DevSecOps Engineer (Remote)
A.C. Coy · Falls Church, VA
View and Apply ↗
Opens the original job posting in a new tab.
Job description
Overview
- Tier One Technologies is seeking a DevSecOps Engineer to strengthen software development lifecycle by embedding security practices into every stage of delivery for our US Government client.
- This remote contract-to-hire position will be originated in Falls Church, VA.
- SELECTED CANDIDATES WITHOUT REQUIRED CLEARANCE WILL BE SUBJECT TO A FEDERAL GOVERNMENT BACKGROUND INVESTIGATION TO RECEIVE IT.
Responsibilities
- Working across development, operations, and security teams to ensure applications and infrastructure are secure, compliant, and resilient, while maintaining speed and efficiency in deployment.
- Lead the evolution of the software delivery lifecycle by embedding security into every stage of the CI/CD pipeline.
- Integrate existing automation frameworks with AI-based solutions to improve coverage, reliability, and efficiency.
- Ensure that all AI scripts and programs are fully executable on postal-issued laptops within approved security and environment constraints.
- Perform Static and Dynamic Application Security Testing (SAST/DAST), integrated into pipelines.
- Collaborate with software developers and IT staff to oversee code releases and deployments.
- Design and implement scalable cloud architecture using platforms such as AWS, Google Cloud Platform, or Azure.
- Manage containerization technologies such as Docker and orchestration tools like Kubernetes.
- Utilize Infrastructure as Code (IaC) tools like Ansible for automated provisioning of infrastructure.
- Ensure system reliability through monitoring, logging, and alerting using tools like Jenkins and Git.
- Develop RESTful APIs and microservices to facilitate communication between applications.
- Maintain databases including MySQL, PostgreSQL, Oracle, and Microsoft SQL Server.
- Participate in Agile development processes to improve software delivery cycles.
- Troubleshoot issues across the application stack from front-end to back-end services.
- Manage and secure cloud environments (AWS, Azure, GCP) and containerized workloads (Docker, Kubernetes).
- Implement Infrastructure as Code (IaC) with secure configurations using Terraform, Ansible, or CloudFormation.
- Monitor and respond to security incidents, leveraging SIEM tools and observability platforms.
- Ensure compliance with industry standards and regulations (ISO 27001, NIST, GDPR, HIPAA, PCI DSS).
- Provide training and guidance to teams on DevSecOps best practices.
Qualifications
- Bachelor’s degree in Computer Science, Cybersecurity, or related field.
- 13+ years of overall IT experience.
- 10+ years of experience managing software releases across DEV, SIT, CAT/UAT, and PROD environments, supporting major and minor releases, patches, upgrades, and production deployments.
- 10+ years of experience providing release support, code promotion, deployment monitoring, and production data fixes to ensure application stability and successful software delivery.
- 5+ years of experience designing, implementing, and maintaining secure CI/CD pipelines with integrated automated security testing and compliance controls.
- 3+ years of experience leveraging GitHub Copilot and other AI-enabled tools to automate manual processes, improve developer productivity, and streamline software delivery workflows.
- 3+ years of experience implementing and enforcing Secure Coding Standards throughout the software development lifecycle.
- Strong knowledge of integrating application security testing tools, including SAST, DAST, and Software Composition Analysis (SCA), into CI/CD pipelines and development workflows.
- Proven ability to collaborate with development teams to promote secure coding practices and remediate security vulnerabilities early in the SDLC.
- Hands-on experience with Jenkins, GitLab CI/CD, Azure DevOps, and/or CircleCI to automate builds, deployments, testing, and embedded security validation.
- Deep knowledge of cloud security services and best practices across AWS, Microsoft Azure, and Google Cloud Platform (GCP).
- Hands-on experience securing containerized applications and orchestration platforms, including Docker and Kubernetes.
- Proficiency in Python and Java for developing automation scripts, security tooling, and CI/CD pipeline integrations.
- Familiarity with Terraform, Ansible, or CloudFormation, with emphasis on secure configurations.
- Excellent communication skills.
- Be able to pass a drug screening, criminal history, and credit checks.
- Must be a US Citizen or have permanent residence status (Green Card).
- Must be able to obtain a Position of Public Trust Clearance.
- Must have lived in the United States for the past 5 years.
- Cannot have more than 6 months travel outside the United States within the last five years. Military Service excluded. (Exception does not include military family members.)