Назад
Company hidden
3 часа назад

DevSecOps Engineer (Cloud Security)

179 000 - 192 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
DevSecOps Engineer (Cloud Security): Securing CI/CD pipelines for the Department of Veterans Affairs supply chain and logistics systems with an accent on automated security controls, cloud security, compliance evidence, and vulnerability remediation. Focus on implementing Guardrails-as-Code, securing AWS and Azure environments, supporting ATO and FedRAMP requirements, and responding to incidents across federal Agile delivery teams.

Location: Remote within the continental United States (CONUS) or Rockville, Maryland. Travel up to 10%.

Salary: $179,000–$192,000 per year, with potential additional compensation and benefits.

Company

hirify.global provides technology services supporting federal government missions, including the Department of Veterans Affairs Supply Chain Management DevSecOps program.

What you will do

  • Embed Guardrails-as-Code, SAST/DAST scanning, SBOM generation, policy gates, secrets management, and artifact signing into CI/CD pipelines.
  • Harden container images and infrastructure, automate configuration drift detection, and enforce DISA STIG and CIS benchmarks.
  • Track and remediate vulnerabilities within five days for Critical findings and ten days for High findings.
  • Automate security evidence collection for Continuous Assessment and Authorization, ATO, VA, and FedRAMP compliance.
  • Implement Zero Trust, identity and access controls, logging, encryption, network segmentation, and cloud security across AWS, Azure, and VA Enterprise Cloud.
  • Support incident response, secure coding guidance, AI-generated code validation, technical proposals, mentoring, and after-hours escalation rotations.

Requirements

  • 7+ years of experience in IT security or DevSecOps, including at least four years integrating security controls into CI/CD pipelines for federal Agile or SAFe programs.
  • Hands-on experience with SAST/DAST, container scanning, secrets management, SBOMs, Ansible, Terraform, Splunk, HashiCorp Vault, mutual TLS, and ICAM/PIV.
  • Experience with NIST RMF, ATO, POA&Ms, continuous control evidence, DISA STIG, CIS benchmarks, and vulnerability remediation.
  • Cloud security experience across AWS, Azure, and VA Enterprise Cloud, including IAM, encryption, and network segmentation.
  • Bachelor’s degree in cybersecurity, computer science, computer engineering, information systems, or a related field; a master’s degree is preferred.
  • Tier 2 / Moderate Risk Background Investigation and the ability to obtain a VA PIV credential are required.

Nice to have

  • Experience securing VA supply chain systems or HL7/FHIR healthcare APIs.
  • Experience with one-hour incident response requirements and validation of AI-generated code.
  • CISSP or Security+, AWS or Azure associate-level certifications, and Red Hat or Ansible certifications.

Culture & Benefits

  • Mission-driven work supporting the Department of Veterans Affairs and supply chain logistics.
  • Remote working options, paid time off, paid holidays, military leave, and disability coverage.
  • Healthcare benefits, HSA and FSA options, paid life insurance, and a 401(k) match.
  • Training and certification opportunities, tuition reimbursement, internal mobility, and an employee assistance program.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →