> Markdown version of [/jobs/ext/2960468-software-engineer-devsecops](https://www.wearedevelopers.com/jobs/ext/2960468-software-engineer-devsecops). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Software Engineer-DevSecOps - **Company:** AnaVation, LLC - **Location:** San Antonio, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Agile Methodology, Amazon Web Services, Advanced Message Queuing Protocol, Microsoft Azure, Bash Shell, Cyber Security, Continuous Integration, Linux, Java Message Service (JMS), Spring Framework, Python (Programming Language), Node.Js, Ansible, Zero Trust Network Access, Software Engineering, Software Factory, Software Vulnerability Management, Data Logging, Scripting, Google Cloud, Cloud Platform System, Istio, Infrastructure as Code (IaC), Gitlab, AngularJS, Gitlab-ci, Kubernetes, Information Technology, Restful APIs, Terraform, Software Version Control, Devsecops, Docker, Jenkins, Static Application Security Testing, Microservices, Dynamic Application Security Testing - **Published:** September 17, 2026 - **Apply:** https://startup.jobs/software-engineer-devsecops-anavation-10095883 ## About the Role * Clearance: U.S. Citizen; TS/SCI. * Education: Bachelor's degree in Computer Science, Cybersecurity, IT, Software Engineering, or related field. * Certification: DoD 8140/8570 IAT Level II e.g., Security+ CE or equivalent. * Location: Full-time on-site in San Antonio, TX. * Experience and Knowledge: * Senior level comprehensive knowledge across key tasks and high-impact assignments; plans and leads major technology assignments; functions as a technical expert across the team; may lead others. * Deep understanding of Agile and DevSecOps methodologies; DevSecOps implementation using Jenkins, GitLab, or similar. * Skillset to build and maintain CI/CD pipelines for a large enterprise (hundreds of applications). * Experience developing IaC/CaC with Packer, Terraform, and Ansible; development experience with Kubernetes, Docker, and Helm. * Experience with cloud systems and architectures (AWS, Google Cloud, or Azure); Linux and scripting (Bash, Python). * Working knowledge of source version control, build/release tools, and CI/CD; strong security-first mindset. * Minimum years of experience - 4 years of relevant experience, * Clearance: Active TS/SCI. * Education: Advanced degree in a related technical field. * Certification: CKS, CKA, AWS certifications, CCSP, or GitLab certifications. * Experience and Knowledge: * Experience developing software with Java/Spring, Python, JavaScript/node.js, or Angular; microservice architectures (REST, JMS, AMQP). * Experience with Istio; experience supporting Government software factory environments. * Experience supporting Continuous Authority to Operate (cATO). * Experience with secure software supply chain (SBOM, artifact signing). * Experience supporting IL4, IL5, or IL6 cloud environments; COT, CPT, or Security Control Assessors. * Experience with GitLab security policies, Twistlock, Anchore, Defect Dojo, container signing (e.g., cosign/sigstore), and End-of-Life image detection. Benefits ## Description Position Responsibilities: This position establishes the automation standard for secure software delivery, ensuring security is built into pipelines, and control evidence is generated continuously., * Build and maintain CI/CD pipelines (e.g., GitLab CI, Jenkins) for an enterprise consisting of many applications. * Develop, test, and maintain containerized applications; work with source version control and build/release tooling. * Develop Infrastructure as Code (IaC) and Configuration as Code (CaC) using Packer, Terraform, and Ansible. * Automate security control implementation, validation, and evidence collection supporting RMF, ATO, and cATO. * Integrate and tune pipeline security tooling: SAST, DAST, SCA, container scanning, secrets detection, and policy gates. * Support security-relevant changes (SRCs), Security Impact Assessments (SIAs), and control validation for embedded value streams. * Support application/container vulnerability management, whitelisting decisions, and CTF/pipeline compliance so changes do not invalidate the ATO. * Collaborate with ISSEs, software developers, Value Stream engineers, COT, CPT, and Government stakeholders across sprint cadences. * Architect logging, monitoring, and telemetry to support continuous monitoring. * Maintain a strong security-first mindset and support Zero Trust and secure software supply chain practices. * Maintain and validate A&A control evidence in eMASS (control implementation, SIAs, SRCs, POA&Ms) supporting continuous monitoring and cATO readiness. * Develop automated security policies in CI/CD (e.g., GitLab Policies) to flag End-of-Life images, remediate pipeline vulnerabilities, prevent unauthorized deployments, and quarantine compromised artifacts. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)