Skip to content

Open nowPosted 23 hours ago

DevSecOps Engineer

Jobgether4,233 open roles

Where
US
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowDevSecOps EngineerJobgether · US
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Jobgether's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. Jobgether postings stay open a median of 4 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.1%30 days
This job: posted 23 hours ago

Jobgether median: 4 days open

The posting

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a DevSecOps Engineer based in the United States.

This role supports a mission-critical federal DevSecOps program focused on modernizing supply chain and logistics solutions. You’ll embed security directly into CI/CD pipelines, ensuring that applications are protected throughout the software development lifecycle. The position combines hands-on pipeline engineering, cloud security, vulnerability management, and compliance automation. You’ll collaborate closely with Agile delivery teams, developers, security leaders, and federal stakeholders to turn security requirements into practical controls. Your work will help maintain secure, compliant systems and support continuous authorization in complex cloud environments. You’ll also contribute to secure coding practices, incident response, reusable security solutions, and the ongoing evolution of DevSecOps capabilities.

Accountabilities:

  • Embed Guardrails-as-Code and automated security controls across CI/CD pipelines, including SAST, DAST, SBOM generation, vulnerability scanning, and policy gates.
  • Manage secrets, cryptographic code signing, artifact integrity, hardened container images, and automated configuration drift detection.
  • Triage, track, and remediate security vulnerabilities within defined deadlines, ensuring critical and high-risk findings are addressed before production.
  • Automate security evidence collection to support Continuous Assessment and Authorization (ATO), NIST RMF activities, and VA/FedRAMP compliance.
  • Implement Zero Trust principles, identity and access controls, logging, encryption, network segmentation, and cloud security measures across AWS, Azure, and VA Enterprise Cloud environments.
  • Mentor development teams on secure coding and security design practices, including the review and validation of AI-generated code and test scripts.
  • Support security incident response through component isolation, forensic activities, rapid reporting, and after-hours escalation rotations.
  • Contribute to DevSecOps strategies for proposals, security performance metrics, technical interviews, reusable pipeline security templates, cybersecurity communities, and corporate quality initiatives.
  • 7+ years of experience in IT security or DevSecOps, including at least 4 years integrating continuous security controls into CI/CD pipelines within federal Agile/SAFe environments.
  • 3+ years of hands-on experience with pipeline security automation, including SAST/DAST, container scanning, secrets management, and SBOM generation using standards such as SPDX or CycloneDX.
  • Strong experience automating infrastructure hardening and configuration compliance with tools such as Ansible and Terraform against DISA STIG and CIS benchmarks.
  • Proven knowledge of NIST Risk Management Framework (RMF), Authority to Operate (ATO) processes, POA&Ms, and automated continuous control evidence collection.
  • Extensive experience securing AWS, Azure, and VA Enterprise Cloud environments, including IAM, encryption, network segmentation, and related cloud security controls.
  • Strong vulnerability management experience, with the ability to partner directly with development teams to investigate, prioritize, and resolve findings.
  • Experience with security monitoring and logging platforms such as Splunk, as well as identity and access technologies including HashiCorp Vault, mutual TLS, ICAM, and PIV.
  • Ability to support secure development across Java, .NET, Python, and legacy MUMPS environments, with experience embedding automated Section 508 accessibility testing into pipelines.
  • Experience with VA supply chain systems, HL7/FHIR healthcare APIs, one-hour incident response requirements, or AI-generated code validation is highly preferred.
  • Bachelor's degree in Cybersecurity, Computer Science, Computer Engineering, Information Systems, or a related field; a master's degree is preferred.
  • Required certification: ISC2 CISSP or Security+. Additional preferred certifications include AWS Solutions Architect Associate, AWS Developer Associate, Azure Solutions Architect, Azure Developer Associate, Red Hat Certified Specialist in Ansible Automation, or Red Hat Certified Architect.
  • Ability to obtain a Tier 2 / Moderate Risk Background Investigation and VA PIV credential.
  • Suggested salary range of $161,000–$176,000, with actual compensation based on skills, qualifications, experience, and location.
  • Certain positions may be eligible for additional compensation, including bonuses.
  • Comprehensive healthcare benefits above industry standards.
  • Remote working options for eligible employees.
  • Paid time off and paid holidays.
  • 401(k) matching.
  • Healthcare Savings Account and Flexible Spending Account options.
  • Paid life insurance and short- and long-term disability coverage.
  • Training, professional development, and certification opportunities.
  • Tuition reimbursement and Employee Assistance Program.
  • Military leave and additional employee benefits.
  • Remote position within the continental United States, with the option to work from Rockville, Maryland.
  • Up to 10% travel.
  • Opportunities to work on mission-driven federal technology initiatives while developing long-term career and technical expertise.

How Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Jobgether's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Jobgether's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Jobgether's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.