Jobs · Engineering · Virginia

DevSecOps Engineer - SME

Dark Wolf · Herndon, VA · 6 days ago
Engineering$185k–$240k/yrFull-time

Dark Wolf constructs and deploys data management and analytics solutions for the defense and intelligence communities. We’re proud to boast a world-class engineering team that thrives on rolling up their sleeves to solve your mission’s biggest challenges.

About the role

Dark Wolf is seeking a DevSecOps Subject Matter Expert (SME) to architect, lead, and optimize Continuous Integration/Continuous Deployment (CI/CD) tooling, security paradigms, and operational observability across the entire software development lifecycle. In this role, you will serve as the principal authority on modern DevSecOps strategies, driving shift-left security practices, zero-trust architectures, and high-reliability platform engineering. We are seeking a technical leader and strategic problem solver capable of delivering superior, high-impact results across high-performing teams in fast-paced environments.

Responsibilities

  • Enterprise CI/CD Strategy & Operations: Architect, maintain, and optimize mission-critical CI/CD pipelines and infrastructure, leveraging tools such as Jenkins, GitLab CI/CD, and enterprise automation engines.
  • Automated Security Integration & Continuous ATO: Spearhead the seamless integration of dynamic security tools and automated governance into pipelines—including SAST, DAST, dependency scanning, and container analysis—to support Continuous Authority to Operate (cATO).
  • Testing & Quality Framework Design: Establish and maintain comprehensive automated testing architectures covering unit testing, integration testing, and User Acceptance Testing (UAT).
  • Vulnerability & Threat Remediation: Lead cross-functional collaboration with software development and security teams to proactively identify, prioritize, and remediate application and infrastructure vulnerabilities.
  • Governance & Standards Compliance: Define and enforce compliance strategies aligned with federal security regulations, DoD guidelines, and strict agency security standards.
  • Technical Leadership & Innovation: Drive DevSecOps roadmaps, evaluate cutting-edge tools, define infrastructure-as-code (IaC) governance, and mentor multi-disciplinary engineering teams.

Requirements

  • Clearance: Must be a US Citizen holding an active TS/SCI security clearance with an active Full-Scope Polygraph.
  • Education: Bachelor's degree in Computer Science, Information Systems, Engineering, or a related technical field.
  • Experience: Minimum 15+ years of total technical experience, with at least 7+ years specializing in building, securing, and maintaining automated CI/CD pipelines.
  • Infrastructure Automation: Minimum 7+ years of hands-on experience using automation tools for infrastructure provisioning and configuration management (e.g., Terraform, Ansible).
  • Source Control & Developer Tooling: Expert-level proficiency with version control systems and ecosystem platforms (e.g., Git, GitLab, Jira).
  • Systems & Networking Mastery: Strong understanding of Containerization, Linux systems administration, kernel-level operations, and fundamental networking protocols.
  • Communication & Leadership: Superior problem-solving skills and excellent communication abilities to articulate complex technical architectures, risks, and strategies to executive leadership, technical teams, and government stakeholders.
  • Security Discipline: Deep commitment to adhering to strict security protocols, defensive systems design, and DoD/IC best practices.

Skills

  • Continuous ATO (cATO) & Compliance-as-Code: Proven expertise translating NIST SP 800-53, DISA STIGs, and CNSSI 1253 controls into automated pipeline validation checks (e.g., using OSCAL, Open Policy Agent).
  • Air-Gapped & High-Security Environment Engineering: Hands-on experience designing, deploying, and maintaining CI/CD pipelines and mirror repositories within disconnected, air-gapped, or Cross Domain Solution (CDS) networks.
  • Advanced Container Orchestration Security: Expert-level knowledge of Kubernetes security architectures, Service Mesh traffic policies (Istio), Admission Controllers (OPA/Gatekeeper, Kyverno), and runtime security tooling (Falco).
  • Zero Trust & Secrets Lifecycle Management: Architecture experience implementing identity-aware security models and enterprise secrets management solutions (HashiCorp Vault, AWS Secrets Manager) for automated dynamic secret rotation.

Desired Qualifications

  • Programming & Scripting: Strong proficiency in programming/scripting languages such as Python, Go, Bash, or C/C++.
  • Containerization: Deep practical experience with containerized software practices and container runtimes (Docker, Podman, Kubernetes).
  • Agile Frameworks: Experience driving outcomes within Agile, Scrum, or SAFe software engineering methodologies.
  • Multi-Cloud Architecture: Direct experience architecting secure cloud platforms across AWS, Azure, GCP, or specialized IC cloud environments (C2S/GovCloud).
  • Security Scanning Tooling: Deep familiarity with modern vulnerability management and static/dynamic scanning tools (e.g., SonarQube, Snyk, Trivy, OWASP ZAP, Fortify).
  • Advanced Certifications:
    • Certified Kubernetes Security Specialist (CKS) or Certified Kubernetes Administrator (CKA)
    • Certified Information Systems Security Professional (CISSP)
    • AWS Certified DevOps Engineer – Professional
    • CompTIA Security+ or GIAC DevSecOps Automation (GCSA)

US Citizenship with an active TS/SCI security clearance with Full-Scope Polygraph is required.

Pay

Target Salary Range: $185,000.00 – $240,000.00+ (commensurate with specialized expertise and technical skillset).

Location

Chantilly/Herndon, VA.

Similar jobs

DevSecOps Engineer SME

Modern Technology Solutions, Inc. (MTSI)Huntsville, AL· 2 mo ago
Engineeringapply on mtsi-va.eightfold.ai

DevSecOps Engineer

InadevReston, VA· Yesterday
Engineeringapply on recruiting.paylocity.com

DevSecOps Engineer

Core4ceUnited States· 2 days ago
RemoteEngineering$110k–$180k/yrapply on jobs.silkroad.com