilities.
  • Participate effectively in an Agile software-development environment.
  • Perform other related duties as assigned.

  What You’ll Bring

  • Hands-on experience designing, developing, and supporting CI/CD pipelines.
  • Experience with GitHub Actions, AWS CloudFormation, Amazon CloudWatch, or comparable technologies.
  • Experience creating, configuring, and supporting AWS services, including ECS, S3, RDS, and Lambda.
  • Experience developing and improving CI/CD scripts and automated services supporting software development and deployment.
  • Experience identifying, assessing, prioritizing, and remediating infrastructure, application, container, and cloud-security vulnerabilities.
  • Demonstrated experience developing vulnerability-patching and remediation plans.
  • Experience managing or supporting POA&Ms, including defining corrective actions, owners, dependencies, milestones, target dates, and closure evidence.
  • Ability to translate security findings into practical engineering tasks and work directly with technical teams through remediation and closure.
  • Experience supporting ATO activities, Security Impact Assessments, or federal security-authorization processes.
  • Knowledge of federal cybersecurity and secure software-development requirements.
  • Experience with Infrastructure as Code and configuration-management practices.
  • Experience supporting and securing Linux-based environments.
  • Experience working with Docker and investigating container configurations and vulnerabilities.
  • Understanding of Zero Trust principles and their application within cloud-based environments.
  • Strong organizational skills and the ability to manage multiple security findings, remediation activities, dependencies, and deadlines simultaneously.
  • Ability to develop realistic plans of action and level-of-effort estimates in an environment where requirements and priorities may change.
  • Strong analytical skills, including the ability to identify duplicate findings, ownership boundaries, inherited risks, and external dependencies.
  • Proactive communication skills and the ability to engage engineers, security teams, program leaders, and external stakeholders without waiting for issues to escalate.
  • Ability to maintain accurate dashboards, trackers, documentation, and status reports.
  • A collaborative mindset and the ability to work successfully with multidisciplinary teams of developers, engineers, managers, security professionals, and product managers.
  • A security-first mindset and the ability to keep infrastructure, application, and data security at the forefront of engineering decisions.
  • Experience working as part of an Agile software-development team.

Preferred Qualifications

  • Experience supporting federal government systems or programs.
  • Experience working with federal security frameworks, authorization requirements, and continuous-monitoring processes.
  • Experience supporting ATO maintenance and POA&M remediation in an AWS cloud environment.
  • Familiarity with federal Zero Trust initiatives and data-classification or data-tagging practices.
  • Experience implementing automated security testing, vulnerability scanning, compliance validation, or policy enforcement within CI/CD pipelines.

Employment Requirements

  • Applicants must be authorized to work in the United States.
  • In alignment with federal contract requirements, certain positions may require U.S. citizenship and the ability to obtain and maintain a federal background investigation and/or security clearance.
Requirements:

What You’ll Bring

  • Hands-on experience designing, developing, and supporting CI/CD pipelines.
  • Experience with GitHub Actions, AWS CloudFormation, Amazon CloudWatch, or comparable technologies.
  • Experience creating, configuring, and supporting AWS services, including ECS, S3, RDS, and Lambda.
  • Experience developing and improving CI/CD scripts and automated services supporting software development and deployment.
  • Experience identifying, assessing, prioritizing, and remediating infrastructure, application, container, and cloud-security vulnerabilities.
  • Demonstrated experience developing vulnerability-patching and remediation plans.
  • Experience managing or supporting POA&Ms, including defining corrective actions, owners, dependencies, milestones, target dates, and closure evidence.
  • Ability to translate security findings into practical engineering tasks and work directly with technical teams through remediation and closure.
  • Experience supporting ATO activities, Security Impact Assessments, or federal security-authorization processes.
  • Knowledge of federal cybersecurity and secure software-development requirements.
  • Experience with Infrastructure as Code and configuration-management practices.
  • Experience supporting and securing Linux-based environments.
  • Experience working with Docker and investigating container configurations and vulnerabilities.
  • Understanding of Zero Trust principles and their application within cloud-based environments.
  • Strong organizational skills and the ability to manage multiple security findings, remediation activities, dependencies, and deadlines simultaneously.
  • Ability to develop realistic plans of action and level-of-effort estimates in an environment where requirements and priorities may change.
  • Strong analytical skills, including the ability to identify duplicate findings, ownership boundaries, inherited risks, and external dependencies.
  • Proactive communication skills and the ability to engage engineers, security teams, program leaders, and external stakeholders without waiting for issues to escalate.
  • Ability to maintain accurate dashboards, trackers, documentation, and status reports.
  • A collaborative mindset and the ability to work successfully with multidisciplinary teams of developers, engineers, managers, security professionals, and product managers.
  • A security-first mindset and the ability to keep infrastructure, application, and data security at the forefront of engineering decisions.
  • Experience working as part of an Agile software-development team.

