> Markdown version of [/jobs/ext/1914175-software-engineer](https://www.wearedevelopers.com/jobs/ext/1914175-software-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Software Engineer - **Company:** Helsing Inc. - **Location:** Washington, DC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Bash Shell, Cloud Computing, CompTIA Security+, Cyber Security, Information Systems, Computer Programming, Continuous Delivery, Continuous Integration, Distributed Systems, Federal Information Processing Standards (FIPS), Integrated Development Environments, Internet Security, Information Systems Security Architecture Professional, Python (Programming Language), Role-Based Access Control, Security Information and Event Management, Software Engineering, System Programming, Workflow Management Systems, Reinforcement Learning, Policy as Code, Data Processing, Scripting, Graphics Processing Unit (GPU), Data Classification, Delivery Pipeline, Kubernetes Helm Charts, Gitlab, Kubernetes, Information Technology, Terraform, Devsecops, Surface Modeling, Vulnerability Analysis, Artifactory, Programming Languages - **Published:** August 4, 2026 - **Apply:** https://www.careerbuilder.com/job-details/software-engineer-devsecops-washington-dc--760c77a3-0b8c-4b35-96f1-99f6455b958c ## About the Role * Have 5+ years of experience in DevSecOps, security engineering, or infrastructure engineering with a security focus * Have a Bachelor''s degree in Computer Science, Engineering, Cybersecurity, or a related field * Have deep experience with Kubernetes - deployment, networking, RBAC, pod and cluster security, and operational troubleshooting * Are proficient with ArgoCD or similar GitOps tooling for managing Kubernetes workloads at scale * Have strong experience writing and maintaining Helm charts * Are proficient in Python and Bash, with experience automating security and compliance workflows * Understand software supply chain security, including container image hardening, FIPS-validated cryptography, vulnerability scanning, SBOM, and artifact signing * Have hands-on experience implementing security controls from frameworks like NIST 800-171, NIST 800-53, or CMMC * Are comfortable with CI/CD pipeline design, particularly building in security gates, policy-as-code, and automated compliance checks * Have working knowledge of AWS and can collaborate effectively on infrastructure decisions * Are a U.S. citizen eligible to obtain a security clearance Nice to have * Experience with Go or other systems programming languages * Experience shepherding systems through an ATO process * Familiarity with DISA STIGs and the Risk Management Framework (RMF) * Familiarity with Terraform and infrastructure-as-code for cloud resources * Experience with Nix or NixOS * Experience with SIEM platforms (e.g., Elastic) and security monitoring/incident response * Experience securing and deploying ML/AI workloads - GPU environments, training pipelines, data classification * Red teaming or penetration testing experience * Certifications such as CKS, Security+, or CISSP * Experience in defense, intelligence, or other regulated environments, Aerospace and Defense, Amazon Web Services (AWS), Architectural Services, Artificial Intelligence (AI), Bash Scripting, CISSP - Certified Information Systems Security Professional, Cloud Computing, CompTIA Security+, Computer Science, Computer Security, Continuous Deployment/Delivery, Continuous Integration, Cryptography, Defense Information Systems Agency (DISA), Defense Intelligence, Distributed Computing, Federal Information Processing Standards (FIPS), GPU (Graphics Processing Unit), Government Contracts, Incident Response, Insurance, Internet Security, Leading Edge Technology, Machine Tool, Maintain Compliance, Penetration Testing, Problem Solving Skills, Product Engineering, Programming Languages, Python Programming/Scripting Language, Regulatory Compliance, Reinforcement Learning, Risk Management Framework (RMF), Security Clearance, Security Information and Event Management (SIEM), Security Infrastructure, Security Monitoring, Security Policy, Software Engineering, Supply Chain, Surface Modeling, Systems/Internals Programming, Team Player, Testing, Threat Modeling, U.S. National Institute of Standards and Technology (NIST), United States Citizen, Unmanned Aircraft Systems (UAS), Vulnerability Scanners, Writing Skills ## Description You will join the Platform Engineering team as a security-focused engineer responsible for embedding security into every layer of our developer platform and software delivery pipeline. You will own the security posture of our development environment - ensuring CMMC Level 2 compliance, hardening our software supply chain, and implementing the controls required for product teams to achieve ATO against NIST and other cybersecurity frameworks. You will work closely with platform and product engineers to build secure CI/CD pipelines, enforce policy-as-code, and maintain the shared infrastructure that all teams depend on. This role combines hands-on engineering with deep security expertise: you are not just auditing compliance, you are building the systems that make compliance automatic. The day-to-day * Deploying, updating, and securing Kubernetes workloads through ArgoCD and GitOps workflows * Building and maintaining secure CI/CD pipelines that enforce policy, scan for vulnerabilities, and produce auditable build artifacts * Maintaining and hardening shared services (GitLab, Artifactory, container registries) that the entire organization depends on * Implementing and enforcing security controls aligned with CMMC L2, NIST 800-171, and other frameworks required for ATO * Securing the software supply chain: image signing, SBOM generation, dependency scanning, and provenance tracking * Conducting threat modeling to surface architectural risks before they become incidents * Detecting, investigating, and responding to security incidents across infrastructure and applications * Working with product teams to ensure their workloads meet security and compliance requirements before and after deployment * Supporting the secure hosting of ML/AI workloads, including model training environments and sensitive data handling ## Related Videos - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)