DevOps Engineer - Level 6
This position is located in Redondo Beach, CA. Relocation assistance may be available. An active SCI clearance is required for start; candidates must have an active TS clearance at time of application with the ability to obtain SCI within a reasonable period. Travel is required, approximately 10% of the time.
About the role
At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come. Our pioneering and inventive spirit has enabled us to be at the forefront of many technological advancements in our nation's history. We look for people who have bold new ideas, courage, and a pioneering spirit to join forces to invent the future, and have fun along the way. Our culture thrives on intellectual curiosity, cognitive diversity, and bringing your whole self to work.
This position is contingent upon capturing program award(s) and obtaining and maintaining associated business and/or customer funding. Continued employment will be subject to maintenance of the required clearance and program access level.
Responsibilities
- Design, develop, and maintain secure containerized software components to be deployed in cloud environments.
- Implement and maintain Kubernetes (or equivalent) clusters, including networking, security, and observability.
- Build and maintain CI/CD pipelines that enforce security gates and automated testing.
- Perform security assessments on containerized applications and cloud deployments; drive remediation efforts.
- Develop and maintain infrastructure as code for repeatable, auditable deployments.
- Collaborate with software, systems, and security engineers to define secure architectures and deployment patterns.
- Document designs, security controls, and operational procedures for cloud-deployed container platforms.
Requirements
- 14 years of relevant experience with a Bachelor's degree; 12 years with a Master's degree; 10 years with a PhD; an additional 4 years of experience may be considered in lieu of a degree.
- Active SCI clearance at time of application or an active TS clearance with the ability to obtain SCI prior to start date.
- Experience developing, deploying, and maintaining containerized applications (e.g., Docker).
- Experience with container orchestration platforms (e.g., Kubernetes, OpenShift).
- Experience building software for deployment to a commercial or private cloud (AWS, Azure, GCP, or on-prem cloud).
- Experience developing CI/CD scripts to automate build processes (e.g., Jenkins, Python, GitLab).
- Experience with Linux administration and shell scripting.
- Familiarity with microservices architectures and RESTful APIs.
- Experience with CI/CD pipelines (e.g., GitLab CI, Argo CD, GitHub Actions, Jenkins, Azure DevOps).
- Knowledge of secure software development practices (DevSecOps, threat modeling, secure coding standards).
- Experience with vulnerability scanning tools and image security (e.g., Tenable Nessus, Trivy, Anchore, Aqua, Clair, Twistlock).
- Active Security+ Certification.
Preferred Qualifications
- Experience on Space-related programs.
- Experience with Kubernetes security and hardening (Pod Security Standards, network policies, admission controllers, service mesh).
- Experience with infrastructure-as-code tools (e.g., Terraform, CloudFormation, Ansible, Helm).
- Familiarity with security frameworks and standards (e.g., NIST, CIS Benchmarks, RMF, Zero Trust concepts).
- Experience integrating SAST/DAST tools into CI/CD (e.g., SonarQube, Checkmarx, OWASP ZAP, Burp Suite).
- Experience implementing supply chain security (XEOL, SBOMs, signed images, secure registries).
- Knowledge of container runtime security and monitoring (e.g., Falco, Sysdig, eBPF-based tools).
- Experience with logging, monitoring, and observability stacks (e.g., Splunk, Prometheus, Grafana, ELK/EFK, OpenTelemetry).
- Experience with API gateways and service meshes (e.g., Istio, Linkerd, Envoy) in a cloud environment.
- Familiarity with identity and access management in cloud platforms (IAM roles, policies, service principals).
- Familiarity with cloud networking concepts (VPCs, subnets, security groups, ingress/egress, load balancing).
- Experience working in regulated or high-assurance environments (defense).
- Experience creating, executing, and troubleshooting complex, automated processes used to configure servers and/or deploy code.
Pay
Primary level salary range: $192,800.00 - $289,200.00. The above salary range represents a general guideline; base salary offers consider the scope and responsibilities of the position, candidate's experience, education, skills, and current market conditions. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay. Annual bonuses are designed to reward individual contributions as well as allow employees to share in company results. Employees in Vice President or Director positions may be eligible for Long Term Incentives.
Benefits
- Health insurance coverage.
- Life and disability insurance.
- Savings plan.
- Company-paid holidays and paid time off (PTO) for vacation and/or personal business.