> Markdown version of [/jobs/ext/3418070-senior-devsecops-engineer-cloud-and-application-security](https://www.wearedevelopers.com/jobs/ext/3418070-senior-devsecops-engineer-cloud-and-application-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior DevSecOps Engineer, Cloud and Application Security - **Company:** Greenbrier Government Solutions Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $135,443.0 - $163,114.0 - **Contract:** Permanent contract - **Skills:** Cloud Computing, Cloud Computing Security, Cyber Security, Information Systems, Continuous Integration, Identity and Access Management, Systems Integration, Software Vulnerability Management, Policy as Code, Delivery Pipeline, Software Security, Git, Containerization, Kubernetes, Information Technology, Software Version Control, Devsecops, Serverless Computing, Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 2, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=b670f47e28521823 ## About the Role * At least 10 years of DevSecOps experience, including at least 5 years of cybersecurity and cloud security work at a large Government agency comparable in size or scope to GSA, IRS, DoD, or VA. * Experience with CI/CD pipelines, containerization, cloud-native environments, and related DevSecOps practices. * Software-development experience and fluency with source-code repositories, Git, and version control. * Cybersecurity experience that includes security assessment, vulnerability management, and incident response. * Experience integrating security tools into DevOps pipelines and automating security testing and compliance checks. * Bachelor's degree in business administration, business management, cybersecurity, computer science, information systems, information assurance, information security, information resource management, or a related field. * One or more of the following: IAT III, IAM III, or IASAE III qualification/certification. Preferred qualifications * Hands-on experience with Kubernetes, container registries, artifact repositories, infrastructure-as-code, and policy-as-code. * Experience with SAST, DAST, SCA, secrets detection, container scanning, SBOM generation, and automated control evidence. * Federal RMF, ATO, FedRAMP, or VA delivery experience. ## Description * Design and improve secure CI/CD workflows for applications, containers, infrastructure-as-code, and cloud-native services. * Integrate source-code, dependency, secrets, container, infrastructure, dynamic, and compliance testing into delivery pipelines. * Set useful quality gates, exception paths, and evidence-capture rules based on risk and release context. * Review repositories, branching and version-control practices, build definitions, artifact handling, software bills of materials, and provenance. * Apply threat modeling, secure-design review, vulnerability management, and incident lessons to pipeline and platform controls. * Automate repeatable compliance checks and produce traceable evidence that supports continuous monitoring and authorization. * Work with developers and platform teams to reproduce findings, choose practical remediations, and verify closure. * Measure pipeline and remediation performance, then tune tools and rules to improve signal quality and reduce avoidable rework., * Security checks are early, repeatable, and tied to clear release decisions. * Developers receive findings they can reproduce and fix, with less noise and fewer late surprises. * Pipeline evidence supports engineering, continuous monitoring, and authorization without manual reconstruction. Work arrangement and conditions * Full-time role; contingent upon contract award and customer approval. * U.S.-based remote work from a Greenbrier-approved work location. Routine onsite work is not expected. * Availability during VA core hours, 8:00 a.m. to 5:00 p.m. Eastern Time on normal federal workdays. * Occasional travel or onsite support for kickoff and other Government-directed events, with Washington, DC anticipated as the primary location. * Ability to obtain and maintain the Tier 4/High Risk background suitability determination and VA access required for the role. How we work * Communicate clearly and work comfortably across technical teams, program leaders, and senior government stakeholders. * Protect sensitive information and produce work that is complete, traceable, reviewable, and ready for customer use. ## Related Videos - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [A Guide to Green Tech and Green IT Careers](https://www.wearedevelopers.com/magazine/374-a-guide-to-green-tech-and-green-it-careers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers)