> Markdown version of [/jobs/ext/3410855-seniorcybersecurity-engineer](https://www.wearedevelopers.com/jobs/ext/3410855-seniorcybersecurity-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SeniorCybersecurity Engineer - **Company:** Public Sector - **Location:** San Antonio, TX, United States - **Experience:** Expert - **Salary:** $140,000.0 - $160,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Amazon Web Services, Cloud Computing Security, Cyber Security, Continuous Delivery, Octopus Deploy, Package Management Systems, Ansible, Fortify (Software), Software Engineering, Software Factory, SonarQube, Tripwire, Software Vulnerability Management, Policy as Code, Software Security, Gitlab, Git, SC Clearance, Containerization, Gitlab-ci, Kubernetes, Terraform, Prisma Cloud Platform, Data Pipelines, Devsecops, Static Application Security Testing, Vulnerability Analysis, Microservices, Dynamic Application Security Testing - **Published:** September 15, 2026 - **Apply:** https://www.thejobnetwork.com/job/senior-engineer-509975390 ## About the Role * 3+ years of experience in Cybersecurity Engineering, DevSecOps, Platform Engineering, Cloud Security, Application Security, or a related technical discipline. * Hands-on experience implementing security capabilities within CI/CD pipelines, preferably GitLab CI/CD. * Experience with one or more application or container security technologies such as Fortify, SonarQube, Trivy, Twistlock/Prisma Cloud, NeuVector, or equivalent tools. * Experience with containerized environments and Kubernetes security concepts. * Experience identifying, assessing, and remediating software, container, infrastructure, or configuration vulnerabilities. * Working knowledge of DoD RMF, NIST SP 800-53, and DoD cybersecurity/Information Assurance requirements. * Understanding of DevSecOps principles and the integration of security controls throughout the software development lifecycle. * Experience working with Git and infrastructure/configuration-as-code technologies such as Terraform, Ansible, Helm, or equivalent technologies. * Understanding of software supply chain security concepts, including SBOMs, artifact signing, provenance, vulnerability scanning, and attestations. * Ability to translate cybersecurity requirements into practical technical controls and communicate effectively with both cybersecurity and engineering stakeholders. Highly preferred: * Experience with GitLab, GitLab Runners, Argo CD, Kubernetes, Helm, SOPS, AWS/GovCloud, Platform One or other DoD software factories, and DoD cATO environments is preferred. Familiarity with Cosign/Sigstore, container registries, package managers, microservices architectures, Kubernetes admission controls, policy-as-code, and automated compliance evidence collection is also highly desirable. * Experience supporting software delivery within IL4/IL5/IL6 DoD environments and working directly with ISSMs, ISSOs, security control assessors, Authorizing Officials, or government cybersecurity organizations is a plus. Certifications * DoD 8140/8570-compliant cybersecurity certification appropriate to the position is preferred (e.g., Security+, CySA+, CASP+/SecurityX, CISSP, or equivalent). * Kubernetes, cloud security, or AWS certifications are desirable. Clearance Requirements: * Minimum active Secret Clearance required to start ## Description The SeniorCybersecurity Engineer supports a DoW program by ensuring Information Assurance (IA), cybersecurity, and security engineering requirements are incorporated directly into the platform's DevSecOps pipelines, tooling, configurations, and software delivery processes., This role works closely with the Pipeline Architect, Software Engineering SMEs, infrastructure/platform engineers, and government stakeholders to ensure required DoD cybersecurity thresholds are met without creating unnecessary friction in the software delivery lifecycle. The Senior Cybersecurity Engineer helps translate security and compliance requirements into technical controls that can be automated, validated, and continuously enforced within the pipeline., * Work with the Pipeline Architect and Software Engineering SMEs to ensure DoD IA and cybersecurity thresholds are met and built directly into pipeline tooling, configurations, and workflows. * Translate DoD cybersecurity, RMF, and DevSecOps requirements into actionable technical requirements for engineering teams. * Design, implement, configure, and maintain automated security controls within CI/CD pipelines. * Integrate and maintain security tooling for SAST, DAST, software composition analysis (SCA), container scanning, secrets detection, dependency scanning, and vulnerability management. * Establish and enforce security gates and thresholds within GitLab CI/CD pipelines to prevent noncompliant or vulnerable software artifacts from progressing through the delivery lifecycle. * Support secure software supply chain practices, including artifact integrity, SBOM generation, vulnerability scanning, signing, provenance, and software attestations. * Work with engineering teams to integrate tools such as Fortify, SonarQube, Trivy, Twistlock/Prisma Cloud, NeuVector, Cosign/Sigstore, and similar security capabilities into automated workflows. * Review Kubernetes, container, GitLab Runner, infrastructure-as-code, and pipeline configurations for security vulnerabilities and configuration weaknesses. * Support vulnerability triage and remediation by working directly with software and platform engineering teams to determine severity, operational impact, remediation approaches, and acceptable mitigation strategies. * Develop and maintain security-as-code and policy-as-code approaches that allow cybersecurity requirements to be consistently enforced across environments. * Support compliance with the DoD DevSecOps Reference Design, NIST Risk Management Framework (RMF), NIST 800-53 controls, and applicable DoD cybersecurity requirements. * Support the collection and automation of security evidence required for authorization and continuous monitoring activities. * Partner with platform and application teams to ensure cybersecurity requirements support the UP continuous Authority to Operate (cATO) approach and Continuous Delivery/Continuous Deployment processes. * Identify cybersecurity risks associated with changes to pipeline architecture, platform baselines, infrastructure, and application delivery processes and recommend technical mitigations. * Develop security documentation, technical implementation guidance, configuration standards, and engineering best practices. * Participate in architecture reviews, technical discussions, troubleshooting sessions, and security assessments. ## Related Videos - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Dev & Test in the Cloud? Deploy your cloud environments with Ansible & Terraform](https://www.wearedevelopers.com/videos/1607-dev-test-in-the-cloud-deploy-your-cloud-environments-with-ansible-terraform) - [GitLab CI pipelines for a whole company](https://www.wearedevelopers.com/videos/143-gitlab-ci-pipelines-for-a-whole-company) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Eclipse Che for Infrastructure Automation](https://www.wearedevelopers.com/videos/1611-eclipse-che-for-infrastructure-automation) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)