Location: Fort Meade, MD or Chambersburg, PA
Schedule: Hybrid, 4 days onsite per week
Position Overview
The DevSecOps Engineer will provide security engineering expertise to system owners, security teams, architects, and software development teams throughout the Software Development Life Cycle (SDLC). This role will focus on integrating cybersecurity requirements and controls directly into Agile development and CI/CD processes, helping teams identify and address security risks earlier in the development lifecycle.
The DevSecOps Engineer will work closely with technical and security stakeholders to securely move applications and capabilities from initial concept through production.
Key Responsibilities
- Embed cybersecurity engineering practices into Agile software development and modernization initiatives.
- Integrate security requirements and controls throughout the SDLC and CI/CD pipelines.
- Apply DevSecOps and shift-left security practices to identify and remediate vulnerabilities earlier in development.
- Implement and support automated security testing within CI/CD workflows.
- Participate in requirements discussions, design sessions, sprint planning, and other development lifecycle activities.
- Translate RMF, NIST SP 800-53, DoD cybersecurity policies, STIGs, and SRGs into actionable technical and development requirements.
- Partner with developers, architects, system owners, ISSMs, and ISSOs to develop achievable technical security controls prior to formal assessments.
- Provide threat-informed security guidance for legacy, modernized, and cloud-native applications.
- Support secure development of APIs, microservices, containerized workloads, and other modern application architectures.
- Help development teams remediate vulnerabilities while maintaining functionality and delivery objectives.
- Provide recommendations around authentication, encryption, network segmentation, application security, and other technical controls.
- Communicate security findings, technical risks, remediation recommendations, and implementation approaches to both technical and government stakeholders.
- Manage security engineering activities across multiple projects and development sprints.
Required Qualifications
- Bachelor's degree and 10+ years of related experience.
- Must hold at least one qualifying DoD 8140 Work Role 652 Security Architect certification, such as SecurityX/CASP+ CE, CCSP, Cloud+, CISSP, CSSLP, CISM, CISSP-ISSAP, CISSP-ISSIP, or GSEC.
- Active Top Secret clearance required.
- Must live within commuting distance of Fort Meade, MD or Chambersburg, PA and be able to work onsite 4 days per week.
- Experience integrating cybersecurity requirements into Agile SDLC environments.
- Hands-on experience working with CI/CD pipelines.
- Practical experience implementing DevSecOps and shift-left security practices.
- Experience incorporating automated security testing tools into software development processes.
- Strong knowledge of RMF, NIST SP 800-37, and NIST SP 800-53.
- Experience applying DoD STIGs and SRGs.
- Ability to translate security and compliance requirements into specific technical controls and development tasks.
- Understanding of modern application architectures and cloud-native development.
- Strong collaboration skills across cybersecurity, engineering, architecture, and software development teams.
- Strong written and verbal communication skills.
- Ability to manage multiple development efforts and sprints in a fast-paced environment.