Назад
Company hidden
2 дня назад

DevSecOps Engineer

110 000 - 160 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
UK/US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
DevSecOps Engineer (Cloud Security/CI/CD): Building secure CI/CD pipelines and automating compliance, vulnerability scanning, and infrastructure security across classified and unclassified environments with an accent on Kubernetes, infrastructure-as-code, and cloud security. Focus on integrating shift-left security controls, supporting RMF/ATO and CMMC requirements, and hardening disconnected and production systems at scale.

Location: Washington D.C., United States; travel up to 15% CONUS may be required for program site integrations, customer engagements, and security architecture reviews.

Salary: $110,000–$160,000 per year

Company

hirify.global develops defense products powered by Coherent Distributed Networks for warfighters, commercial air operators, and border protection teams.

What you will do

  • Design and maintain secure CI/CD pipelines with SAST, DAST, SCA, secrets detection, and automated vulnerability scanning.
  • Automate STIG/SRG validation, policy-as-code enforcement, compliance controls, evidence collection, and continuous monitoring for cloud and on-premise systems.
  • Partner with software engineers on vulnerability remediation, threat modeling, secure coding practices, and security training.
  • Harden containerized environments, Kubernetes configurations, registries, images, and runtime protection controls.
  • Build secure infrastructure-as-code with Terraform, CloudFormation, or Ansible, including least-privilege access and secrets management.
  • Monitor security tooling and pipeline metrics, produce remediation reports, and coordinate with ISSM, ISSO, and system administration teams.

Requirements

  • Bachelor’s degree in Computer Science, Software Engineering, Cybersecurity, or a related field; equivalent experience may be considered.
  • 4–7 years of experience in DevOps, software engineering, or cybersecurity, including security tooling integration into CI/CD pipelines and cloud environments.
  • Proficiency in Python, Bash, Go, or an equivalent scripting or programming language.
  • Hands-on production experience with Docker and Kubernetes security hardening, image scanning, and runtime protection.
  • Working knowledge of AWS GovCloud or Azure Government security, including IAM, network security, monitoring, and secrets management.
  • Eligibility for Security Clearance is required.

Nice to have

  • Active TS clearance and experience with NIST RMF/ATO, CMMC Level 2/3, and DFARS requirements.
  • Experience with GitOps, policy-as-code, SBOM generation, artifact signing, and dependency provenance tracking.
  • Experience with classified or air-gapped environments and disconnected CI/CD toolchains.
  • Security+, AWS Security Specialty, or equivalent certification.

Culture & Benefits

  • Medical, dental, and vision benefits fully paid by the company.
  • 401(k) with a 50% company match up to 6% of pay, plus FSA, HSA, and life insurance.
  • Unlimited PTO, free daily lunch, casual dress code, and no-meeting Fridays.
  • Relocation assistance, pre-IPO stock option grants, and annual bonuses planned.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →