DevSecOps Engineer - CI/CD, Containerization & Automation

Wintrio Llc
United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Kubernetes Security Agile Methodology Amazon Web Services Audit Trail Build Automation Microsoft Azure Bash Shell Cloud Computing Cloud Computing Security Cloud Engineering Configuration Management Software Quality
+57 more
CompTIA Security+ Cyber Security Continuous Delivery Continuous Integration DevOps Github Monitoring of Systems Integrated Development Environments Python (Programming Language) Key Management OpenShift Windows PowerShell Scrum Methodology Systems Development Life Cycle Release Management Reliability Engineering Fortify (Software) Prometheus Security Software Software Deployment Software Engineering SonarQube Data Logging Scripting Cloud Platform System Spring Cloud Delivery Pipeline Grafana HybridCloud Infrastructure as Code (IaC) Gitlab Git Cloudformation Containerization Gitlab-ci Git Flow Kubernetes Infrastructure Automation Frameworks Information Technology Deployment Automation Bicep Hashicorp Azure AKS Bitbucket Checkmarx Cloudwatch Terraform Software Version Control Devsecops Azure Resource Manager Docker Security Orchestration, Automation & Response Elk Stack Jenkins Static Application Security Testing Programming Languages Dynamic Application Security Testing

Job description

WINTrio LLC is seeking an experienced DevSecOps Engineer to support Federal IT modernization initiatives by designing, implementing, and maintaining secure CI/CD pipelines, automating infrastructure deployments, and integrating security throughout the software development lifecycle.

This role focuses on cloud-native and hybrid environments, enabling secure, scalable, and automated software delivery while ensuring compliance with Federal cybersecurity and governance requirements. The successful candidate will collaborate with software developers, cloud engineers, cybersecurity teams, and program leadership to streamline application delivery through Infrastructure as Code (IaC), containerization, automation, and DevSecOps best practices., * Design, build, and maintain secure CI/CD pipelines supporting application, infrastructure, and data deployments.

  • Implement Infrastructure as Code (IaC) solutions using Terraform, CloudFormation, ARM Templates, Bicep, or similar technologies.

  • Integrate security controls throughout the software delivery lifecycle, including SAST, DAST, Software Composition Analysis (SCA), container scanning, and secrets management.

  • Automate infrastructure provisioning, application deployments, configuration management, and environment management across AWS and Microsoft Azure environments.

  • Deploy and manage containerized applications using Docker, Kubernetes, Amazon EKS, Azure AKS, or OpenShift.

  • Develop pipeline automation supporting build, testing, deployment, release management, rollback, and recovery processes.

  • Manage source code repositories, branching strategies, and version control using Git-based platforms.

  • Integrate monitoring, logging, alerting, and observability into cloud environments and deployment pipelines.

  • Support compliance requirements through audit logging, traceability, documentation, and secure configuration management.

  • Collaborate with software developers, cloud architects, cybersecurity engineers, and infrastructure teams to ensure secure and reliable software delivery.

  • Support continuous improvement initiatives that enhance automation, deployment efficiency, and operational resilience.

Requirements

The ideal candidate will possess hands-on experience with cloud platforms, CI/CD pipeline engineering, container orchestration, scripting, and security integration across enterprise development environments., * Bachelor’s degree in Computer Science, Information Technology, Software Engineering, Cybersecurity, or a related field, or equivalent professional experience.

  • Minimum five (5) years of experience in DevOps, DevSecOps, Platform Engineering, Site Reliability Engineering (SRE), or automation engineering.

  • Hands-on experience designing and maintaining CI/CD pipelines.

  • Experience working with AWS, Microsoft Azure, or hybrid cloud environments.

  • Experience implementing Infrastructure as Code (IaC) solutions.

  • Experience with scripting or programming languages such as Python, Bash, or PowerShell.

  • Strong understanding of Secure Software Development Lifecycle (Secure SDLC) principles.

  • Strong written and verbal communication skills.

  • Strong analytical, troubleshooting, and problem-solving abilities.

