TL;DR
DevSecOps Compliance Engineer: Implementing and maintaining an automated compliance platform integrated with customer DevSecOps pipelines, focusing on AI-driven compliance automation and continuous monitoring. Focus on integrating security controls, automating compliance documentation, and ensuring real-time compliance validation within CI/CD workflows.
Location: Onsite in Annapolis Junction, Maryland, United States
Company
hirify.global provides AI-powered decision intelligence solutions for national security and complex mission environments, headquartered in McLean, Virginia.
What you will do
- Integrate ATO Automation platform with CI/CD pipelines and DevOps toolchains (GitHub, GitLab, Jenkins)
- Configure automated security control validation and continuous compliance monitoring with cloud APIs (AWS, Azure)
- Automate System Security Plan generation and maintain compliance documentation synchronization
- Establish security gates and remediation workflows within CI/CD pipelines
- Collaborate with development teams to address compliance gaps
- Deploy integrations with security scanning and container security tools
Requirements
- Active TS/SCI with Poly clearance required
- Experience with CI/CD platforms and Infrastructure as Code tools (Terraform, CloudFormation)
- Deep knowledge of NIST 800-53 Rev 5 and FedRAMP compliance
- Proficiency with containerization and orchestration (Docker, Kubernetes, OpenShift)
- Strong scripting skills for automation (Python, Bash, PowerShell)
- Familiarity with security scanning tools and Git version control
Nice to have
- Experience with LLM-based automation and RAG architectures
- Prior federal compliance automation experience
- Knowledge of AWS GovCloud or Azure Government
- Relevant certifications (DevSecOps, AWS Security Specialty, Azure Security Engineer)
- Experience with SIEM platforms and zero-trust architecture
Culture & Benefits
- Work onsite in Maryland with support for multiple customers in the Baltimore/Washington corridor
- Equal opportunity employer supporting protected groups and veterans
Будьте осторожны: если вас просят войти в iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →