DevSecOps Security Engineer
$191.25k - $258.75kFull-time
Gdit
Responsibilities for this Position
Location: Any Location / RemoteFull Part/Time: Full time
Job Req: RQ226409 Type of Requisition:
Regular Clearance Level Must Currently Possess:
None Clearance Level Must Be Able to Obtain:
None Public Trust/Other Required:
BI Full 6C (T4) Job Family:
Cyber and IT Risk Management Job Qualifications: Skills:
AWS Cloud Computing, CI/CD, DevSecOps
Certifications:
None
Experience:
8 + years of related experience
US Citizenship Required:
Yes Job Description: DevSecOps Security Engineer Help us simplify the complex as a DevSecOps Security Engineer at GDIT, where we tailor advanced cloud security solutions to critical client missions. In this role, your priority will be engineering automated, secure compliance and vulnerability-management workflows for our program, while we focus on supporting your professional growth. Our work on the AED program depends on a senior security engineer who has managed the security portion of a DevSecOps pipeline operating under a continuous ATO (cATO). You'll leverage a modern stack, including AWS GovCloud security services, Terraform, and CI/CD pipeline tooling, to shift our security posture from reactive to proactive across a highly secure, automated environment. HOW A DEVSECOPS SECURITY ENGINEER WILL MAKE AN IMPACT:
- Architect and automate security workflows across our CI/CD pipeline and compliance operations, reducing manual effort in vulnerability scan analysis, security inventory auditing, and continuous monitoring reporting.
- Partner with development and platform teams to integrate, automate, and monitor security tool components (scan ingestion, finding triage, evidence generation) within automated pipelines.
- Build automation for compliance and ATO artifacts, including continuous monitoring reports, SPIAs, and control evidence mapping against NIST 800-53 / 800-171.
- Perform automated inventory delta analysis and drift detection across cloud accounts to maintain an accurate, auditable security posture.
- Champion DevSecOps culture by mentoring junior/mid-level engineers, educating teams on modern security tooling, and resolving complex configuration or performance issues.
- Leverage Generative AI engineering tools (such as Claude, Gemini, Copilot) to accelerate the development of security automation, compliance reporting, and Infrastructure as Code (IaC) scanning workflows.
- Define guidelines and standards for securing AWS Cloud and container environments, implementing advanced solutions for system security, logging, and audit correlation.
- Drive engineering excellence by guiding the preparation of comprehensive technical documentation, processes, and procedures.
- Continuous ATO Pipeline Security (Required): Direct, hands-on experience managing the security portion of a DevSecOps pipeline in a continuous ATO (cATO) environment. Candidates must have owned automated security gates, control evidence, and compliance posture within a live continuous-authorization pipeline, not point-in-time ATO or general DevOps exposure.
- Education & Experience: BA/BS Degree and 8+ years of relevant experience (or an equivalent combination of education and experience).
- Compliance Automation: Hands-on automation of compliance workflows: scan ingestion, finding triage, evidence generation, and continuous monitoring reporting.
- Cloud Security Tooling: Familiarity with AWS GovCloud security services (Security Hub, Inspector, GuardDuty, Config) and centralizing/correlating their findings, along with scanning and monitoring tooling such as Qualys, CrowdStrike, Nexus/Sonatype, SonarQube, and Datadog.
- Infrastructure as Code Security: Experience building and scanning IaC (Terraform, CloudFormation) for security and compliance.
- Standards & Frameworks: Background in NIST 800-53 or 800-171 control implementation and evidence mapping; familiarity with FedRAMP and IAM.
- Scripting/Development: Strong proficiency in automation scripting (Python, Bash, or similar) for building internal security tooling; Linux/Unix administration (RHEL or CentOS preferred).
- Compliance: Active Security+ Certification (or equivalent DoD 8570/8140 baseline).
- Team Leadership Potential: Demonstrated capability or strong desire to mentor junior/mid-level engineers, drive technical consensus, and serve as a technical anchor for the team.
- Problem Solving: Exceptional critical thinking skills with a proven track record of delivering simple, elegant solutions to highly complex security and compliance problems.
