DevSecOps / Security Engineer

ZANTECH INC.
Arlington, VA, United States
14 days ago
Apply on www.wayup.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Adobe Analytics Kubernetes Security Amazon Web Services Microsoft Azure Cloud Computing Configuration Management Cyber Security Continuous Integration Ansible Software Deployment Data Logging Information Security Management System
+19 more
Cloudformation Containerization Gitlab-ci Kubernetes Infrastructure Automation Frameworks Information Technology Deployment Automation Nessus Terraform Splunk Devsecops Docker Elk Stack Jenkins Plan of Action and Milestones Static Application Security Testing Vulnerability Analysis Microservices Dynamic Application Security Testing

Job description

Are you looking for your next challenge? Are you ready to work with a performance-based small company? At Zantech, we are a dynamic Woman Owned Small Business focused on providing complex, mission-focused solutions with a proven track record of outstanding customer performance and high employee satisfaction. We would love to talk with you regarding the next step in your career. Come join our team! Zantech is looking for a talented DevSecOps / Security Engineer to contribute to the success of our upcoming Technical Infrastructure and Platform Support project for an On-Site role based out of Arlington, VA. The DevSecOps / Security Engineer will play a crucial role in providing:

  • Technical Infrastructure and Platform Support
  • Cybersecurity and Information Assurance (RMF, continuous ATO, Compliance-as-Code) The DevSecOps / Security Engineer serves as the lead technical engineer for automation, CI/CD, and security posture of the cloud infrastructure, directly executing Technical Infrastructure and Platform Support requirements and supporting continuous Authority to Operate (ATO) under the DoD Risk Management Framework. Responsibilities include, but will not be limited to:

  • Build and maintain secure, automated CI/CD pipelines and zero-downtime deployment processes
  • Automate infrastructure provisioning and configuration management via Infrastructure as Code
  • Support the RMF process: System Security Plan, Security Assessment Report, and POA&M development and continuous monitoring
  • Apply and automate DISA STIGs; run vulnerability scanning and manage remediation
  • Integrate SAST/DAST testing and auto-generate compliance-as-code artifacts (e.g., Ports/Protocols/Services, topology diagrams) for eMASS

Requirements

  • 5 years in DevSecOps, including designing, implementing, and maintaining CI/CD pipelines and automating software deployment (Jenkins, GitLab CI/CD, or Ansible)
  • 5 years supporting the Risk Management Framework (RMF) for DoD or federal systems, including DISA STIGs, vulnerability assessments, and patching/remediation
  • 5 years automating cloud infrastructure and platform provisioning (AWS, Azure) using Infrastructure as Code (Terraform or CloudFormation).
  • Skills Required: o CI/CD pipeline design and secure software deployment automation o Infrastructure as Code (Terraform, Ansible, CloudFormation) o Security scanning and monitoring/logging integration (Nessus, OpenSCAP, Splunk, ELK Stack) o Containerization and orchestration in microservices architectures (Docker, Kubernetes) o SAST/DAST integration directly into the CI/CD pipeline o RMF process support, DISA STIG application, and continuous ATO / eMASS artifact automation Required Education/Certifications:

  • Education Required: o Bachelor’s degree in computer science, engineering, or equivalent, and 5+ years of experience OR o AA with 7+ years of experience is an accepted substitute

  • Education Preferred: o Bachelor’s degree in Computer Science, Cybersecurity, or a related field

  • Certifications Required:
  • Current DoDM 8140.03-qualifying certification for the assigned cyberspace work role, e.g., Security+ or CySA+)
  • Certifications Preferred: o CISSP, AWS/Azure security specialty certification, Certified Kubernetes Security Specialist (CKS) Required Security Clearance:

  • US Citizenship and the ability to obtain and maintain an active Secret or higher clearance, per contract requirements.

Benefits & conditions

Our corporate motto represents our commitment to build long-term relationships with both our clients and our employees by providing the highest quality service in everything we do. We strive for excellence for our clients and for each other. We embrace the opportunity to hire individuals with new talents and fresh perspectives. Zantech offers competitive compensation, strong benefits, and a vacation package, as well as a fast-paced and exciting work environment. Come join our team!

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.wayup.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

2:34 min

Docker sandbox architecture and microVM environment integration

Manuel de la Peña Manuel de la Peña · World Congress 2026 Europe

Videos

See all

Related articles

See all