SonicJobs Logo
Left arrow iconBack to search

DevSecOps Engineer Role

OpenDataJobs
Posted a month ago, valid for 25 days
Location

Washington, DC, US

Salary

Competitive

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • DevSecOps Engineers ensure secure and repeatable software delivery by designing CI/CD paths and operational feedback loops.
  • The role requires hands-on experience with automated testing, CI/CD, and deployment automation, along with infrastructure-as-code tools like Terraform or AWS CloudFormation.
  • Candidates should have a working knowledge of container security and vulnerability remediation, as well as experience with logging and incident response practices.
  • Compensation details vary by opening, but the salary for this role typically ranges around $100,000 to $150,000 annually.
  • Applicants should have at least 3-5 years of relevant experience and the ability to translate NIST control expectations into engineering work.

The work

DevSecOps Engineers make secure delivery repeatable. They design the CI/CD paths, deployment controls, and operational feedback loops that carry software from a change in source code to a running service. In federal environments, that work also includes assembling and maintaining security evidence for an Authority to Operate (ATO), the formal decision to allow a system to operate at an accepted level of risk.

The role works across development, operations, and security. DevSecOps Engineers automate build, test, deployment, configuration, vulnerability management, logging, and recovery practices so teams can release with visible controls and usable evidence. They partner with Cloud Infrastructure Engineers who provide the underlying platform, while they own the delivery path and its security integration.

What you'll build

路聽聽聽聽聽聽聽 CI/CD pipelines that run tests, security checks, approvals, and deployments consistently.

路聽聽聽聽聽聽聽 Infrastructure-as-code modules and deployment patterns that are versioned and reviewable.

路聽聽聽聽聽聽聽 Container build, image-scanning, and release processes for application workloads.

路聽聽聽聽聽聽聽 Observability and vulnerability-management workflows that turn operating signals into action.

路聽聽聽聽聽聽聽 Control evidence and traceability that support authorization, assessment, and continuous monitoring.

Who you are

You treat security, reliability, and delivery speed as one engineering problem. You look for manual deployment steps, unreviewed configuration changes, and missing evidence because each makes a system harder to operate and defend.

You can work across specialties without blurring accountability. You understand enough application engineering, cloud infrastructure, and security practice to create a dependable delivery system, communicate tradeoffs clearly, and help teams use it.

What you bring

路聽聽聽聽聽聽聽 Hands-on experience with source control, automated testing, CI/CD, and deployment automation.

路聽聽聽聽聽聽聽 Infrastructure-as-code experience with tools such as Terraform, Amazon Web Services CloudFormation, or comparable platforms.

路聽聽聽聽聽聽聽 Working knowledge of container security, software supply-chain controls, and vulnerability remediation.

路聽聽聽聽聽聽聽 Experience with logging, monitoring, incident response, and recovery practices.

路聽聽聽聽聽聽聽 Ability to translate National Institute of Standards and Technology (NIST) Special Publication 800-53 control expectations into engineering work and evidence.

About OPEN Data Jobs

OPEN Data Jobs connects AI, data, and software professionals with critical roles, primarily in the federal sector. Registering with ODJ can put your profile in view for multiple positions across several clients.

Register for DevSecOps Engineer Role

Click Apply below to register for DevSecOps Engineer Role.

What openings may require

Some openings may ask for experience supporting an ATO or working with the Risk Management Framework, a structured NIST process for managing security risk. Others may focus on a specific cloud, orchestration platform, programming language, or delivery toolchain.

Openings with production accountability may require demonstrated work with on-call operations, incident response, security assessments, or regulated release controls. Requirements should distinguish responsibility for the delivery pipeline from responsibility for the underlying cloud environment or independent security assessment.

Compensation, benefits, work location, and employment terms are set for each specific opening and will be stated with that opening




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.