Preferred Qualifications

  • Experience supporting federal government systems or programs.
  • Experience working with federal security frameworks, authorization requirements, and continuous-monitoring processes.
  • Experience supporting ATO maintenance and POA&M remediation in an AWS cloud environment.
  • Familiarity with federal Zero Trust initiatives and data-classification or data-tagging practices.
  • Experience implementing automated security testing, vulnerability scanning, compliance validation, or policy enforcement within CI/CD pipelines.

Employment Requirements

  • Applicants must be authorized to work in the United States.
  • In alignment with federal contract requirements, certain positions may require U.S. citizenship and the ability to obtain and maintain a federal background investigation and/or security clearance.
Vacancy posted 16 days ago
Similar jobs that could be interesting for youBased on the DevSecOps Engineer in Stafford, VA vacancy
  •  .... As a recognized leader in providing Information Technology, Engineering Services, Program Management, and Consulting Services to the U...  ...seeking Mid to Senior Systems Architects, Software Engineers, DevSecOps Engineers, Cybersecurity Engineers, and Data Engineers to support... 
    Suggested
    For contractors
    Remote work
    Flexible hours

    Solerity

    Quantico, VA
    16 days ago
  • Xcelerate Solutions is seeking a Senior Systems Engineer to join our GovCon team in Quantico, VA. Hybrid work arrangement. You will design, implement, and maintain secure CI/CD pipelines and Kubernetes clusters across on‑prem and cloud environments. The role requires 5... 
    Suggested

    VMD Corp

    Quantico, VA
    3 days ago
  • $145k - $210k

     ...Overview UICGS Bowhead is seeking an experienced Release Train Engineer (RTE) to support Agile Release Trains (ARTs) within PM Marine...  ...events. • Strong understanding of Agile software delivery, DevSecOps practices, and solution/ART-level alignment. • Excellent... 
    Suggested
    Work experience placement

    Bowhead

    Stafford, VA
    4 days ago
  • $61.9k - $141k

    DevOps EngineerThe Opportunity:Everyone is trying to “harness the cloud,” but not everyone knows how. As a DevOps engineer, you’re eager to develop, manage, and secure a container platform that meets your client’s needs and takes advantage of cloud capabilities. We need... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Fredericksburg, VA
    3 days ago
  •  ...Maturity Level 5, positioning us as one of a handful of elite companies to receive the highest form of third-party validation. DevOps Engineer is responsible for bridging the gap between development and operations teams by implementing automation, Continuous Integration/... 
    Suggested
    Full time
    Contract work
    Local area

    ValidaTek

    Quantico, VA
    6 days ago
  • $75k - $85k

     ...outcomes in complex, high-security environments. Who We're Looking For (Position Overview): Spry is seeking a DevOps Engineer Jr to join our team in Quantico, VA. This team oversees the creation, deployment, and ongoing support of software applications and... 
    Full time

    Spry Methods

    Quantico, VA
    3 days ago
  •  ...of people by bringing quality software to the federal space. What you'll be doing: Working hand in hand with great devops engineers building out devops best practices in the federal space. This will include creating and documenting CI/CD jobs, creating infrastructure... 
    Contract work

    Wilcore Technologies

    Stafford, VA
    28 days ago
  •  ...Job Description Job Description RiVidium Inc. is seeking a highly skilled Senior DevOps Engineer to bridge the gap between development and operations teams. This role is focused on fostering a collaborative, automation-driven environment that emphasizes continuous... 
    Contract work

    RIVIDIUM

    Quantico, VA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to DevSecOps Engineer. Be the first to apply!