- Communication: Highly effective communication and collaboration skills, with the ability to bridge technical concepts between development teams and program stakeholders.
- Growth Mindset: A strong commitment to continuous learning, engineering best practices, and driving process improvements.
- Prior experience at a company that builds security products or DevSecOps tooling for software development, with a focus on cyber automation.
- Experience with continuous monitoring automation and proactive compliance posture management.
- Experience supporting a security audit cadence and evidence collection at scale.
- Exposure to security analytics platforms (e.g., Databricks) for correlating and analyzing security telemetry at scale.
- True Work-Life Autonomy: Enjoy a full-flex work week designed to give you ownership over your personal and professional priorities.
- Total Well-being: Comprehensive health, dental, vision, and wellness packages to support you and your family.
- Invested in Your Wealth: A robust 401(k) program with a competitive company match.
- Continuous Technical Evolution: Access to paid advanced certifications, higher education, and dedicated professional growth opportunities to keep your skills sharp.
- Internal Career Mobility: A dedicated internal talent team focused entirely on helping you navigate and advance your career path within GDIT.
- Scale & Innovation: Work with complex, mission-critical technologies and modern infrastructure frameworks that make a tangible impact.
- Rest & Recharge: Generous paid vacation, floating holidays, and time off to ensure you maintain peak performance.
40 Travel Required:
Less than 10% Telecommuting Options:
Remote Work Location:
Any Location / Remote Additional Work Locations: Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. GDIT typically provides new employees with 15 days of paid leave per calendar year to be used for vacations, personal business, and illness and an additional 10 paid holidays per year. Paid leave and paid holidays are prorated based on the employee's date of hire. The GDIT Paid Family Leave program provides a total of up to 160 hours of paid leave in a rolling 12 month period for eligible employees. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most. Our Identity Verification Process:
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes. About Our Work:
We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development. Join our Talent Community to stay up to date on our career opportunities and events at
gdit.com/tc . Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
PI286529516
DevSecOps Security Engineer
Help us simplify the complex as a DevSecOps Security Engineer at GDIT, where we tailor advanced cloud security solutions to critical client missions. In this role, your priority will be engineering automated, secure compliance and vulnerability-management workflows for our program, while we focus on supporting your professional growth.
Our work on the AED program depends on a senior security engineer who has managed the security portion of a DevSecOps pipeline operating under a continuous ATO (cATO). You'll leverage a modern stack, including AWS GovCloud security services, Terraform, and CI/CD pipeline tooling, to shift our security posture from reactive to proactive across a highly secure, automated environment.
HOW A DEVSECOPS SECURITY ENGINEER WILL MAKE AN IMPACT:
- Architect and automate security workflows across our CI/CD pipeline and compliance operations, reducing manual effort in vulnerability scan analysis, security inventory auditing, and continuous monitoring reporting.
- Partner with development and platform teams to integrate, automate, and monitor security tool components (scan ingestion, finding triage, evidence generation) within automated pipelines.
- Build automation for compliance and ATO artifacts, including continuous monitoring reports, SPIAs, and control evidence mapping against NIST 800-53 / 800-171.
- Perform automated inventory delta analysis and drift detection across cloud accounts to maintain an accurate, auditable security posture.
- Champion DevSecOps culture by mentoring junior/mid-level engineers, educating teams on modern security tooling, and resolving complex configuration or performance issues.
- Leverage Generative AI engineering tools (such as Claude, Gemini, Copilot) to accelerate the development of security automation, compliance reporting, and Infrastructure as Code (IaC) scanning workflows.
- Define guidelines and standards for securing AWS Cloud and container environments, implementing advanced solutions for system security, logging, and audit correlation.
- Drive engineering excellence by guiding the preparation of comprehensive technical documentation, processes, and procedures.
WHAT YOU'LL NEED TO SUCCEED:
Technical Expertise:
- Continuous ATO Pipeline Security (Required): Direct, hands-on experience managing the security portion of a DevSecOps pipeline in a continuous ATO (cATO) environment. Candidates must have owned automated security gates, control evidence, and compliance posture within a live continuous-authorization pipeline, not point-in-time ATO or general DevOps exposure.
