We are building a team for one of the U.S. Federal Government's largest technology modernization programs, underpinning the U.S. capital markets.
Built on AWS and leveraging an AI-powered software engineering platform, this program offers a unique opportunity to gain hands-on experience with next-generation AI, Agentic AI, cloud technologies, and AI-driven engineering.
If you are looking for technically challenging work, exceptional learning, and a résumé-defining opportunity with national impact, I would love to connect.
Job Title: DevSecOps Engineer
Position Type: Full-Time
Location: Hybrid – Reston, Virginia, and client locations in the Washington, D.C. metropolitan area
Days Remote: 2–3 days remote
Position Summary:
The DevSecOps Engineer is responsible for building and operating secure software delivery pipelines for an AWS-based platform. This role implements CI/CD automation, infrastructure as code, security scanning, policy enforcement, and automated environment provisioning using AWS-native technologies. The DevSecOps Engineer works closely with development, security, and engineering teams to embed shift-left security practices throughout the software development lifecycle, support secure and reliable deployments, and automate compliance evidence for FedRAMP and NIST requirements. The role also leverages AI-assisted tools, where appropriate, to improve pipeline development, testing, security scanning, and delivery efficiency.
Key Responsibilities:
• Build, maintain, and optimize CI/CD pipelines using AWS CodePipeline and AWS CodeBuild.
• Implement infrastructure as code using AWS CDK and AWS CloudFormation.
• Automate provisioning, configuration, and deployment of application environments.
• Integrate Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), and other security checks into CI/CD pipelines.
• Implement policy-as-code controls within the software delivery pipeline.
• Automate the collection and management of compliance evidence supporting FedRAMP and NIST security controls.
• Support deployment automation using blue/green and canary deployment strategies.
• Embed shift-left security practices throughout the software development lifecycle.
• Develop automation scripts using Python, Bash, or similar scripting languages.
• Utilize AI-assisted tools to improve pipeline development, security scanning, testing, and operational efficiency.
• Monitor pipeline health, troubleshoot failures, and continuously improve delivery performance.
• Collaborate with software developers, architects, and security teams to support secure application releases.
• Maintain documentation for CI/CD pipelines, infrastructure automation, deployment procedures, and security integrations.
• Participate in Agile ceremonies, technical reviews, and continuous improvement initiatives.
Minimum Experience:
• 3+ years of DevOps, DevSecOps, cloud engineering, or related experience.
• Hands-on experience with AWS, CI/CD pipelines, and infrastructure-as-code.
• Experience integrating security automation into software delivery pipelines.
• Experience developing automation using Python, Bash, or similar scripting languages.
Mandatory Skills:
• AWS cloud services.
• CI/CD pipeline development and support.
• AWS CodePipeline.
• AWS CodeBuild.
• Infrastructure as Code (AWS CDK and/or AWS CloudFormation).
• Security automation within CI/CD pipelines.
• Python, Bash, or similar scripting language.
• U.S. Citizenship.
• Ability to obtain and maintain a U.S. Government security clearance.
• Ability to work a hybrid schedule in Reston, Virginia and client locations in the Washington, D.C. metropolitan area.
Nice-to-Have Skills:
• Static Application Security Testing (SAST).
• Dynamic Application Security Testing (DAST).
• Software Composition Analysis (SCA).
• Policy-as-Code.
• FedRAMP compliance.
• NIST security controls.
• Automated compliance evidence collection.
• Blue/green and canary deployment strategies.
• AI-assisted DevSecOps, testing, or security tooling.
• AWS Certified DevOps Engineer – Professional.
• AWS Certified Security – Specialty.
• Federal government or federal contracting experience.
• Strong communication and collaboration skills.
Degrees and Certifications
Required
• No specific degree or certification requirement was stated.
• Equivalent professional experience will be considered.
Preferred
• AWS Certified DevOps Engineer – Professional.
• AWS Certified Security – Specialty.
• Other relevant AWS, DevOps, or cloud security certifications.