SonicJobs Logo
Left arrow iconBack to search

DevSecOps Engineer - 4173703

TCG, Inc.
Posted 2 days ago, valid for 19 days
Location

Washington, DC, US

Salary

Competitive

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • TCG, an award-winning B Corp government contractor, is seeking an experienced DevSecOps Engineer with at least five years of experience in the field.
  • The role involves designing, developing, and implementing solutions for government customers, primarily in a remote capacity with occasional onsite requirements near Washington, D.C.
  • Candidates must possess expertise in managing AWS ecosystems, containerized applications using Kubernetes and Docker, and implementing CI/CD pipelines.
  • The salary for this full-time position ranges from $140,000 to $155,000, and U.S. citizenship is required.
  • TCG is recognized for its employee-friendly practices and benefits, including healthcare, 401K, and a positive work/life balance.

You've stumbled upon the rare B Corp government contractor! At TCG, we aim to prove that businesses can be good to their employees and responsible to their community while being profitable. We're an award-winning IT solutions provider to the Federal government seeking a DevSecOps Engineer to join our project team.

This Position Description (PD) is for an experienced DevSecOps Engineer to help design, develop, and implement solutions for one of our government customers.

U.S. citizenship is required for this role. In addition, the selected applicant must submit to a government background investigation and be favorably adjudicated before their first day.

This is a full-time position. It is primarily a remote role. However, the selected candidate may be required to be on site occasionally and therefore must live within commuting distance of Washington, D.C.

RESPONSIBILITIES:

  • Design, implement, and maintain CI/CD pipelines in an AWS environment, leveraging tools like GitLab.
  • Manage and deploy containerized applications using Kubernetes and Docker in an AWS environment.
  • Configure and maintain AWS environments for various applications, including defining and applying baselines and security policies.
  • Implement security best practices throughout the DevSecOps lifecycle, focusing on vulnerability management and secure configuration.
  • Integrate SAST and DAST tools, such as Sonarqube and Invicti, into the CI/CD pipeline for analysis of code and container images.
  • Ensure application security specifically for containers in the Kubernetes and AWS environments.
  • Collaborate with development teams to resolve security vulnerabilities reported by tools like Tenable and track resolution progress.
  • Automate deployment and configuration management tasks across development, test, and production environments, leveraging tools like Ansible.
  • Implement and maintain monitoring and logging solutions (e.g. Splunk or ELK Stack) to ensure system uptime, performance, and application health.
  • Support platform operations, including updates, patching, and system maintenance for the underlying AWS cloud infrastructure.
  • Review and suggest improvements and changes to the current cloud architecture to aid in scaling cloud presence.

REQUIRED SKILLS:

  • Five (5) plus years of experience in DevSecOps engineering, with at least 3+ years managing and maintaining AWS ecosystems.
  • Expertise in managing and deploying containerized applications using Kubernetes and Docker.
  • Proficiency with AWS cloud security, including configuring baselines and security policies to create a Zero Trust Architecture for tools such as encrypted S3 buckets, IAM role, and service/network logging.
  • Proficiency in designing, implementing, and maintaining CI/CD pipelines using tools such as GitLab, and utilizing tools, such as Terraform or Cloud Formation, to implement an Infrastructure as Code methodology.
  • Hands-on experience with security scanning and analysis tools, including SAST/DAST (e.g., Sonarqube, Invicti) and vulnerability management (e.g., Tenable);
  • Ability to work in an agile or iterative development environment.
  • Experience authoring and debugging Dockerfiles for web applications, preferably for Docker images using Java or Angular.
  • Experience standing up and managing an AWS/Gitlab architecture, preferably in a non-DOD federal government space.

PREFERRED SKILLS:

  • DevSecOps relevant certifications in Cloud platforms (AWS preferred).
  • Experience ensuring application security for Java Spring Boot API containers.
  • Practice working with regulatory, legal, or government data sets.

EDUCATION:

  • Bachelor's degree in Information Systems, Computer Engineering, Computer Science or a related discipline.

TCG does not discriminate based on race, sex, color, religion, national origin, age, disability, caste, or veteran status.

Our B Corp mission is reflected in our benefits, including offerings like health care, 401K, parental leave, adoption assistance, financial planning services, student loan repayment assistance, and training budget. There's more, see for yourself.

TCG is recognized for treating employees well, in fact, in 2025 The Washington Post named TCG as a "Top Workplace" for the eleventh straight year based on how our employees feel about the company, the benefits TCG offers, and the work/life balance that our staff achieves. In the Washington Post Top Workplace survey, our CEO was ranked best by TCG employees' votes among all midsize companies.

Try us ... we'll make you happy.


Salary Range: $140,000 - $155,000




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.