> Markdown version of [/jobs/ext/1829227-cleared-it-positions-devsecops-engineer](https://www.wearedevelopers.com/jobs/ext/1829227-cleared-it-positions-devsecops-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cleared IT Positions - DevSecOps Engineer - **Company:** Virtual, Inc. - **Location:** United States - **Experience:** Experienced - **Salary:** $80,000.0 - $145,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Artificial Intelligence, Systems Engineering, Bash Shell, Linux, DevOps, Monitoring of Systems, Python (Programming Language), Key Management, Linux System Administration, Red Hat Enterprise Linux, Prometheus, Security Software, Policy as Code, Scripting, Delivery Pipeline, Grafana, Gitlab-ci, Kubernetes, Terraform, Data Pipelines, Devsecops, Vulnerability Analysis - **Published:** July 17, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9039719/cleared-it-positions-devsecops-engineer ## About the Role * BS degree and 4+ years of professional DevSecOps or DevOps engineering experience * Hands-on experience designing and maintaining CI/CD pipelines using GitLab CI; experience with additional pipeline tools a plus * Experience with Kubernetes administration and hardening in DoD or compliance-driven environments - RKE2 or K3S experience strongly preferred * Experience implementing DISA STIG compliance in containerized and Linux environments (RHEL or Rocky Linux) * Proficiency with Infrastructure as Code tooling, particularly Terraform * Experience with Helm chart authoring and Kubernetes deployment management * Experience with automated security scanning, SBOM generation, and CVE triage and remediation * Scripting proficiency in Python or Bash for pipeline and operational automation * Demonstrated use of AI tooling to accelerate engineering workflows * Background contributing to application feature development alongside infrastructure work * Ability to operate independently and manage workload across competing priorities in a small, fast-moving team * Must possess and maintain an active Secret security clearance or above * Please note that pursuant to a government contract, this specific position requires U.S. citizenship status. Preferred Qualifications: * Experience operating in air-gapped or disconnected network environments * Experience supporting ATO through automation, documentation, and technical leadership * Active Security+ certification or equivalent IAT Level II certification * Experience with secrets management tooling such as Vault, Sealed Secrets, or SOPS * Familiarity with observability and monitoring tools such as Prometheus or Grafana * Certified Kubernetes Administrator (CKA) or willingness to obtain upon onboarding * Experience applying "as code" approaches beyond infrastructure (e.g., configuration-as-code, policy-as-code, workflows-as-code, documentation-as-code) What is Important to Us: * You are an excellent communicator in writing and speaking. * You have the ability to work independently but also value teamwork. * Your problem-solving skills are excellent. * You are looking for a job where performance appraisals occur regularly, and you look forward to advancing your career. * You seek a community of virtue-centered co-workers and clients. ## Description The DevSecOps Engineer is a hands-on practitioner responsible for building, automating, and sustaining the delivery infrastructure that enables mission-critical software to move fast without compromising compliance. You will actively build and maintain CI/CD pipelines, harden and manage Kubernetes environments, automate security compliance, and leverage AI as a force multiplier across the entire delivery lifecycle. When team capacity demands it, you will contribute directly to feature development - bringing a security-first perspective to application code., * Design, implement, and maintain automated CI/CD pipelines that carry code from development through security scanning, compliance validation, and deployment into Navy and DoD environments * Build and maintain hardened Kubernetes environments aligned to DISA STIG requirements across cloud and restricted network deployment contexts * Automate security artifact generation including SBOM production, CVE scanning, and continuous compliance validation * Drive adoption of Infrastructure as Code, GitOps practices, and controls-as-code across the team * Leverage AI tooling to accelerate pipeline development, vulnerability triage, compliance remediation, and operational documentation * Partner closely with software engineers, systems engineers, and ISSE's to embed security and compliance requirements from the start of development * Maintain and evolve deployment infrastructure across multiple secure environments, including cloud and air-gapped or intermittently connected contexts * Support ATO processes through automated evidence generation, documentation as code, and direct collaboration with the security team * Establish and promote standards for pipeline design, container security, secrets management, and deployment consistency * Contribute to feature development when team capacity requires, applying security-first development practices to application code * Maintain operational documentation including runbooks, deployment guides, and architecture diagrams as version-controlled artifacts ## Related Videos - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [5 steps for running a Kubernetes environment at scale](https://www.wearedevelopers.com/videos/88-5-steps-for-running-a-kubernetes-environment-at-scale) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [#90DaysOfDevOps - The DevOps Learning Journey](https://www.wearedevelopers.com/videos/548-90daysofdevops-the-devops-learning-journey) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Find a Developer Job: 12 Best Job Sites For Developers](https://www.wearedevelopers.com/magazine/165-find-a-developer-job-12-best-job-sites-for-developers) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)