Senior DevSecOps Engineer, Cloud and Application Security

Greenbrier Government Solutions Inc.
United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$135,443.0 - $163,114.0
Working hours
Regular working hours
Job source

Tech stack

Cloud Computing Cloud Computing Security Cyber Security Information Systems Continuous Integration Identity and Access Management Systems Integration Software Vulnerability Management Policy as Code Delivery Pipeline Software Security Git
+8 more
Containerization Kubernetes Information Technology Software Version Control Devsecops Serverless Computing Static Application Security Testing Dynamic Application Security Testing

Job description

  • Design and improve secure CI/CD workflows for applications, containers, infrastructure-as-code, and cloud-native services.

  • Integrate source-code, dependency, secrets, container, infrastructure, dynamic, and compliance testing into delivery pipelines.

  • Set useful quality gates, exception paths, and evidence-capture rules based on risk and release context.

  • Review repositories, branching and version-control practices, build definitions, artifact handling, software bills of materials, and provenance.

  • Apply threat modeling, secure-design review, vulnerability management, and incident lessons to pipeline and platform controls.

  • Automate repeatable compliance checks and produce traceable evidence that supports continuous monitoring and authorization.

  • Work with developers and platform teams to reproduce findings, choose practical remediations, and verify closure.

  • Measure pipeline and remediation performance, then tune tools and rules to improve signal quality and reduce avoidable rework., * Security checks are early, repeatable, and tied to clear release decisions.

  • Developers receive findings they can reproduce and fix, with less noise and fewer late surprises.

  • Pipeline evidence supports engineering, continuous monitoring, and authorization without manual reconstruction.

Work arrangement and conditions

  • Full-time role; contingent upon contract award and customer approval.

  • U.S.-based remote work from a Greenbrier-approved work location. Routine onsite work is not expected.

  • Availability during VA core hours, 8:00 a.m. to 5:00 p.m. Eastern Time on normal federal workdays.

  • Occasional travel or onsite support for kickoff and other Government-directed events, with Washington, DC anticipated as the primary location.

  • Ability to obtain and maintain the Tier 4/High Risk background suitability determination and VA access required for the role.

How we work

  • Communicate clearly and work comfortably across technical teams, program leaders, and senior government stakeholders.

  • Protect sensitive information and produce work that is complete, traceable, reviewable, and ready for customer use.

Requirements

  • At least 10 years of DevSecOps experience, including at least 5 years of cybersecurity and cloud security work at a large Government agency comparable in size or scope to GSA, IRS, DoD, or VA.

  • Experience with CI/CD pipelines, containerization, cloud-native environments, and related DevSecOps practices.

  • Software-development experience and fluency with source-code repositories, Git, and version control.

  • Cybersecurity experience that includes security assessment, vulnerability management, and incident response.

  • Experience integrating security tools into DevOps pipelines and automating security testing and compliance checks.

  • Bachelor’s degree in business administration, business management, cybersecurity, computer science, information systems, information assurance, information security, information resource management, or a related field.

  • One or more of the following: IAT III, IAM III, or IASAE III qualification/certification.

Preferred qualifications

  • Hands-on experience with Kubernetes, container registries, artifact repositories, infrastructure-as-code, and policy-as-code.

  • Experience with SAST, DAST, SCA, secrets detection, container scanning, SBOM generation, and automated control evidence.

  • Federal RMF, ATO, FedRAMP, or VA delivery experience.

Benefits & conditions

  • 401(k)
  • 401(k) matching
  • Dental insurance
  • Flexible schedule
  • Health insurance
  • Life insurance
  • Paid time off
  • Parental leave
  • Professional development assistance
  • Referral program
  • Retirement plan
  • Vision insurance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:55 min

Executing secure deployments with verified compliance and data residency

Alex Laubscher Alex Laubscher · World Congress 2025

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

1:15 min

Deploying local container pods to Kubernetes clusters

Stevan Le Meur Stevan Le Meur · World Congress 2024

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

Videos

See all

Related articles

See all