Software Engineer-DevSecOps

AnaVation, LLC
San Antonio, TX, United States
4 days ago
Apply on startup.jobs
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) JavaScript (Programming Language) Agile Methodology Amazon Web Services Advanced Message Queuing Protocol Microsoft Azure Bash Shell Cyber Security Continuous Integration Linux Java Message Service (JMS) Spring Framework
+27 more
Python (Programming Language) Node.Js Ansible Zero Trust Network Access Software Engineering Software Factory Software Vulnerability Management Data Logging Scripting Google Cloud Cloud Platform System Istio Infrastructure as Code (IaC) Gitlab AngularJS Gitlab-ci Kubernetes Information Technology Restful APIs Terraform Software Version Control Devsecops Docker Jenkins Static Application Security Testing Microservices Dynamic Application Security Testing

Job description

Position Responsibilities: This position establishes the automation standard for secure software delivery, ensuring security is built into pipelines, and control evidence is generated continuously., * Build and maintain CI/CD pipelines (e.g., GitLab CI, Jenkins) for an enterprise consisting of many applications.

  • Develop, test, and maintain containerized applications; work with source version control and build/release tooling.
  • Develop Infrastructure as Code (IaC) and Configuration as Code (CaC) using Packer, Terraform, and Ansible.
  • Automate security control implementation, validation, and evidence collection supporting RMF, ATO, and cATO.
  • Integrate and tune pipeline security tooling: SAST, DAST, SCA, container scanning, secrets detection, and policy gates.
  • Support security-relevant changes (SRCs), Security Impact Assessments (SIAs), and control validation for embedded value streams.
  • Support application/container vulnerability management, whitelisting decisions, and CTF/pipeline compliance so changes do not invalidate the ATO.
  • Collaborate with ISSEs, software developers, Value Stream engineers, COT, CPT, and Government stakeholders across sprint cadences.
  • Architect logging, monitoring, and telemetry to support continuous monitoring.
  • Maintain a strong security-first mindset and support Zero Trust and secure software supply chain practices.
  • Maintain and validate A&A control evidence in eMASS (control implementation, SIAs, SRCs, POA&Ms) supporting continuous monitoring and cATO readiness.
  • Develop automated security policies in CI/CD (e.g., GitLab Policies) to flag End-of-Life images, remediate pipeline vulnerabilities, prevent unauthorized deployments, and quarantine compromised artifacts.

Requirements

  • Clearance: U.S. Citizen; TS/SCI.
  • Education: Bachelor’s degree in Computer Science, Cybersecurity, IT, Software Engineering, or related field.
  • Certification: DoD 8140/8570 IAT Level II e.g., Security+ CE or equivalent.
  • Location: Full-time on-site in San Antonio, TX.
  • Experience and Knowledge:
  • Senior level comprehensive knowledge across key tasks and high-impact assignments; plans and leads major technology assignments; functions as a technical expert across the team; may lead others.
  • Deep understanding of Agile and DevSecOps methodologies; DevSecOps implementation using Jenkins, GitLab, or similar.
  • Skillset to build and maintain CI/CD pipelines for a large enterprise (hundreds of applications).
  • Experience developing IaC/CaC with Packer, Terraform, and Ansible; development experience with Kubernetes, Docker, and Helm.
  • Experience with cloud systems and architectures (AWS, Google Cloud, or Azure); Linux and scripting (Bash, Python).
  • Working knowledge of source version control, build/release tools, and CI/CD; strong security-first mindset.
  • Minimum years of experience - 4 years of relevant experience, * Clearance: Active TS/SCI.
  • Education: Advanced degree in a related technical field.
  • Certification: CKS, CKA, AWS certifications, CCSP, or GitLab certifications.
  • Experience and Knowledge:
  • Experience developing software with Java/Spring, Python, JavaScript/node.js, or Angular; microservice architectures (REST, JMS, AMQP).
  • Experience with Istio; experience supporting Government software factory environments.
  • Experience supporting Continuous Authority to Operate (cATO).
  • Experience with secure software supply chain (SBOM, artifact signing).
  • Experience supporting IL4, IL5, or IL6 cloud environments; COT, CPT, or Security Control Assessors.
  • Experience with GitLab security policies, Twistlock, Anchore, Defect Dojo, container signing (e.g., cosign/sigstore), and End-of-Life image detection. Benefits

Benefits & conditions

  • Generous cost sharing for medical insurance for the employee and dependents
  • 100% company paid dental insurance for employees and dependents
  • 100% company paid long-term and short-term disability insurance
  • 100% company paid vision insurance for employees and dependents
  • 401k plan with generous match and 100% immediate vesting
  • Competitive Pay
  • Generous paid leave and holiday package
  • Tuition and training reimbursement
  • Life and AD&D Insurance

About the company

In a world of technology, people make the difference. We believe if we invest in great people, then great things will happen. At AnaVation, we provide unmatched value to our customers and employees through innovative solutions and an engaging culture., AnaVation is seeking a Software Engineer-DevSecOps to support one of our cybersecurity programs in our San Antonio office. In this position, the right candidate will develop and manage the CI/CD pipelines of mission applications across value streams. Considered a strong generalist on CI/CD and security requirements, the role automates security control implementation and evidence collection and advances inheritance and automation aligned with the Government’s Cyber Assessment Roadmap to sustain IATT, ATO, and cATO readiness., AnaVation is the leader in solving the most complex technical challenges for collection and processing in the U.S. Federal Intelligence Community. We are a US owned company headquartered in Chantilly, Virginia. We deliver groundbreaking research with advanced software and systems engineering that provides an information advantage to contribute to the mission and operational success of our customers. We offer complex challenges, a top-notch work environment, and a world-class, collaborative team. If you want to grow your career and make a difference while doing it, AnaVation is the perfect fit for you! AnaVation is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on startup.jobs
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

2:53 min

Configuring dynamic proxy updates with Istio Pilot

Jan Mensch Jan Mensch · World Congress 2026 Europe

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all