- Education & Experience: BA/BS Degree and 8+ years of relevant experience (or an equivalent combination of education and experience).
- Compliance Automation: Hands-on automation of compliance workflows: scan ingestion, finding triage, evidence generation, and continuous monitoring reporting.
- Cloud Security Tooling: Familiarity with AWS GovCloud security services (Security Hub, Inspector, GuardDuty, Config) and centralizing/correlating their findings, along with scanning and monitoring tooling such as Qualys, CrowdStrike, Nexus/Sonatype, SonarQube, and Datadog.
- Infrastructure as Code Security: Experience building and scanning IaC (Terraform, CloudFormation) for security and compliance.
- Standards & Frameworks: Background in NIST 800-53 or 800-171 control implementation and evidence mapping; familiarity with FedRAMP and IAM.
- Scripting/Development: Strong proficiency in automation scripting (Python, Bash, or similar) for building internal security tooling; Linux/Unix administration (RHEL or CentOS preferred).
- Compliance: Active Security+ Certification (or equivalent DoD 8570/8140 baseline).
Leadership & Professional Skills:
- Team Leadership Potential: Demonstrated capability or strong desire to mentor junior/mid-level engineers, drive technical consensus, and serve as a technical anchor for the team.
- Problem Solving: Exceptional critical thinking skills with a proven track record of delivering simple, elegant solutions to highly complex security and compliance problems.
- Communication: Highly effective communication and collaboration skills, with the ability to bridge technical concepts between development teams and program stakeholders.
- Growth Mindset: A strong commitment to continuous learning, engineering best practices, and driving process improvements.
Preferred Background:
- Prior experience at a company that builds security products or DevSecOps tooling for software development, with a focus on cyber automation.
- Experience with continuous monitoring automation and proactive compliance posture management.
- Experience supporting a security audit cadence and evidence collection at scale.
- Exposure to security analytics platforms (e.g., Databricks) for correlating and analyzing security telemetry at scale.
GDIT IS YOUR PLACE:
- True Work-Life Autonomy: Enjoy a full-flex work week designed to give you ownership over your personal and professional priorities.
- Total Well-being: Comprehensive health, dental, vision, and wellness packages to support you and your family.
- Invested in Your Wealth: A robust 401(k) program with a competitive company match.
- Continuous Technical Evolution: Access to paid advanced certifications, higher education, and dedicated professional growth opportunities to keep your skills sharp.
- Internal Career Mobility: A dedicated internal talent team focused entirely on helping you navigate and advance your career path within GDIT.
- Scale & Innovation: Work with complex, mission-critical technologies and modern infrastructure frameworks that make a tangible impact.
- Rest & Recharge: Generous paid vacation, floating holidays, and time off to ensure you maintain peak performance.
The likely salary range for this position is $191,250 - $258,750. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.
Scheduled Weekly Hours:
40
Travel Required:
Less than 10%
Telecommuting Options:
Remote
Work Location:
Any Location / Remote
Additional Work Locations:
Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. GDIT typically provides new employees with 15 days of paid leave per calendar year to be used for vacations, personal business, and illness and an additional 10 paid holidays per year. Paid leave and paid holidays are prorated based on the employee's date of hire. The GDIT Paid Family Leave program provides a total of up to 160 hours of paid leave in a rolling 12 month period for eligible employees. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.
Our Identity Verification Process:
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.
About Our Work:
We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.
Join our Talent Community to stay up to date on our career opportunities and events at
gdit.com/tc .
Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
PI286529516
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the DevSecOps Security Engineer in Washington DC vacancy
- ...love to talk with you regarding the next step in your career. Come join our team! Zantech is looking for a talented DevSecOps / Security Engineer to contribute to the success of our upcoming Technical Infrastructure and Platform Support project for an On-Site role...SuggestedFull timeContract work
- Onyx Government Services is seeking a knowledgeable Lead Security Engineer to lead application security across a large-scale, cloud-native... ...every phase of the System Development Life Cycle (SDLC) using a DevSecOps methodology. The successful candidate will enforce Zero...SuggestedWork at office
- Dev Technology is seeking a Lead Security Engineer to oversee application security in a cloud-native federal modernization program. This role... ...of security principles, including Zero Trust and DevSecOps, ensuring that security is integrated throughout the development...SuggestedRemote jobFlexible hours
$159.3k - $202.4k
Amazon is seeking qualified Security Engineers to join our innovative, high energy Information Security team. In this role you will work within the Amazon Security Incident Response Team (SIRT). SIRT Security Engineers respond to security events, conduct analysis of threats...SuggestedInternshipFlexible hours$178.4k - $226.7k
Corporate Services Security (CPSS) is the Amazon security team aligned with Finance & Global Business Services (FGBS), People eXperience... ...Services. Apart from work, we provide opportunities for our engineers to pursue projects they are passionate about while maintaining...SuggestedInternshipFlexible hours$136k - $184k
Amazon’s Threat Hunting team is looking for a Security Engineer, Threat Hunting who is excited by the idea of searching for and uncovering undetected threat activities at petabyte scale. In this role, you will work alongside other Threat Hunting engineers to proactively...InternshipFlexible hoursShift work$178.4k - $226.7k
AHAS reduces the risk of human and operator access to AWS production systems and customer environments. As the Senior Security Engineer embedded with an AHAS software development team, you own the security design decisions for the operator-access tooling this team builds...InternshipRemote workFlexible hours$107.93k - $188.9k
Position Summary Deloitte’s Cyber Defense and Resilience offering is seeking a SIEM Engineer to support security monitoring, detection engineering, and incident analysis across complex enterprise environments. This role will focus on building and optimizing SIEM...Remote work$100k - $110k
...enterprise software architectures that support the bank’s information security operations functions. This role performs feedback and... ...bank. The position serves as a technical resource for security engineering initiatives, applying advanced knowledge to evaluate, build, and...Temporary workRemote workFlexible hours- ...Program Manager, the Web Developer Embeds security across the SDLC for mission-critical... ...~ Hands-on secure software dev, DevSecOps automation, vulnerability remediation... ...WAF management ~3+ Web AppSec / AppSec Engineering / SSDLC ~ Modern web tech incl. .NET...Full time
- ...federal government’s most critical national security and defense priorities, helping protect... ...is seeking a Web Developer Security Engineer to join our team. This position is based... ...detection, incident response, and DevSecOps initiatives. Responsibilities and Duties...Full timeLocal areaRemote workFlexible hours
$320k - $405k
...Security Engineer, Corporate Security San Francisco, CA | Seattle, WA | New York City, NY | Washington, DC About Anthropic Anthropic's mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and...Work at officeVisa sponsorshipFlexible hours$77.6k - $176k
DevSecOps EngineerThe Opportunity:Modern engineering teams rely on secure, automated delivery pipelines and cloud-hosted DevSecOps platforms to deliver software quickly, reliably, and securely. As a DevSecOps Engineer, you will design, build, harden, and operate CI/CD systems...Full timeContract workPart timeWork at officeLocal areaRemote work$99k - $225k
DevSecOps Engineer and SMEThe Opportunity:DevOps engineering requires a specific mix of development, engineering, and communication skills.... ...using Docker and KubernetesExperience integrating automated security checks into CI/CD pipelines such as SAST, SCA, or image scanningExperience...Full timeContract workPart timeWork at officeLocal areaRemote work$180k - $200k
...temporary visa status (e.g., H-1B, L-1, F-1, OPT, CPT, etc.) are not eligible for this role.As a Senior DevSecOps Engineer, you will play a crucial role in integrating security practices into the DevOps pipeline. You will be responsible for designing, implementing, and...Permanent employmentTemporary workH1bVisa sponsorshipWork visa$125k
Computer Technologies Consultants (CTC) is seeking a DevSecOps Engineer to support the Congressional Budget Office (CBO) in Washington, DC.... ...agile software development, DevOps, Test Automation, Cyber Security, and infrastructure solutions. Additionally, we provide Professional...Full timeContract workFor contractorsWork at officeLocal areaRemote work$62k - $141k
