Skip to content

Open nowPosted 6 days ago

DevSecOps Engineer (TS/SCI)

Vantor128 open roles

Pay
$116,000 – $154,000 a year
Where
Herndon, VA
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowDevSecOps Engineer (TS/SCI)Vantor · Herndon, VA
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Vantor's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.0% of postings close within 7 days. Measured by our own scanner across the market. Vantor postings stay open a median of 31 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.5%3 days
  3. 8.0%7 days
  4. 15.0%14 days
  5. 34.1%30 days
This job: posted 6 days ago

Vantor median: 31 days open

The posting

Vantor is forging the new frontier of spatial intelligence, helping decision makers and operators navigate what’s happening now and shape what’s coming next. Vantor is a place for problem solvers, changemakers, and go-getters—where people are working together to help our customers see the world differently, and in doing so, be seen differently. Come be part of a mission, not just a job, where you can: Shape your own future, build the next big thing, and change the world.

To be eligible for this position, you must be a U.S. Citizen. This position requires an active U.S. Government security clearance, applicants who do not currently hold the required clearance will not be eligible for consideration. Employment for cleared roles is contingent upon verification of clearance status.



Export Control/ITAR: Certain roles may be subject to U.S. export control laws, requiring U.S. person status as defined by 8 U.S.C. 1324b(a)(3).

Please review the job details below.

Vantor is seeking a Mid-Level DevSecOps Engineer located in Herndon, VA, to support the development, integration, and cybersecurity compliance of intelligence capabilities in Development and Production environments. This is a software engineering-focused DevSecOps role. The primary focus is designing, coding, testing, and maintaining software and automation tools that streamline Cyber Security workflows and improve the reliability of our platforms. We are looking for a candidate with a software development background who can build scalable, reliable systems and developer tools, and contribute to DevSecOps pipelines that integrate and deploy components across multiple networks into private cloud infrastructures hosted for our government customer.

As a Vantor team member, you will closely support our mission partners, and your work will have direct mission impact. You will work with DevSecOps engineers, software developers, infrastructure technicians, and cybersecurity professionals to use open-source technology to create and maintain the full stack of a High-Performance Computing (HPC) system that hosts applications for thousands of users.

About Us:

  • We are a multi-faceted technical team with expertise spanning the full stack of cloud computing technologies including systems administration, DevOps, cybersecurity, software development, and systems engineering that builds and maintains software applications backed by a self-managed cloud infrastructure with a true big-data footprint (over 10 petabytes)
  • Our diverse background of experience in mission support and technology development and operations serves as a catalyst to solve unique and challenging intelligence problems in support of special operations analysts and their on-going activities.
  • Prototyping and frequent, iterative feedback are core to our delivery approach, anchored by a need to work quickly in support of our missions.

Principal Responsibilities:

Software Engineering and Automation

  • Build and maintain custom command-line tools, APIs, and dashboards that reduce manual effort and streamline Cyber Security and developer workflows.
  • Design, write, test, and maintain clean, production-quality code (e.g., Python, Go, Java, or similar) to automate Cyber Security workflows.
  • Convert manual Cyber Security, compliance, infrastructure, and developer workflows into automated, repeatable software workflows.
  • Build automation for security analysis, vulnerability correlation, compliance tracking, remediation workflows, and security exception processes.
  • Develop custom dashboards and reporting applications that aggregate data from multiple systems and provides actionable visibility into security, compliance, infrastructure, and software delivery.
  • Participate in code reviews.
  • Troubleshoot complex application and automation failures by analyzing source code, logs, APIs, infrastructure, and system behavior.

DevSecOps and Software Delivery

  • Deploy and manage highly available applications to ensure system reliability and scalability.
  • Implement and maintain HashiCorp Nomad and Kubernetes clusters for workload orchestration.
  • Execute DNS configuration, management, and performance tuning for enterprise-grade systems.
  • Develop and implement Infrastructure-as-Code (IaC) solutions using tools like Terraform, Ansible, or similar.
  • Build and manage multiple CI/CD pipelines with GitLab or equivalent tools to automate deployments and streamline development workflows for rapid development and integration
  • Perform system monitoring, logging, and troubleshooting to proactively identify and resolve issues.
  • Automate security testing and monitoring within the DevOps workflows using ACAS and Trivy.
  • Analyze cybersecurity scan findings and work with the cybersecurity team to identify false positives.
  • Assist the cybersecurity team in assembling the required Body of Evidence for False Positive exceptions.
  • Assist the cybersecurity team in assembling the required Body of Evidence to submit containerized and non-containerized software packages for enterprise software approval.
  • Integrate static code analysis tools such as GitLab SAST, Fortify, or SonarQube and other security mechanisms into CI/CD pipelines.
  • Build and maintain software tools that automate cybersecurity analysis and correlation workflows as compliance requirements evolve.
  • Perform cybersecurity remediation on DevSecOps-managed virtual machines, including OS patching, OS STIG implementation, and software package updates.
  • Build, maintain, and monitor configuration management of release products.
  • Troubleshoot and resolve issues in networks, automation pipelines, and infrastructure.

Minimum Requirements:

  • Must have an active TS/SCI clearance and be willing and able to pass a CI polygraph.
  • Must be able and willing to work 40 hours per week in a SCIF in Herndon, Virginia.
  • At least 3 years of industry experience in software development or software engineering.
  • At least 5 years of industry experience in DevSecOps, with a bachelor’s degree in Computer Science, Information Systems, or a related field; or a master’s degree and at least 3 years of relevant experience.
  • Demonstrated professional software development experience is required. Candidates must be able to design, write, test, debug, and maintain software using at least one language such as Python, Go, Java, C#, or similar. Experience building automation tools, APIs, or applications is central to this role.
  • Strong expertise in cloud environments, including deployment, optimization, and troubleshooting.
  • Proven track record in building and operating Cloud Native Applications using tools like Kubernetes and Docker.
  • In-depth experience with IaC tools such as Terraform, Ansible, or equivalent.
  • Solid experience in creating and managing CI/CD build pipelines using GitLab or similar tools (e.g., Jenkins, Azure DevOps).
  • Strong software automation skills using Python, Bash, or equivalent languages; Python or comparable application development experience is required.
  • Excellent problem-solving skills with attention to detail and the ability to thrive in a fast-paced environment.
  • Experience applying security best practices in DevSecOps pipelines (e.g., Trivy, Grype, GitLab SAST, or SonarQube).
  • Familiarity with monitoring tools like Prometheus, Grafana, or ELK Stack.
  • Strong knowledge of networking and load balancing technologies.
  • Experience with source control tools such as Git, including collaborative development workflows.
  • Experience with automated deployment technologies such as Cloud Formation, Ansible, Puppet or Chef.
  • Experience deploying and maintaining open-source and custom applications.
  • Moderate Linux system administration experience (Red Hat, Rocky Linux, AlmaLinux, or similar).
  • Working knowledge of Linux and Windows operating systems, web services, and SQL databases.
  • Experience working in an Agile environment.

Desired Skills:

  • Security+ or comparable certification for privileged user access.
  • Experience with distributed processing methods and tools, such as REST APIs, microservices, IaaS/PaaS services.
  • Experience developing and deploying web services.
  • Experience in implementing Docker STIGs
  • Experience with CONMON cybersecurity remediation.
  • RHCSA/LPIC 1/2, CKA, or Docker Certified Associate certification.

#cjpost

#LI-CJ1

#LI-Onsite

Pay Transparency: To support pay transparency, Vantor includes salary ranges in all U.S. job postings. Starting pay for this role will fall within the listed range and will be based on factors such as experience, qualifications, skills, location, and market conditions. Candidates who meet the minimum requirements for the role should not expect to receive compensation at the top of the range. The listed range reflects the expected pay for this position, and final offers will be determined based on each candidate’s experience, expertise, and alignment with the role.

● The base pay for this position within the Washington, DC metropolitan area is: $116,000.00 - $154,000.00 - $169,400.00 annually.

For all other states, we use geographic cost of labor as an input to develop market-driven ranges for our roles, and as such, each location where we hire may have a different range.

Benefits: Vantor offers a competitive total rewards package that goes beyond the standard, including a robust 401(k) with company match, mental health resources, and unique perks like student loan repayment assistance, adoption reimbursement and pet insurance to support all aspects of your life. You can find more information on our benefits at: https://www.Vantor.com/careers

The application window is three days from the date the job is posted and will remain posted until a qualified candidate has been identified for hire. If the job is reposted regardless of reason, it will remain posted three days from the date the job is reposted and will remain reposted until a qualified candidate has been identified for hire.

The date of posting can be found on Vantor's Career page at the top of each job posting.

To apply, submit your application via Vantor's Career page.

EEO Policy: Vantor is an equal opportunity employer committed to an inclusive workplace. We believe in fostering an environment where all team members feel respected, valued, and encouraged to share their ideas. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, sex, gender identity, sexual orientation, disability, protected veteran status, age, or any other characteristic protected by law.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Vantor's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Vantor's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Vantor's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.