> Markdown version of [/jobs/ext/2915802-sme-devsecops-python-engineer](https://www.wearedevelopers.com/jobs/ext/2915802-sme-devsecops-python-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SME - DevSecOps / Python Engineer - **Company:** Konane Solutions - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Cloud Computing, Cyber Security, Continuous Integration, Github, Identity and Access Management, Python (Programming Language), Key Management, Open Web Application Security, Role-Based Access Control, Zero Trust Network Access, Secure Coding, Security Software, Software Engineering, Software Vulnerability Management, Policy as Code, Data Logging, Scripting, Flask (Web Framework), Delivery Pipeline, Git, Fastapi, Gitlab-ci, Git Flow, Kubernetes, Infrastructure Automation Frameworks, Information Technology, Restful APIs, Terraform, Devsecops, Docker, Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 15, 2026 - **Apply:** https://www.dice.com/job-detail/67c822d5-669b-4875-9282-c043ffe11031 ## About the Role * Bachelor's degree in Computer Science, Software Engineering, Cybersecurity, Cloud Computing, or a related technical field. * 10+ years of software engineering, DevSecOps, cloud, platform, or security engineering experience, including senior technical leadership responsibilities. * Expert Python development skills, including FastAPI/Flask, REST APIs, automation, testing, packaging, logging, and secure coding practices. * Strong CI/CD, Git, Terraform, Docker, Kubernetes/ECS, AWS, and automated security testing experience. * Knowledge of OWASP, IAM/RBAC, Zero Trust, secrets management, encryption/TLS, observability, vulnerability management, and software supply-chain security. * Experience supporting federal or regulated environments and familiarity with FISMA, NIST 800-53, FedRAMP, ATO, and continuous monitoring. * Preferred certifications include AWS, CISSP/Security+, CKA/CKS, Terraform, Python, or comparable DevSecOps credentials. ## Description The Senior SME - DevSecOps / Python Engineer provides senior technical leadership and hands-on engineering for secure software delivery, Python automation, cloud infrastructure, and CI/CD within a federal enterprise environment. The role establishes secure delivery standards, builds reusable automation and services, and integrates security throughout the software development lifecycle., * Design, implement, and optimize Git-based CI/CD pipelines for Python and platform workloads using GitLab CI, GitHub Actions, or equivalent tools. * Integrate SAST, DAST, SCA, secrets scanning, container scanning, SBOM generation, artifact signing, and security gates into delivery pipelines. * Develop production-grade Python automation, APIs, services, and operational tooling using Python, FastAPI/Flask, REST, and scripting frameworks. * Automate infrastructure and environment provisioning using Terraform, policy-as-code, GitOps, and configuration-as-code practices. * Build and secure Docker/container deployment patterns using Kubernetes/ECS and integrate AWS IAM, networking, secrets, encryption, and logging controls. * Lead secure design reviews, vulnerability remediation, production troubleshooting, incident root-cause analysis, technical mentoring, and continuous improvement. ## Related Videos - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Find a Developer Job: 12 Best Job Sites For Developers](https://www.wearedevelopers.com/magazine/165-find-a-developer-job-12-best-job-sites-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)