Jobs · Engineering

DevSecOps Project Lead (Sr DevSecOps Engineer)

DEFCON AI · McLean, VA · 3 wk ago
RemoteRemoteEngineering$175k–$215k/yrFull-time

DEFCON AI is an insights company leveraging artificial intelligence, mathematical optimization, data analytics, and software engineering to enable resilient optimization of complex systems. Our technology aligns outcomes with operational goals, enhances decision-making, and empowers customers to anticipate, assess, and mitigate disruptions.

About the Role

As DevSecOps Lead, you will build and operate the delivery platform for a new AI-enabled program in a government cloud environment. This includes the CI/CD pipeline, infrastructure, security controls, and artifacts supporting authorization. The role spans modern DevOps practices and Department of Defense (DoD) deployment at Impact Level 5 (IL-5), requiring sound decisions across government networks, cloud environments, and container strategy. You will make architecture decisions and implement them hands-on, engineering security from the outset. As the program scales, you will lead a small team of platform, cloud, and cyber engineers while serving as the engineering counterpart to the customer’s security and accreditation staff. This fully remote role requires up to 25% travel to DEFCON AI HQ, customer sites, and vendor facilities.

Responsibilities

  • First Deliverable: Platform Into the Government Environment
    • Own the initial platform deployment into the government IL-5 environment as the program’s first contract deliverable.
    • Build and validate the pipeline and infrastructure as code on commercial cloud first, using portable templates for seamless government deployment.
    • Deploy early to identify and address network, security, and interface constraints proactively.
    • Track and drive government-side prerequisites, including account provisioning, network paths, certificates, approved services, base-image sources, container registry access, scanning-tool approvals, and package-repository egress policies.
  • Platform and Pipeline Ownership
    • Own the end-to-end CI/CD pipeline, including build, test, static/dynamic security analysis, software composition analysis, container and infrastructure-as-code scanning, SBOM generation, and gated production promotion.
    • Establish and operate development, test, and production environments in AWS GovCloud at IL-5.
    • Design the platform for reusability across programs.
  • Cloud and Infrastructure Architecture
    • Make architecture decisions for the delivery platform, including account/boundary structure, network paths, identity integration, container strategy, and hardened base images.
    • Work within approved-service lists and base-image sources, driving decisions to closure with customer cloud and security teams.
    • Design for zero-downtime deployment and rehearsed rollback.
    • Build observability into the platform with metrics, logging, tracing, and alerting to identify and resolve issues proactively.
    • Integrate CAC/PIV authentication and role-based access control.
  • Security Engineering and Authorization Support
    • Implement security controls from day one, generating control evidence continuously via the pipeline.
    • Own the security artifact package, including System Security Plan inputs, SBOMs, STIG/SCAP results, scan reports, test coverage, audit trails, and pipeline gate definitions.
    • Serve as the engineering counterpart to the customer’s security and accreditation staff, supporting authorization on their timeline.
    • Drive an evidence-based authorization approach, where assessors consume pipeline output directly.
    • Absorb cyber and RMF responsibilities for the program, with support from dedicated cyber staff as the team grows.
  • Release Management and Delivery Performance
    • Own the release cadence from capability intake to production deployment, aligning with commercial and government timelines.
    • Establish and report delivery/reliability metrics, including deployment frequency, lead time for change, change failure rate, and time to restore service.
    • Secure standing release approval or automated-change exemption to enable continuous delivery.
    • Integrate monitoring and alerting with the customer’s network and security operations centers.
  • Technical Leadership
    • Lead a small team of platform, cloud, and DevOps engineers, including partner/subcontractor staff, as the program scales.
    • Set engineering standards for environment parity, branching, release hygiene, secrets handling, and infrastructure as code.
    • Communicate status, risks, and tradeoffs clearly, escalating blockers early.

Requirements

  • 8+ years of DevOps/DevSecOps engineering experience, including owning a production pipeline end-to-end at scale.
  • 3+ years working in DoD or federal cloud environments at IL-4 or IL-5 (AWS GovCloud strongly preferred).
  • Hands-on leadership: you make architecture decisions and implement them directly.
  • Cloud/infrastructure expertise: containers (Docker, Kubernetes), infrastructure as code (Terraform, CloudFormation), CI/CD tooling, hardened base images, and image promotion.
  • Observability practice: instrument builds with metrics/logs to drive improvements proactively.
  • Security integration: treat scanning, compliance validation, and evidence generation as standard pipeline stages.
  • Direct experience supporting ATO/cATO or equivalent authorization, including producing assessor-accepted artifacts.
  • Proven ability to deploy under hard deadlines in environments with external dependencies (e.g., government accounts, approvals).
  • Ready on day one: adapt an existing pipeline pattern rather than researching from scratch.
  • Ownership mindset: drive work to completion, communicate status plainly, and operate independently.
  • Active US Secret clearance (required from day one for government cloud access).
  • US citizenship.
  • Willingness to travel up to 25% as required.

Preferred Qualifications

  • Active TS/SCI clearance.
  • Experience taking a program from an empty government cloud account to a deployed, authorized production system.
  • Hands-on management of ATO/cATO pathways, including continuous authorization models.
  • Knowledge of DoD impact-level boundaries and the Cloud Computing SRG.
  • Experience with Iron Bank container certification, STIG/SCAP tooling, ACAS, OpenSCAP, and FIPS requirements.
  • Experience with AWS Bedrock or comparable managed inference services in government environments.
  • Familiarity with government secure-software platforms (e.g., Second Front/Game Warden, Stormbreaker, Black Pearl).
  • Experience integrating with enterprise ICAM/IdP services and DoD PKI.
  • Experience working alongside partner/subcontractor engineering teams.
  • Experience delivering into high-volume federal case-processing or workflow environments handling sensitive data.

What Success Looks Like

  • A hardened pipeline deploying end-to-end within the first month, with active security gates and automated authorization evidence generation.
  • Platform deployed into the government IL-5 environment on schedule, with constraints surfaced and resolved early.
  • Authorization evidence accepted by assessors as produced, without manual reassembly.
  • Zero critical/high vulnerabilities at delivery, enforced by the pipeline on every build.
  • Application teams never blocked on environments or deployments, as the platform is ready ahead of need.
  • A reusable platform and practices for future programs.

Benefits

  • Fully remote, results-based environment.
  • Competitive salary, bonus, and equity package.
  • 100% employer-paid comprehensive health insurance (medical, dental, vision) for you and your family.
  • Unlimited PTO (with manager approval).
  • Flexible work environment with self-managed schedules.
  • 14 weeks of fully paid parental leave.

Pay

Salary range: $175,000–$215,000, based on experience, skills, and other factors.

Similar jobs

Lead DevSecOps Engineer

The Depository Trust & Clearing Corporation (DTCC)Jersey City, NJ· 1 mo ago
Information Technologyapply on ebxr.fa.us2.oraclecloud.com