> Markdown version of [/jobs/ext/3461747-expert-devsecops-engineer](https://www.wearedevelopers.com/jobs/ext/3461747-expert-devsecops-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Expert DevSecOps Engineer - **Company:** Dark Wolf Solutions - **Location:** Herndon, VA, United States - **Experience:** Expert - **Salary:** $160,000.0 - $210,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Amazon Web Services, Unit Testing, Microsoft Azure, Bash Shell, Burp Suite, C++ (Programming Language), Static Program Analysis, CompTIA Security+, Information Systems, Continuous Delivery, Continuous Integration, DevOps, Python (Programming Language), Key Management, Scrum Methodology, Fortify (Software), Prometheus, Scaled Agile Framework, Security Software, Software Engineering, SonarQube, Tripwire, Policy as Code, Scripting, Istio, Grafana, Sonatype, Multi-Cloud, Containerization, Gitlab-ci, Integration Tests, Kubernetes, Information Technology, Hashicorp, Linkerd (Service Mesh), Oracle Cloud Infrastructure, Devsecops, Docker, Jenkins, Static Application Security Testing, Vulnerability Analysis, Golang, Dynamic Application Security Testing - **Published:** September 10, 2026 - **Apply:** https://startup.jobs/devsecops-engineer-expert-dark-wolf-solutions-9980199 ## About the Role We are seeking a seasoned leader and problem solver with a proven ability to deliver superior results while guiding high-performing engineering teams in fast-paced environments., * Clearance: Must be a US Citizen holding an active TS/SCI security clearance with an active Full-Scope Polygraph. * Education: Bachelor's degree in Computer Science, Information Systems, Engineering, or a related technical field. * Professional Experience: 10+ years of progressive engineering experience, including deep expertise in CI/CD concepts, methodologies, and enterprise automated pipeline construction. Core Technical Skills Required for Expert Level: (Advanced competencies expected for a 10+ year Expert practitioner) * Enterprise Container Orchestration & Security: Deep experience managing enterprise Kubernetes clusters, authoring NetworkPolicies, implementing Service Meshes (e.g., Istio, Linkerd), and enforcing runtime security (e.g., Falco). * Policy-as-Code & Guardrails: Experience implementing Policy-as-Code architectures using tools like Open Policy Agent (OPA/Gatekeeper) or Kyverno to automate compliance enforcement before runtime. * Secrets Management Architecture: Hands-on design and implementation of automated secret lifecycle solutions (e.g., HashiCorp Vault) integrating dynamically into pipelines and runtime platforms. * Distributed Observability: Proven capability building centralized telemetry stacks leveraging OpenTelemetry, Prometheus, Grafana, and ELK/OpenSearch. Desired Qualifications: * Programming & Scripting: High proficiency in languages such as Python, Go, Bash, or C/C++. * Containerization: Comprehensive experience with containerized software engineering practices and runtimes (Docker, Podman, OCI specs). * Agile Engineering: Proven experience working within and leading Agile/Scrum software development teams. * Multi-Cloud Expertise: Architecture experience across major cloud platforms, including AWS, Azure, or GCP. * Security Tooling Ecosystem: Hands-on experience integrating modern security scanners (e.g., SonarQube, Snyk, Trivy, OWASP ZAP, Fortify). Industry Certifications: * Certified Kubernetes Administrator (CKA) / Certified Kubernetes Security Specialist (CKS) * AWS Certified DevOps Engineer - Professional * CompTIA Security+, CISSP, or GIAC DevSecOps Automation (GCSA) Position Clearance Requirement: US Citizenship with an active TS/SCI security clearance with Full-Scope Polygraph ## Description Dark Wolf is seeking an Expert DevSecOps Engineer to serve as a technical anchor, architecting, maintaining, and scaling the Continuous Integration/Continuous Deployment (CI/CD) tools, pipelines, and infrastructure used across the development lifecycle. In this role, you will lead the integration of security and operational resilience, ensuring total observability, automated compliance, and software assurance across complex systems., * CI/CD Platform Leadership: Maintain, optimize, and scale production-grade CI/CD pipelines utilizing platforms such as Jenkins, GitLab CI/CD, and custom workflow engines. * Automated Security Engineering: Ensure the seamless integration of automated security controls and scanning processes throughout the pipeline, including static code analysis (SAST), dynamic code analysis (DAST), dependency auditing, and vulnerability scanning. * Testing Architecture: Implement and maintain robust automated testing frameworks across unit testing, integration testing, and User Acceptance Testing (UAT). * Vulnerability & Risk Remediation: Collaborate directly with software development and security teams to proactively identify, prioritize, and remediate security vulnerabilities and architectural weaknesses in deployed software products. * Regulatory Compliance & Security Governance: Implement and enforce compliance with relevant federal, DoD, and organizational security regulations and standards. * Platform & Infrastructure Strategy: Establish enterprise Infrastructure-as-Code (IaC) module standards, direct multi-environment deployment frameworks, and lead response strategies for enterprise-level vulnerabilities. ## Related Videos - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) - [Scoring 2000 Products per Request: Performance Pitfalls in Golang](https://www.wearedevelopers.com/videos/2073-scoring-2000-products-per-request-performance-pitfalls-in-golang) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)