DevSecOps / Security Engineer
About the role
Zantech is looking for a talented DevSecOps / Security Engineer to contribute to the success of our upcoming Technical Infrastructure and Platform Support project for an On-Site role based out of Arlington, VA. The DevSecOps / Security Engineer will play a crucial role in providing Technical Infrastructure and Platform Support and Cybersecurity and Information Assurance (RMF, continuous ATO, Compliance-as-Code). The DevSecOps / Security Engineer serves as the lead technical engineer for automation, CI/CD, and security posture of the cloud infrastructure, directly executing Technical Infrastructure and Platform Support requirements and supporting continuous Authority to Operate (ATO) under the DoD Risk Management Framework.
Responsibilities
- Build and maintain secure, automated CI/CD pipelines and zero-downtime deployment processes
- Automate infrastructure provisioning and configuration management via Infrastructure as Code
- Support the RMF process: System Security Plan, Security Assessment Report, and POA&M development and continuous monitoring
- Apply and automate DISA STIGs; run vulnerability scanning and manage remediation
- Integrate SAST/DAST testing and auto-generate compliance-as-code artifacts (e.g., Ports/Protocols/Services, topology diagrams) for eMASS
Required Experience
- 5 years in DevSecOps, including designing, implementing, and maintaining CI/CD pipelines and automating software deployment (Jenkins, GitLab CI/CD, or Ansible)
- 5 years supporting the Risk Management Framework (RMF) for DoD or federal systems, including DISA STIGs, vulnerability assessments, and patching/remediation
- 5 years automating cloud infrastructure and platform provisioning (AWS, Azure) using Infrastructure as Code (Terraform or CloudFormation)
Skills Required
- CI/CD pipeline design and secure software deployment automation
- Infrastructure as Code (Terraform, Ansible, CloudFormation)
- Security scanning and monitoring/logging integration (Nessus, OpenSCAP, Splunk, ELK Stack)
- Containerization and orchestration in microservices architectures (Docker, Kubernetes)
- SAST/DAST integration directly into the CI/CD pipeline
- RMF process support, DISA STIG application, and continuous ATO / eMASS artifact automation
Education
Bachelor's degree in computer science, engineering, or equivalent, and 5+ years of experience OR AA with 7+ years of experience is an accepted substitute.
Certifications
Required: Current DoDM 8140.03-qualifying certification for the assigned cyberspace work role, e.g., Security+ or CySA+.
Preferred: CISSP, AWS/Azure security specialty certification, Certified Kubernetes Security Specialist (CKS).
Security Clearance
US Citizenship and the ability to obtain and maintain an active Secret or higher clearance, per contract requirements.