Technical Areas

DevSecOps & CI/CD

  • Continuous Integration (CI)

  • Continuous Delivery (CD)

  • Continuous Deployment

  • Pipeline Automation

  • Release Management

  • Build Automation

  • Deployment Automation

  • Secure SDLC

Infrastructure Automation

  • Infrastructure as Code (IaC)

  • Configuration Management

  • Environment Provisioning

  • Infrastructure Automation

  • Deployment Orchestration

Cloud Platforms

  • AWS

  • Microsoft Azure

  • Hybrid Cloud Environments

  • Cloud-Native Applications

  • Cloud Infrastructure

Containerization & Orchestration

  • Docker

  • Kubernetes

  • Amazon EKS

  • Azure AKS

  • Helm

  • OpenShift

Security Integration

  • Static Application Security Testing (SAST)

  • Dynamic Application Security Testing (DAST)

  • Software Composition Analysis (SCA)

  • Secrets Management

  • Container Security

  • Security Automation

Tools & Platforms

CI/CD Platforms

  • Jenkins

  • GitLab CI/CD

  • GitHub Actions

  • Azure DevOps

Source Code Management

  • Git

  • GitHub

  • GitLab

  • Bitbucket

Infrastructure as Code

  • Terraform

  • AWS CloudFormation

  • ARM Templates

  • Bicep

Security & Code Quality

  • Fortify

  • SonarQube

  • Checkmarx

  • Snyk

Secrets Management

  • HashiCorp Vault

  • AWS Secrets Manager

  • Azure Key Vault

Monitoring & Observability

  • Prometheus

  • Grafana

  • ELK Stack

  • Amazon CloudWatch

  • Azure Monitor

Scripting & Automation

  • Python

  • Bash

  • PowerShell

Compliance & Security

  • NIST Risk Management Framework (RMF)

  • FedRAMP

  • FISMA

  • STIGs

  • Audit Logging

  • Secure Configuration Management

Preferred Certifications

  • AWS Certified DevOps Engineer

  • Microsoft Azure DevOps Engineer Expert

  • Certified Kubernetes Administrator (CKA)

  • Certified Kubernetes Security Specialist (CKS)

  • CompTIA Security+

  • Certified Cloud Security Professional (CCSP)

Preferred Qualifications

  • Experience supporting Federal DevSecOps, CI/CD, or software modernization programs.

  • Experience integrating automated security testing and security tools into CI/CD pipelines.

  • Experience working within Agile, Scrum, or SAFe software development environments.

  • Experience supporting large-scale container orchestration platforms and Kubernetes clusters.

  • Experience supporting cloud-native application development and modernization initiatives.

  • Familiarity with Federal cybersecurity compliance frameworks and secure software delivery requirements.

Benefits & conditions

  • Full-time position.

  • Remote within the United States.

  • Standard business hours Monday through Friday.

  • Occasional travel may be required in support of customer meetings, technical workshops, and program activities.

WINTrio Benefits

  • Healthcare (Medical, Dental, and Vision)

  • Flexible Spending Account (FSA) and Health Savings Account (HSA)

  • 401(k) and Retirement Savings Plan

  • Annual Bonus and Profit Sharing Opportunities

  • Paid Time Off (PTO) and Vacation

  • Employee Assistance Program (EAP)

  • Life, Personal, and Voluntary Disability Insurance

Growth Opportunities

There is ample opportunity to grow in multiple dimensions, including DevSecOps, cloud engineering, platform engineering, cybersecurity, automation, Artificial Intelligence (AI), Machine Learning (ML), cloud modernization, and enterprise digital transformation. We are a completely employee-driven company, and our continued success is built on the talent, dedication, and innovation of our team members.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.wintrio.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:32 min

Embracing DevSecOps and automating the software development lifecycle

Mathias Tausig · LIVE

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · WWC Europe 2026

2:56 min

Provisioning a secure container infrastructure with Bicep

Matthias Falkenberg +1 · WWC 2022

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

4:09 min

Selecting infrastructure tools and determining proper abstraction layers

Alayshia Knighten Alayshia Knighten · WWC 2024

Videos

See all

Related articles

See all