Company
Technology
DevSecOpsEngineer
Neural analysis suggests this role is
optimal for Senior candidates.
“DevSecOps Engineer. Skills: DevSecOps, Infrastructure-as-code, CI/CD, Containerization. Maintain infrastructure-as-code repositories. Extend infrastructure-as-code repositories”
Industry & Context.
Federal screening, Federal suitability
What They're Looking For.
Must Have
Five years of experience in DevSecOps, Five years of experience in infrastructure automation, Five years of experience in CI/CD pipeline engineering, Hands-on experience with Terraform, Hands-on experience with OpenTofu, Proficiency with Ansible, Demonstrated experience designing GitHub Actions workflows, Demonstrated experience maintaining GitHub Actions workflows, Working knowledge of Docker, Working knowledge of Kubernetes, Working knowledge of Helm, Working knowledge of container security scanning tools, Familiarity with SAST tools, Familiarity with secrets scanning, Familiarity with policy-as-code frameworks, Familiarity with Git-based workflows, Ability to meet federal screening requirements, Ability to meet federal suitability requirements
Nice to Have
Experience in regulated environments, Experience in federal environments, Familiarity with NIST SP 800-53, Familiarity with FISMA, Familiarity with FedRAMP compliance, Amazon Web Services (AWS) cloud platform experience, Experience with secrets management tools, Python scripting experience, Bash scripting experience
What You'll Do.
Maintain infrastructure-as-code repositories
Extend infrastructure-as-code repositories
Improve infrastructure-as-code repositories
Develop configuration-as-code assets
Maintain configuration-as-code assets
Build GitHub Actions workflows
Maintain GitHub Actions workflows
Improve GitHub Actions workflows
Support containerized delivery
Integrate security practices into pipelines
Participate in stand-ups
Participate in sprint planning
Participate in technical reviews
Participate in peer reviews
How You'll Work.
Team & Collaboration
Stand-ups; Sprint planning; Technical reviews; Peer reviews
Process & Methodology
Sprint planning
Full Job Description
## What Your Day-To-Day Looks Like (Position Responsibilities) Maintain, extend, and improve infrastructure-as-code repositories using Terraform and OpenTofu. Develop and maintain configuration-as-code assets using Ansible. Build, maintain, and improve GitHub Actions workflows for build, test, scanning, and deployment automation. Support containerized delivery using Docker and Kubernetes, including manifests, Helm charts, role-based access control (RBAC), and image hardening and scanning. Integrate security practices into delivery pipelines, including static application security testing (SAST), secrets scanning, policy-as-code, and compliance hardening. Participate in stand-ups, sprint planning, technical reviews, peer reviews, and documentation updates. ## What You Need to Succeed (Minimum Requirements) Five years of experience in DevSecOps, infrastructure automation, or continuous integration and continuous delivery (CI/CD) pipeline engineering. Hands-on experience with Terraform and OpenTofu, including modules, remote state, and workspace management. Proficiency with Ansible, including playbooks, roles, inventories, and secrets handling. Demonstrated experience designing and maintaining GitHub Actions workflows. Working knowledge of Docker, Kubernetes, Helm, and container security scanning tools. Familiarity with SAST tools, secrets scanning, policy-as-code frameworks, and Git-based workflows. Ability to meet federal screening and suitability requirements prior to start. ## Ideally, You Also Have (Preferred Qualifications) Experience in regulated or federal environments. Familiarity with National Institute of Standards and Technology (NIST) Special Publication 800-53, the Federal Information Security Modernization Act (FISMA), and Federal Risk and Authorization Management Program (FedRAMP) compliance requirements. Amazon Web Services (AWS) cloud platform experience. Experience with secrets management tools such as HashiCorp Vault, plus Python and Bash scripting.
Applying for this DevSecOps Engineer role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Lever
- Lever uses a streamlined one-page form — apply in under 5 minutes.
- LinkedIn import works well; review parsed data before submitting.
- The cover letter field is optional but visible to reviewers — use it to differentiate.
- Referral codes from employees can significantly boost visibility of your application.
ANONYMOUS · UNFILTERED
What do employees actually say about this company?
Real rants from real employees. Read before you apply.