Senior DevSecOps Engineer, Cloud and Application Security
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+8 more
Job description
-
Design and improve secure CI/CD workflows for applications, containers, infrastructure-as-code, and cloud-native services.
-
Integrate source-code, dependency, secrets, container, infrastructure, dynamic, and compliance testing into delivery pipelines.
-
Set useful quality gates, exception paths, and evidence-capture rules based on risk and release context.
-
Review repositories, branching and version-control practices, build definitions, artifact handling, software bills of materials, and provenance.
-
Apply threat modeling, secure-design review, vulnerability management, and incident lessons to pipeline and platform controls.
-
Automate repeatable compliance checks and produce traceable evidence that supports continuous monitoring and authorization.
-
Work with developers and platform teams to reproduce findings, choose practical remediations, and verify closure.
-
Measure pipeline and remediation performance, then tune tools and rules to improve signal quality and reduce avoidable rework., * Security checks are early, repeatable, and tied to clear release decisions.
-
Developers receive findings they can reproduce and fix, with less noise and fewer late surprises.
-
Pipeline evidence supports engineering, continuous monitoring, and authorization without manual reconstruction.
Work arrangement and conditions
-
Full-time role; contingent upon contract award and customer approval.
-
U.S.-based remote work from a Greenbrier-approved work location. Routine onsite work is not expected.
-
Availability during VA core hours, 8:00 a.m. to 5:00 p.m. Eastern Time on normal federal workdays.
-
Occasional travel or onsite support for kickoff and other Government-directed events, with Washington, DC anticipated as the primary location.
-
Ability to obtain and maintain the Tier 4/High Risk background suitability determination and VA access required for the role.
How we work
-
Communicate clearly and work comfortably across technical teams, program leaders, and senior government stakeholders.
-
Protect sensitive information and produce work that is complete, traceable, reviewable, and ready for customer use.
Requirements
-
At least 10 years of DevSecOps experience, including at least 5 years of cybersecurity and cloud security work at a large Government agency comparable in size or scope to GSA, IRS, DoD, or VA.
-
Experience with CI/CD pipelines, containerization, cloud-native environments, and related DevSecOps practices.
-
Software-development experience and fluency with source-code repositories, Git, and version control.
-
Cybersecurity experience that includes security assessment, vulnerability management, and incident response.
-
Experience integrating security tools into DevOps pipelines and automating security testing and compliance checks.
-
Bachelor’s degree in business administration, business management, cybersecurity, computer science, information systems, information assurance, information security, information resource management, or a related field.
-
One or more of the following: IAT III, IAM III, or IASAE III qualification/certification.
Preferred qualifications
-
Hands-on experience with Kubernetes, container registries, artifact repositories, infrastructure-as-code, and policy-as-code.
-
Experience with SAST, DAST, SCA, secrets detection, container scanning, SBOM generation, and automated control evidence.
-
Federal RMF, ATO, FedRAMP, or VA delivery experience.
Benefits & conditions
- 401(k)
- 401(k) matching
- Dental insurance
- Flexible schedule
- Health insurance
- Life insurance
- Paid time off
- Parental leave
- Professional development assistance
- Referral program
- Retirement plan
- Vision insurance
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
A Guide to Green Tech and Green IT Careers
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
9 Ways to Make Money Hacking
Is Software Engineering Over-Saturated?