> Markdown version of [/jobs/ext/2189843-devsecops-security-engineer](https://www.wearedevelopers.com/jobs/ext/2189843-devsecops-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # DevSecOps / Security Engineer - **Company:** ZANTECH INC. - **Location:** Arlington, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Adobe Analytics, Kubernetes Security, Amazon Web Services, Microsoft Azure, Cloud Computing, Configuration Management, Cyber Security, Continuous Integration, Ansible, Software Deployment, Data Logging, Information Security Management System, Cloudformation, Containerization, Gitlab-ci, Kubernetes, Infrastructure Automation Frameworks, Information Technology, Deployment Automation, Nessus, Terraform, Splunk, Devsecops, Docker, Elk Stack, Jenkins, Plan of Action and Milestones, Static Application Security Testing, Vulnerability Analysis, Microservices, Dynamic Application Security Testing - **Published:** August 22, 2026 - **Apply:** https://www.wayup.com/i-j-DevSecOps-Security-Engineer-Zantech-341142236936939/ ## About the Role + 5 years in DevSecOps, including designing, implementing, and maintaining CI/CD pipelines and automating software deployment (Jenkins, GitLab CI/CD, or Ansible) + 5 years supporting the Risk Management Framework (RMF) for DoD or federal systems, including DISA STIGs, vulnerability assessments, and patching/remediation + 5 years automating cloud infrastructure and platform provisioning (AWS, Azure) using Infrastructure as Code (Terraform or CloudFormation). + Skills Required: o CI/CD pipeline design and secure software deployment automation o Infrastructure as Code (Terraform, Ansible, CloudFormation) o Security scanning and monitoring/logging integration (Nessus, OpenSCAP, Splunk, ELK Stack) o Containerization and orchestration in microservices architectures (Docker, Kubernetes) o SAST/DAST integration directly into the CI/CD pipeline o RMF process support, DISA STIG application, and continuous ATO / eMASS artifact automation Required Education/Certifications: + Education Required: o Bachelor's degree in computer science, engineering, or equivalent, and 5+ years of experience OR o AA with 7+ years of experience is an accepted substitute + Education Preferred: o Bachelor's degree in Computer Science, Cybersecurity, or a related field + Certifications Required: + Current DoDM 8140.03-qualifying certification for the assigned cyberspace work role, e.g., Security+ or CySA+) + Certifications Preferred: o CISSP, AWS/Azure security specialty certification, Certified Kubernetes Security Specialist (CKS) Required Security Clearance: + US Citizenship and the ability to obtain and maintain an active Secret or higher clearance, per contract requirements. ## Description Are you looking for your next challenge? Are you ready to work with a performance-based small company? At Zantech, we are a dynamic Woman Owned Small Business focused on providing complex, mission-focused solutions with a proven track record of outstanding customer performance and high employee satisfaction. We would love to talk with you regarding the next step in your career. Come join our team! Zantech is looking for a talented DevSecOps / Security Engineer to contribute to the success of our upcoming Technical Infrastructure and Platform Support project for an On-Site role based out of Arlington, VA. The DevSecOps / Security Engineer will play a crucial role in providing: + Technical Infrastructure and Platform Support + Cybersecurity and Information Assurance (RMF, continuous ATO, Compliance-as-Code) The DevSecOps / Security Engineer serves as the lead technical engineer for automation, CI/CD, and security posture of the cloud infrastructure, directly executing Technical Infrastructure and Platform Support requirements and supporting continuous Authority to Operate (ATO) under the DoD Risk Management Framework. Responsibilities include, but will not be limited to: + Build and maintain secure, automated CI/CD pipelines and zero-downtime deployment processes + Automate infrastructure provisioning and configuration management via Infrastructure as Code + Support the RMF process: System Security Plan, Security Assessment Report, and POA&M development and continuous monitoring + Apply and automate DISA STIGs; run vulnerability scanning and manage remediation + Integrate SAST/DAST testing and auto-generate compliance-as-code artifacts (e.g., Ports/Protocols/Services, topology diagrams) for eMASS ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) ## Related Articles - [DevOps Engineer Salary [2023]](https://www.wearedevelopers.com/magazine/203-devops-engineer-salary-2023) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)