Назад
Company hidden
6 дней назад

Mid-Level Security Engineer (DevSecOps)

135 000 - 150 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Mid-Level Security Engineer (DevSecOps): Performing hands-on security analysis, vulnerability testing, and DevSecOps integration across GitLab CI/CD and a large Kubernetes environment with an accent on container security, AI artifact scanning, and federal compliance. Focus on configuring automated security gates, correlating findings across Wiz, Snyk, DSPM, SIEM, and vulnerability-management platforms, and producing evidence for ATO and FISMA reporting.

Location: Alexandria, VA, United States

Salary: $135,000–$150,000 USD per year

Company

hirify.global is a mission-driven IT services company and systems integrator supporting digital transformation and modernization for federal government agencies.

What you will do

  • Operate and maintain Wiz Code security gates in the GitLab CI/CD software factory, including container image scanning and infrastructure-as-code analysis.
  • Run Snyk Agent Scan on AI artifacts such as prompt files, cursor rules, Copilot instructions, and MCP configuration files.
  • Maintain Kubernetes security posture through admission controls, runtime monitoring, container vulnerability management, and RBAC.
  • Correlate DSPM, Axonius, Tenable, XSIAM, and QRadar data to prioritize remediation, triage alerts, and update POA&M records.
  • Support Netskope FedRAMP High CASB administration, including DLP policy tuning, violation investigations, and exception documentation.
  • Perform audits, risk analysis, vulnerability testing, code reviews, ATO and SSP documentation, FISMA reporting, and security work within Agile sprints.

Requirements

  • Bachelor’s degree with 5 years of relevant experience, or a master’s degree with 3 years of relevant experience in cybersecurity, information assurance, or a related technical field.
  • Active CISSP certification required.
  • Hands-on experience with GitLab CI/CD security, SAST/DAST, container scanning, IaC analysis, and DevSecOps software factories.
  • Working knowledge of Kubernetes security, including admission controllers, runtime scanning, container vulnerability management, and RBAC.
  • Familiarity with SIEM and ITSM remediation workflows, including security finding triage and POA&M tracking.
  • Knowledge of NIST SP 800-53, FedRAMP, federal ATO processes, Python or Bash, REST APIs, Git workflows, GitLab CI YAML, and JSON analysis.

Nice to have

  • Experience with Wiz, Snyk Agent Scan, Netskope CASB, Axonius, or Tenable in federal or FedRAMP-authorized environments.
  • Experience securing AI infrastructure such as AWS Bedrock, SageMaker, or API gateway brokered services.
  • Additional certifications such as CKS, AWS Security Specialty, CEH, OSCP, or CompTIA Security+.
  • Experience with federal civilian agencies, policy-as-code, Kubernetes admission tooling, secrets detection, SBOMs, or dependency analysis.

Culture & Benefits

  • Mission-driven work supporting federal public-sector modernization and community-focused outcomes.
  • Employee-first environment based on trust, ownership, collaboration, and meaningful work.
  • Opportunity to contribute ideas, develop technical skills, and make an impact from the start.
  • Equal employment opportunity and accommodation support throughout the hiring process.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →