> Markdown version of [/jobs/ext/2189957-cybersecurity-engineer-devsecops](https://www.wearedevelopers.com/jobs/ext/2189957-cybersecurity-engineer-devsecops). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Engineer (DevSecOps) - **Company:** Arcfield, Inc. - **Location:** United States - **Experience:** Experienced - **Salary:** $101,157.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Artificial Intelligence, Amazon Web Services, Amazon S3, Systems Engineering, User Authentication, Microsoft Azure, Bash Shell, Cloud Storage, Cyber Security, Information Technology Consulting, DevOps, Dynamic Program Analysis, Identity and Access Management, Python (Programming Language), Open Web Application Security, Windows PowerShell, RabbitMQ, Role-Based Access Control, Prometheus, Security Information and Event Management, Software Engineering, Systems Modeling Language, Toolchain, Tripwire, Software Vulnerability Management, Scripting, ReactJS, Large Language Models, Grafana, Generative AI, HybridCloud, Fastapi, Gitlab-ci, Kubernetes, Information Technology, Tenable Nessus, Front End Software Development, Devsecops, Docker, Vulnerability Analysis, Microservices - **Published:** August 22, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9103703/cybersecurity-engineer-devsecops ## About the Role The candidate should be capable of working independently as a contributor to software development team. He or she should exhibit expertise in, * BS 8-10, MS 6-8, PhD 3-5 * BS in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field (or equivalent experience). * 3-7 years of experience in cybersecurity, security engineering, DevSecOps, or a related field. * Experience securing AWS, Azure, or hybrid cloud environments, with a strong emphasis on securing containerized architectures (Docker, Kubernetes). * Working knowledge of networking, operating systems, encryption, authentication, and secure software development principles. * Experience with vulnerability management and DevSecOps toolchains (GitLab CI/CD, static/dynamic analysis tools). * Experience with scripting or automation using Python, PowerShell, or Bash. * Understanding of AI/ML security best practices (e.g., OWASP Top 10 for LLMs) and securing Retrieval-Augmented Generation (RAG) pipelines. * Strong communication and collaboration skills with both technical teams and external customers. * Active Top Secret/Sensitive Compartmented Information (TS/SCI) security clearance. Required Technologies & Tools * Familiarity with Model-Based Systems Engineering (MBSE) workflows or tools (e.g., Cameo Systems Modeler, SysML v2). * Experience securing message brokering and orchestration services (e.g., RabbitMQ). ## Description This position is for Strategic Technology Consulting (STC), an Arcfield Company, * Design, implement, and maintain security controls across cloud (AWS/Azure), on-premises, AI, and classified environments. * Support security accreditation and compliance activities for systems governed by NIST SP 800-53, RMF, NIST SP 800-171, CMMC, and FedRAMP, specifically focusing on achieving ATOs for high-side classified deployments. * Coordinate with IT, Corporate Security, Program Security, software engineering teams, and government customers to ensure security requirements are incorporated throughout the system lifecycle. * Conduct vulnerability assessments, security reviews, and remediation tracking across our React frontend, Python (FastAPI) backends, and Java-based Cameo plugins. * Implement DevSecOps practices within GitLab CI/CD pipelines, integrating automated security scanning tools (e.g., Trivy, Semgrep, yGuard, and OWASP tools) into secure software development processes. * Monitor security events and system health, leveraging Prometheus and Grafana, and support incident response activities. * Configure and manage identity, access management (IAM), privileged access, and least-privilege controls (RBAC) for microservices and cloud storage boundaries (S3/Blob). * Implement security controls and guardrails for state-of-the-art AI models, Large Language Models (LLMs), and Retrieval-Augmented Generation (RAG) services to ensure data privacy, prevent prompt injection, and validate deterministic outputs. * Develop and maintain security documentation, System Security Plans (SSPs), security procedures, and technical guidance. * Support Authority to Operate (ATO) packages, security audits, and continuous monitoring activities. * Evaluate emerging cybersecurity technologies and recommend improvements to strengthen the organization's security posture. The candidate should also demonstrate a general understanding of or interest in gaining expertise in: * Systems Engineering processes, methods, and tools as applied to systems lifecycles * Digital Engineering methodologies and tooling, We are seeking a Security Engineer to design, implement, and maintain secure infrastructure and applications for our AI-driven Intelligent MBSE (iMBSE) platform across enterprise, cloud, AI, and classified environments. This role partners closely with software engineers, DevOps, IT, Security, and government customers to ensure cybersecurity is integrated throughout the system lifecycle while enabling rapid delivery of mission-critical systems engineering capabilities. The ideal candidate has experience supporting Department of Defense (DoD) or Intelligence Community (IC) programs, implementing DevSecOps practices (specifically within containerized Kubernetes environments), and guiding systems through security compliance and accreditation for high-side networks. ## Related Videos - [Watch Tests Go Brrrr! : Getting Started with Cypress in ReactJS](https://www.wearedevelopers.com/videos/282-watch-tests-go-brrrr-getting-started-with-cypress-in-reactjs) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)