Cybersecurity Engineer – DevSecOps
Core
Integrating cybersecurity throughout the software development and delivery lifecycle within a Department of Defense and Department of the Navy environment, focusing on secure software delivery, vulnerability management, and compliance.
Role type
Senior IC DevSecOps Engineer
Builds
Secure software delivery pipelines and containerized workloads for DoD/DoN systems
Domain
Defense / Cybersecurity
Required skills
DevSecOps, CI/CD pipeline security, SAST/DAST, container security, vulnerability management, GitLab security, RMF compliance, DISA STIGs/SRGs, NeuVector, Sonatype
Preferred skills
DoD/DoN environment experience, RAISE methodology, Common Criteria/NIAP evaluation
Technologies
GitLab, NeuVector, Sonatype, SAST, DAST
Responsibilities
Conduct code and container vulnerability assessments using DISA STIGs and SRGs; Assess operating system security configurations; Perform cybersecurity assessments, audits, and risk analyses; Integrate security policies and controls within CI/CD pipelines; Serve as GitLab security reviewer and approver for merge requests; Review GitLab SAST, dependency, secret detection, and container scanning results; Track cybersecurity findings through closure; Provide cybersecurity oversight for containerized workloads using NeuVector; Collaborate with engineering teams to investigate findings and refine security policies; Prepare RMF artifacts and Memoranda of Agreement; Evaluate cybersecurity products for alignment with DoD/DoN requirements.
Seniority
Senior, hands-on IC