> Markdown version of [/jobs/ext/1471769-mid-level-devsecops-sme-information-system-security-engineer](https://www.wearedevelopers.com/jobs/ext/1471769-mid-level-devsecops-sme-information-system-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Mid-Level DevSecOps SME / Information System Security Engineer - **Company:** Dark Wolf Solutions - **Location:** Herndon, VA, United States - **Experience:** Experienced - **Salary:** $130,000.0 - $140,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Amazon Web Services, Burp Suite, Cyber Security, Information Systems, Information Security Management, Python (Programming Language), Network Architecture, Ansible, Prometheus, Zero Trust Network Access, Software Engineering, Product Software Implementation Methods, SonarQube, Data Logging, Scripting, Google Cloud, Cloud Platform System, Istio, Grafana, Containerization, Gitlab-ci, Kubernetes, Information Technology, Tenable Nessus, Restful APIs, Devsecops, Docker, Vulnerability Analysis, Golang, Programming Languages - **Published:** July 28, 2026 - **Apply:** https://www.dice.com/job-detail/563324df-203b-4142-be81-533e7b4a0bdf ## About the Role * 5+ years of experience in IT security, information assurance, or DevSecOps engineering * Background in secure software development with a proficiency in a scripting or programming language (e.g., Python, Golang) with an emphasis on automation and a foundational knowledge of how to interact with REST APIs * Experience and enjoyment in working directly with customers to improve cyber security posture * Experience authoring and maintaining systems security documentation and hardening configurations for modern cloud environments * Experience in generating appropriate security documentation to receive proper authorization from customer security personnel, and correcting security shortfalls as they are identified through customer-sponsored reviews * Strong understanding of Kubernetes Administration and a deep foundational knowledge of containerization (Docker and similar technologies) * Understanding of the cyber environment and threats of our cyber adversaries, specifically regarding cloud and supply-chain vulnerabilities * Possesses strong technical skills and analytic ability * Bachelor's Degree in Computer Science, Cyber Security, or a related technical field * IAT Lvl 2 certification (e.g., Security+) * ship and active TS/SCI clearance Desired Qualifications: * Previous experience as an ISSE / ISSM in a DoD or federal environment * Relevant technical certifications such as Certified Kubernetes Administrator (CKA), Certified Kubernetes Security Specialist (CKS), or cloud-specific professional DevOps/Security certifications ## Description Dark Wolf is looking for a Mid-Level DevSecOps SME / Information System Security Engineer (ISSE) to join a collaborative, dynamic team in a fast-paced, innovative mission environment. This position will work hand-in-hand with the customer team as well as external satellite software development contractors. The successful candidate will have a strong understanding of information security principles, as well as experience in software development, security engineering, risk management, and compliance. The specialist must be able to analyze complex technical issues and develop effective technical solutions. This role can be supported at a hybrid capacity in Colorado Springs, CO or Herndon, VA. Responsibilities include but are not limited to: * Conducting technical evaluations of information systems design, containerized applications, and cloud architectures (AWS or Google Cloud Platform), and information security aspects and accreditation. * Performing vulnerability assessments using automated software, pipeline, and container scanning tools including SonarQube, Snyk, NeuVector, and OWASP ZAP. * Reviewing requests for software installation and conduct technical risk assessments on software implementation, specifically within Kubernetes clustered environments. * Coordinating and tracking security action requests and report status to senior managers, leveraging GitOps workflows and automation tooling like ArgoCD and GitLab CI/CD. * Analyzing, modifying when necessary, and maintaining the client's certification to field security approvals (continuous ATO) by implementing DISA STIGs through automated Ansible Playbooks and hardened Dockerfiles. * Conducting and analyzing auditing requirements continuously, implementing and monitoring logging, metrics, and tracing stacks via Grafana, Loki, Prometheus, Tempo, and Alloy. * Enforcing zero-trust network architectures and traffic management within containerized environments using Istio or similar service meshes. ## Related Videos - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)