Platform Security Engineer
Role details
Job location
Tech stack
Job description
CI/CD Triage Gitlab GitOps Tooling Equities Hardening DevSecOps Operations Management Automation Kubernetes Market Data Observability Ancient History Business Process Security Controls CompTIA Security+ Container Security DevOps Engineering Workflow Management Systems Engineering Software Engineering Prometheus (Software) Software Documentation Compliance Remediation Artificial Intelligence Red Hat Enterprise Linux Bash (Scripting Language) IAT Level II Certification Infrastructure as Code (IaC) Python (Programming Language), At Leidos, we are advancing mission-critical platforms that simulate, interact with, and act on complex technical and business environments. These platforms enable teams to engage with network operations, automate business processes, and gain insight through intent-driven and agent-based systems.
The team operates with a strong belief in "everything as code," using version-controlled artifacts and automation to manage not only infrastructure and software, but also deployment pipelines, security controls, compliance artifacts, and operational workflows.
The DevSecOps Engineer is a hands-on practitioner responsible for building, automating, and sustaining the delivery infrastructure that enables mission-critical software to move fast without compromising compliance. You will actively build and maintain CI/CD pipelines, harden and manage Kubernetes environments, automate security compliance, and leverage AI as a force multiplier across the entire delivery lifecycle. When team capacity demands it, you will contribute directly to feature development - bringing a security-first perspective to application code.
Primary Responsibilities
- Design, implement, and maintain automated CI/CD pipelines that carry code from development through security scanning, compliance validation, and deployment into Navy and DoD environments
- Build and maintain hardened Kubernetes environments aligned to DISA STIG requirements across cloud and restricted network deployment contexts
- Automate security artifact generation including SBOM production, CVE scanning, and continuous compliance validation
- Drive adoption of Infrastructure as Code, GitOps practices, and controls-as-code across the team
- Leverage AI tooling to accelerate pipeline development, vulnerability triage, compliance remediation, and operational documentation
- Partner closely with software engineers, systems engineers, and ISSEs to embed security and compliance requirements from the start of development
- Maintain and evolve deployment infrastructure across multiple secure environments, including cloud and air-gapped or intermittently connected contexts
- Support ATO processes through automated evidence generation, documentation as code, and direct collaboration with the security team
- Establish and promote standards for pipeline design, container security, secrets management, and deployment consistency
- Contribute to feature development when team capacity requires, applying security-first development practices to application code
- Maintain operational documentation including runbooks, deployment guides, and architecture diagrams as version-controlled artifacts, Related Jobs Cloud Platform Engineer TEKsystems Oshkosh, WIRemote JSON CI/CD DevOps Billing Tooling On Prem Jenkins Auditing Power BI IBM VNET Scripting Templates Terraform Operations Leadership Automation Kubernetes Encryption Databricks Scalability Multi-Cloud Digital Twin Communication Accountability Virtualization Cloud Security Azure Firewall Detail Oriented Microsoft Azure Problem Solving Computer Science Active Directory SAP Applications Agile Methodology Docker (Software) Cloud Engineering Disaster Recovery Project Management Windows PowerShell Workday (Software) Business Valuation Wide Area Networks Amazon Web Services DocuSign (Software) Business Requirements Full Stack Development Azure Active Directory Enterprise Integration Artificial Intelligence Business Transformation Internet Of Things (IoT) Critical Illness Insurance Google Cloud Platform (GCP) Platform As A Service (PaaS) Microsoft Azure Expressroute Virtual Private Networks (VPN) Protocol Independent Multicast Role-Based Access Control (RBAC) Troubleshooting (Problem Solving) Cloud Financial Management (FinOps) Puppet (Configuration Management Tool) Azure Command-Line Interface (Azure CLI) SAP Concur (Travel And Invoice Software) Information Technology Infrastructure Library +0 Platform Security Engineer TEKsystems Chandler, AZRemote Linux Auditing CyberArk Terraform HashiCorp Operations Management Resilience Scalability Cloud Services Authentications Active Directory Operating Systems Incident Response Disaster Recovery Influencing Skills Acceptance Testing Business Valuation Financial Services Credential Manager Medical Monitoring Root Cause Analysis Password Management Security Engineering Full Stack Development Production Engineering Artificial Intelligence Business Transformation Configuration Management Critical Illness Insurance Product Family Engineering Standard Operating Procedure Infrastructure as Code (IaC) Role-Based Access Control (RBAC) +0 Kubernetes Architect Leidos Remote CI/CD Istio GitOps On Prem Argo CD Equities DevSecOps Scheduling Leadership Automation
Requirements
- Must have and maintain a Secret security clearance
- BS degree and 4+ years of professional DevSecOps or DevOps engineering experience, 8+ years of total relevant experience.
- Hands-on experience designing and maintaining CI/CD pipelines using GitLab CI; experience with additional pipeline tools a plus
- Experience with Kubernetes administration and hardening in DoD or compliance-driven environments - RKE2 or K3S experience strongly preferred
- Experience implementing DISA STIG compliance in containerized and Linux environments (RHEL or Rocky Linux)
- Proficiency with Infrastructure as Code tooling, particularly Terraform
- Experience with Helm chart authoring and Kubernetes deployment management
- Experience with automated security scanning, SBOM generation, and CVE triage and remediation
- Scripting proficiency in Python or Bash for pipeline and operational automation
- Demonstrated use of AI tooling to accelerate engineering workflows
- Background contributing to application feature development alongside infrastructure work
- Ability to operate independently and manage workload across competing priorities in a small, fast-moving team
Preferred Qualifications
- Experience operating in air-gapped or disconnected network environments
- Experience supporting ATO through automation, documentation, and technical leadership
- Active Security+ certification or equivalent IAT Level II certification
- Experience with secrets management tooling such as Vault, Sealed Secrets, or SOPS
- Familiarity with observability and monitoring tools such as Prometheus or Grafana
- Certified Kubernetes Administrator (CKA) or willingness to obtain upon onboarding
- Experience applying as code" approaches beyond infrastructure (e.g., configuration-as-code, policy-as-code, workflows-as-code, documentation-as-code), Prototyping Market Data Self-Starter Cyber Security Control Systems Ancient History Secret Clearance Command Controls Conceptual Design Rancher (Software) Container Security Workflow Management Technical Leadership Solution Architecture Prometheus (Software) Information Technology Reliability Engineering Integrated Product Team Verbal Communication Skills Internet Protocol Telephony Node.js (Javascript Library) Battle Management Technology Backbone.js (Javascript Library) Troubleshooting (Problem Solving) Software Configuration Management +0
Benefits & conditions
Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits .