Cloud DevSecOps Engineer III

Turbo Federal, LLC
Washington, DC, United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$150,000.0 - $180,000.0
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Application Programming Interfaces (APIs) Amazon Web Services Amazon Cloudfront Amazon S3 User Authentication Software as a Service Cloud Computing Cloud Engineering Cloud Foundry Configuration Management Code Review
+36 more
Cyber Security Information Systems Continuous Integration Linux Infrastructure as a Service (IaaS) Identity and Access Management IT Management Information Systems Security Architecture Professional Key Management Open Source Technology Windows PowerShell Prism (Software) Software Engineering SonarQube Systems Integration Software Vulnerability Management Policy as Code Data Logging Software Security Amazon Virtual Private Cloud (VPC) Cloudformation Data Lakes Git Flow Information Technology Nessus Cloudflare Fortinet Functional Programming Api Gateway Elastic Beanstalk Splunk Devsecops Docker Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

The Cloud DevSecOps Engineer III will provide senior engineering support to embed cybersecurity, compliance, automation, and continuous control validation into application development, infrastructure deployment, cloud engineering, and system integration workflows.

This role will ensure that new projects, applications, scripts, pipelines, infrastructure-as-code templates, and cloud-native deployments are designed and implemented with appropriate cybersecurity features and safeguards in accordance with federal policies, standards, directives, and Authorizing Official requirements.

The Cloud DevSecOps Engineer III will be a hands-on security automation engineer who works across development, security, operations, ISSO, SCA, SOC, vulnerability management, cloud architecture, and project management teams. The role will help shift security left into design and code review, shift security right into monitoring and runtime validation, and maintain traceability from requirements to controls, controls to pipeline checks, pipeline checks to evidence, and evidence to JCAM/ATO documentation., · Support secure software development and system integration lifecycle by reviewing application designs, infrastructure scripts, pipeline configurations, container images, open-source dependencies, secrets management approaches, authentication flows, data protection methods, and deployment patterns for compliance risks and security weaknesses.

· Identify issues before they become ATO blockers, production vulnerabilities, or POA&M findings.

· Support the Cybersecurity, Policy and Oversight team and ISSOs in the preparation of Security and Privacy Authorization documentation required to attain Authorization to Test or Authorization to Operate.

· Provide cybersecurity reviews, security configuration reviews, initial risk assessment support, certification testing review, coordination with ISSOs on security design changes, and development of POA&Ms when security requirements are not being met.

· Design, maintain, and improve secure CI/CD and DevSecOps pipelines that incorporate SAST, DAST, software composition analysis, infrastructure-as-code scanning, container image scanning, secrets detection, dependency vulnerability review, policy-as-code, configuration compliance, and deployment security gates.

· Support DevSecOps security tools used to detect open-source components in code, static and dynamic application security testing, SonarQube, PowerShell DSC, Palo Alto Prisma, and related pipeline security capabilities.

· Implement cloud automation using AWS-native services, CloudFormation, infrastructure-as-code, APIs, Lambda, IAM, security groups, KMS, S3 encryption, RDS encryption, HTTPS, SSL certificates, API Gateway, CloudFront, egress proxies, container security, domain segmentation, authentication controls, data protection, and automated evidence capture.

· Review application code, deployment scripts, infrastructure-as-code, CI/CD jobs, container configurations, and cloud deployment templates for security risks, compliance violations, and deviations from federal security requirements.

· Embed security checks into CI/CD pipelines using tools such as SonarQube, Prisma, SAST, DAST, dependency scanning, secrets detection, vulnerability scanning, and configuration compliance tooling.

· Support risk assessments during concept development, design review, testing, and deployment phases.

· Automate the deployment and verification of technical controls, supporting requirement to integrate configuration management and DevSecOps pipelines to automatically deploy, enforce, and verify technical controls.

· Build repeatable AWS infrastructure patterns using IaC and secure-by-default baselines for VPCs, security groups, IAM roles, KMS keys, encryption, logging, monitoring, and cloud-native alerts.

· Help close POA&Ms by engineering durable remediation into code, templates, automation, and standard operating procedures instead of relying on one-time manual fixes.

· Provide monthly briefings and/or reports to upper management on the cybersecurity status of new projects, applications, and information systems.

Pay: $150,000.00 - $180,000.00 per year

Requirements

Do you have experience in Vulnerability scanning?, Do you have a Bachelor’s degree?, · Bachelor’s degree in cybersecurity, computer science, software engineering, cloud engineering, information systems, or a related discipline.

· Public Trust / Suitability (eligible for Secret).

· Two (2) or more certifications from the following list:

o ISACA - Certified Information Systems Auditor (CISA)

o ISACA - Certified in Risk and Information Systems Control (CRISC)

o ISACA - Certified Information Security Manager (CISM)

o ISACA - Certified in Governance of Enterprise IT (CGEIT)

o (ISC)2 - Certified Information Systems Security Professional (CISSP)

o (ISC)2 - Certified Authorization Professional (CAP)

· Practical experience with SonarQube, SAST/DAST tooling, IaC scanning, container scanning, Splunk, Nessus/Tenable, Palo Alto Prisma, PowerShell DSC, Git-based workflows, and CI/CD platforms.

Required Knowledge, Skills, and Abilities

· Minimum 5 years of demonstrated experience in all of the following areas: Cloud-native architectures, AWS, VPC, Security Groups, IAM, Docker, KMS, S3 Encryption, RDS Encryption, HTTPS, SSL Certificates, Data Lake security, CloudFormation, CloudFlare, CloudFront, API Gateway, Lambda, Egress proxies, application security, domain segmentation, authentication, data protection, and automation of processes.

· Experience using AWS Infrastructure-as-Code (IaC), Infrastructure-as-a-Service (IaaS), Platform-as-a-Service (PaaS) and Software-as-a-Service (SaaS).

· Research, Design, Development, Testing and Deployment experience using AWS IaaS, PaaS services, tools and technologies to support continuous integration and delivery on Linux Environment.

· Demonstrated ability to build and execute complex security plans in AWS.

· Experience working with compliance and regulatory requirements in AWS.

· Experience working in a risk-based environment including mitigation, planning, and implementation in AWS.

· Hands on experience with experience in Splunk, Nessus, Tenable Security Center, and firewall tools such as Palo Alto, Imperva, Fortinet, etc., * Bachelor’s (Preferred)

Security clearance:

  • Secret (Preferred)

Benefits & conditions

$150,000 - $180,000 a year - Full-time, Contract, Pulled from the full job description

  • Professional development assistance
  • 401(k)
  • Health insurance
  • Retirement plan
  • 401(k) matching
  • Paid time off
  • Vision insurance, * 401(k)
  • 401(k) matching
  • Dental insurance
  • Flexible spending account
  • Health insurance
  • Life insurance
  • Paid time off
  • Professional development assistance
  • Retirement plan
  • Vision insurance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · WWC 2025

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

2:34 min

Docker sandbox architecture and microVM environment integration

Manuel de la Peña Manuel de la Peña · WWC Europe 2026

Videos

See all

Related articles

See all