DevSecOps Engineer-Experienced
Pratt Miller, an Oshkosh Company, is a product-development firm serving the motorsports, defense, and mobility industries. We provide clients with end-to-end engineering, prototype manufacturing, test & validation, and low-rate production solutions that accelerate high-quality product delivery.
About the role
As a DevSecOps Engineer, you will implement secure development pipelines, automation frameworks, and compliant infrastructure to support defense programs operating under CMMC Level 2 and NIST 800-171/172 requirements. This hands-on role integrates security controls into cloud and on-prem environments, supports continuous monitoring and vulnerability management, and ensures systems hosting Controlled Unclassified Information (CUI) meet mission-critical performance and cybersecurity standards. You will collaborate closely with software, IT, and security teams to deliver resilient, secure, and auditable solutions across defense projects.
Responsibilities
- Design, implement, and maintain secure DevSecOps infrastructure and delivery pipelines for defense programs under CMMC Level 2 compliance.
- Implement security controls and automation within CI/CD pipelines using GitLab and related DevSecOps tooling.
- Ensure adherence to secure coding practices, NIST SP 800-171/172, and CMMC Level 2 cybersecurity standards across software development and infrastructure management.
- Collaborate with defense software and cybersecurity teams to integrate automated testing, vulnerability management, and secure deployment strategies into cloud and on-prem environments.
- Assist in identifying technologies and tools that enhance security posture, automation, and compliance monitoring capabilities.
- Maintain a customer-focused view of system security and DevSecOps process effectiveness across defense project initiatives.
- Participate in technical and compliance reviews with customers and stakeholders to ensure systems meet mission-critical availability, reliability, and security requirements.
- Research and implement new technologies, security tools, and methodologies to enhance automation, compliance, and system resilience.
- Stay informed on evolving DoD cybersecurity standards, cloud governance models, and zero-trust architectures to ensure continuous compliance.
- Work across multidisciplinary engineering and IT teams, integrating security controls within development and operational environments.
- Collaborate with network, software, and security engineers to ensure end-to-end protection of systems hosting Controlled Unclassified Information (CUI).
- Participate in design and code reviews, infrastructure planning meetings, and post-implementation security assessments.
- Work effectively with remote and hybrid teams using collaboration tools such as MatterMost and GitLab.
- Demonstrate strong analytical thinking and problem-solving skills to address complex infrastructure and cybersecurity challenges.
- Leverage automation and monitoring to proactively identify and resolve performance or compliance issues within DevSecOps pipelines.
- Document configurations, compliance evidence, and standard operating procedures.
- Clearly explain complex security concepts to both technical and non-technical audiences.
Requirements
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field; advanced degree preferred.
- Must meet requirements for obtaining a U.S. Government clearance; active Secret or higher clearance preferred.
- Experience developing and maintaining secure CI/CD pipelines using GitLab, Jenkins, or Azure DevOps.
- Experience implementing automated security testing tools (SAST, DAST, SCA) and vulnerability management systems.
- Experience with CMMC Level 2 or NIST 800-171 compliance in defense or government environments.
- Experience managing secure infrastructure in AWS GovCloud, Azure Government, or on-prem DoD-accredited environments.
- Deep understanding of DevSecOps principles, CI/CD, and automation frameworks.
- Expertise in network architecture and security (TCP/IP, VLANs, VPNs, firewalls, IDS/IPS systems).
- Active Directory and Group Policy administration for secure identity and access management.
- Experience implementing zero-trust and least-privilege access models.
- Knowledge of cloud security configurations, infrastructure-as-code (Terraform, Ansible), and container orchestration (Docker, Kubernetes).
- Familiarity with CMMC Level 2, DFARS 252.204-7012, and DoD cybersecurity frameworks.
Skills
- Networking/Infrastructure/Security: TCP/IP, VLAN, VPN, DNS, zero-trust networking; firewalls; IDS/IPS; endpoint protection; Active Directory/Azure AD; log aggregation and monitoring (Prometheus, Kibana, Splunk, Jaeger).
- DevSecOps / Automation Tools: GitLab, Jenkins, Azure DevOps, Nexus, Ansible, Terraform; Docker and Kubernetes; SAST/DAST/fuzz testing/SBOM tools; OpenTelemetry; Prometheus; collaboration tools including MatterMost and Jira/Atlassian.
- Cloud Platforms: AWS GovCloud (EC2, Lambda, Route 53, ECR, CloudTrail); Azure Government (Virtual Machines, IoT Hub, Functions, CosmosDB, Azure Security Center).
Schedule
- Standard daytime schedule Monday–Friday, with flexibility for surge requirements or deadline-driven tasks.
- On-site position in New Hudson, MI.
- Some travel for customer engagement, system integration, or compliance activities.
Pay
The pay range reflects the minimum and maximum target pay for the position across all U.S. locations. Individual pay is determined by factors including the scope and responsibilities of the role, the candidate's experience, education, skills, and equity among team members in similar positions.