Senior DevSecOps Engineer
Mount Laurel, New Jersey, United States
Full Time Senior-level / Expert Clearance required USD 129K - 241K *
Innovative Defense Technologies (IDT)
Innovative Defense Technologies (IDT) develops state-of-the-art automated solutions, enabling the rapid delivery of warfare capabilities for the DOD.- Infrastructure as Code (IaC): Contribute to the development and maintenance of automation for provisioning and updating the S3C stack and Kubernetes-based deployments.
- Security Automation: Develop and maintain advanced automated security testing processes, including static code analysis, static application security testing (SAST), software composition analysis (SCA), and security scanning for containers and infrastructure.
- CI/CD Pipeline Security: Integrate security checks at various stages of the CI/CD pipelines to ensure that security assessments are performed automatically during code build, testing, and deployment.
- Infrastructure Security: Implement advanced security controls and best practices for cloud infrastructure, virtual machines, and container environments to safeguard against unauthorized access and data breaches in the S3C.
- Vulnerability Management: Identify, prioritize, and remediate security vulnerabilities across the development and testing environments. This includes coordinating with developers and operations teams to address critical issues promptly.
- Security Compliance: Collaborate with internal Cyber/Compliance/SECOPs groups to ensure that software and infrastructure meet relevant security compliance standards and regulations, such as DISA STIGs.
- Identity and Access Management (IAM): Manage access controls and permissions for users and applications, employing principles like least privilege and role-based access control (RBAC).
- Continuous Improvement: Continuously evaluate and enhance our DevSecOps practices, tools, and processes to adapt to evolving security threats and industry best practices.
- Minimum 10 years of experience in DevOps/DevSecOps or full-stack software development and test.
- B.S. in a software engineering field.
- Proven experience with containerization technologies like podman and Docker.
- Strong experience with virtualization (hypervisor) environments such as VMware.
- Advanced proficiency in Linux and Windows.
- Extensive experience in software development processes, version control systems (e.g., Git), and coding and scripting languages such as Python, Ruby, JavaScript, Shell scripting, etc.
- In-depth experience working with software development tools such as Jenkins, Maven, Gradle, Nexus, etc.
- Strong working knowledge of Dev[Sec]Ops and CI/CD practices.
- Experience with Infrastructure as Code (IaC) and automation tools such as Ansible or Puppet.
- Familiarity with various security concepts, vulnerabilities, and best practices.
- Ability to travel approximately 10%.
- Extensive experience in DevSecOps and CI/CD.
- Advanced experience with Infrastructure as Code (IaC) and automation software such as Ansible or Puppet.
- Experience with advanced security testing tools such as SAST (Static Application Security Testing), DAST (Dynamic Application Security Testing), SCA (Software Composition Analysis), and other vulnerability scanning tools.
- Familiarity with container orchestration platforms like Kubernetes.
- Strong understanding of common security threats and how to mitigate them, as well as familiarity with security frameworks and standards like OWASP and NIST.
- Experience with industry-specific security compliance standards and regulations, such as DISA.
- Knowledge of network security concepts, firewalls, VPNs, and intrusion detection/prevention systems (IDS/IPS).
- Expertise in authentication mechanisms (e.g., OAuth, SAML) and authorization protocols (e.g., RBAC, ABAC).
- Leadership and Communication Skills: Excellent communication skills and the ability to work effectively in a collaborative, fast-paced, and mission-driven environment while providing leadership and mentoring to the team.
- Advanced Problem-Solving Skills: Ability to think critically about security risks and develop solutions to mitigate them.
- Adaptability and Learning: A willingness to adapt to new technologies and stay up to date with the latest security trends and best practices.
- Team Player and Independent Worker: Capable of working independently but thrive in a team environment, demonstrating leadership when needed.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Ansible Application security Automation CI/CD Clearance Cloud Code analysis Compliance DAST DevOps DevSecOps DISA Docker DoD Firewalls Full stack IAM IDS Intrusion detection IPS JavaScript Jenkins Kubernetes Linux Maven Network security NIST OKR OWASP Puppet Python Ruby SAML SAST Scripting SDLC SecOps Security assessment Security Clearance STIGs Travel VMware VPN Vulnerabilities Vulnerability management Windows
Perks/benefits: Career development
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.