DevSecOps EngineerThe Opportunity:As a DevOps engineer, you know how to set up cloud environments and provision computer networking, storage, and virtual networks... ...:Applicants selected will be subject to a security investigation and may need to meet eligibility requirements...Full timeContract workPart timeWork at officeLocal areaRemote work$107.93k - $188k
...Deloitte’s Government & Public Services practice as a DevSecOps-focused Senior Consultant, Enterprise Security. In this role, you will help clients build, secure... ...secrets detectionSupporting cloud and platform engineering teams with secure configuration, infrastructure as...Local area$170k - $193k
As a Sr. DevSecOps Engineer II, you’ll design, implement, and sustain secure, automated CI/CD pipelines and infrastructure across hybrid on‐premises and cloud environments. This role integrates security controls directly into DevOps workflows, enabling continuous compliance...Full timeLocal area$107.93k - $188.9k
Deloitte's Cyber Defense and Resilience offering is seeking a SIEM Engineer to support security monitoring, detection engineering, and incident analysis across complex enterprise environments. This role will focus on building and optimizing SIEM content, improving alert...Remote work$320k - $405k
...Extend device-trust and zero-trust access controls while balancing security protections with employee workflow needs. Build identity... ...software security reviews. Partner with Security, IT, and Engineering on telemetry, detections, shared standards, and secure...Full timeWork at officeVisa sponsorshipFlexible hours$140k - $196k
...Devsecops Automation EngineerCydecor is a premier federal government solutions provider,... ...business platforms. We leverage leading-edge secure systems and software development, backed... ...is seeking a DevSecOps Automation Engineer to implement secure, automated development...Temporary work- ...Modernisation, and Industry-Specific Software Solutions, DXC modernises, secures, and operates some of the world’s most complex technology... ...and New Zealand market, we are enhancing the Security Engineering Team who work within the Secured Infrastructure capacity to deliver...Full timeLocal area
- GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and... ...prime contractors. We are growing our federal presales engineering team and looking for technically exceptional engineers who thrive...Contract workFor contractorsRemote workFlexible hours
$145k - $200k
Washington, D.C.Information Security /Full-time /HybridA World-Changing CompanyPalantir builds the world’s leading software for data-driven... ...the way a real attacker would. As an Offensive Security Engineer, you will test internal applications and infrastructure, chain...Full timeWork experience placementWork at officeRemote workWork from homeRelocation package- ...Responsibilities The U.S. Cybersecurity and Infrastructure Security (CISA) mission is to lead the national effort to protect and enhance... ...as well as its MEOs. This task order is to provide Enterprise Engineering and Operations Support Services (EEOSS) to CISA/OCIO to...Full timeNight shift
$120k - $130k
Job DescriptionEverforth ECS is seeking an Identity Security Engineer to work in our Washington, DC office / remote. The role is contingent upon additional funding.We are seeking a technically experienced Identity Security Engineer to join our security operations division...Work at officeRemote work$135k - $200k
Washington, D.C.Information Security /Full-time /HybridA World-Changing CompanyPalantir builds the world’s leading software for data-driven... ...children, and more.The Role As a Senior Identity Security Engineer on Palantir's Identity Security team, you will own the security...Full timeWork experience placementWork at officeRemote workWork from homeRelocation packageShift work$90k - $150k
...We’re excited about generating creative solutions to ambiguous security requirements. Our mission is deploying software in support of our... ...to Operate (ATO) process.As a Forward Deployed Security Engineer, you support a variety of projects which draw from your wide spectrum...Full timeWork experience placementWork at officeRemote workWork from homeRelocation package$5,000 per month
...Candidates who are not U.S. citizens are not eligible for this role. Imagine One Technology & Management, Ltd. is seeking two (2) Security Engineers. This position is contingent upon award of the associated work and will be performed in Dahlgren, Virginia.The Security...Work at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to DevSecOps Security Engineer. Be the first to apply!
Related searches
- devsecops engineer Washington DC
- information technology security engineer Washington DC
- application security engineer Washington DC
- senior cloud security engineer Washington DC
- security software engineer Washington DC
- sr security engineer Washington DC
- security infrastructure engineer Washington DC
- security engineer Washington DC
- cloud security engineer Washington DC
- network security engineer Washington DC



