Jobs · Information Technology · Virginia

DevSecOps / Security Engineer

Zantech · Arlington, VA · 6 days ago
Information TechnologyFull-time

About the role

Zantech is looking for a talented DevSecOps / Security Engineer to contribute to the success of our upcoming Technical Infrastructure and Platform Support project for an On-Site role based out of Arlington, VA. The DevSecOps / Security Engineer will play a crucial role in providing Technical Infrastructure and Platform Support and Cybersecurity and Information Assurance (RMF, continuous ATO, Compliance-as-Code). The DevSecOps / Security Engineer serves as the lead technical engineer for automation, CI/CD, and security posture of the cloud infrastructure, directly executing Technical Infrastructure and Platform Support requirements and supporting continuous Authority to Operate (ATO) under the DoD Risk Management Framework.

Responsibilities

  • Build and maintain secure, automated CI/CD pipelines and zero-downtime deployment processes
  • Automate infrastructure provisioning and configuration management via Infrastructure as Code
  • Support the RMF process: System Security Plan, Security Assessment Report, and POA&M development and continuous monitoring
  • Apply and automate DISA STIGs; run vulnerability scanning and manage remediation
  • Integrate SAST/DAST testing and auto-generate compliance-as-code artifacts (e.g., Ports/Protocols/Services, topology diagrams) for eMASS

Required Experience

  • 5 years in DevSecOps, including designing, implementing, and maintaining CI/CD pipelines and automating software deployment (Jenkins, GitLab CI/CD, or Ansible)
  • 5 years supporting the Risk Management Framework (RMF) for DoD or federal systems, including DISA STIGs, vulnerability assessments, and patching/remediation
  • 5 years automating cloud infrastructure and platform provisioning (AWS, Azure) using Infrastructure as Code (Terraform or CloudFormation)

Skills Required

  • CI/CD pipeline design and secure software deployment automation
  • Infrastructure as Code (Terraform, Ansible, CloudFormation)
  • Security scanning and monitoring/logging integration (Nessus, OpenSCAP, Splunk, ELK Stack)
  • Containerization and orchestration in microservices architectures (Docker, Kubernetes)
  • SAST/DAST integration directly into the CI/CD pipeline
  • RMF process support, DISA STIG application, and continuous ATO / eMASS artifact automation

Education

Bachelor's degree in computer science, engineering, or equivalent, and 5+ years of experience OR AA with 7+ years of experience is an accepted substitute.

Certifications

Required: Current DoDM 8140.03-qualifying certification for the assigned cyberspace work role, e.g., Security+ or CySA+.

Preferred: CISSP, AWS/Azure security specialty certification, Certified Kubernetes Security Specialist (CKS).

Security Clearance

US Citizenship and the ability to obtain and maintain an active Secret or higher clearance, per contract requirements.

Similar jobs