Jobs · Engineering · Pennsylvania

Lead DevSecOps Engineer - Clearance Required

hackajob · King of Prussia, PA · 1 mo ago
On-siteEngineeringFull-time

hackajob is collaborating with Lockheed Martin to connect exceptional professionals with this role in the Joint Air-to-Surface Standoff Missile (JASSM) program. JASSM is a United States Air Force initiative providing an autonomous, long-range, precision air-to-ground missile capable of striking highly defended, high-value targets. The JASSM Enterprise Software (JES) improves quality and speed in targeting and strike planning solutions across multiple 363rd Intelligence, Surveillance and Reconnaissance Group production units and Standoff Munitions Application Centers.

About the role

As part of the C4ISR Weapons Platform Integration (WPI) team, you will support on-site DevSecOps for target and strike planning operations within the JASSM Enterprise Software program. Reporting to the DevSecOps lead, you will collaborate with cross-functional, multi-site teams in a highly dynamic customer environment, including geographically dispersed teams.

Responsibilities

  • Ensure software baselines are configuration managed and properly tagged and versioned.
  • Track key software measures, including total, added, modified, and removed Source Lines of Code (SLOC) for each software release.
  • Manage the configuration and documentation of software development-specific licenses, tools, and libraries, including COTS and FOSS, through a human-readable Software Bill of Materials (SBOM).
  • Manage the program’s Agile planning and issue tracking system.
  • Oversee software build pipeline infrastructure to enable the build and deployment of development and operational software versions.
  • Manage deployment of software versions to unclassified and classified test environments, including transfer and packaging of application software, libraries, and dependencies.
  • Manage software installers and supporting deployment scripts for operational software versions with the support of the Field Operations and Maintenance Team.
  • Set up, configure, and maintain all manual and automated test environments to enable integration and testing, with support from the development team (Architects and Product Owners), I&T Team, and System Administration/Infrastructure team.
  • Manage the integration of software applications with internal environments (e.g., SIPR Lab) with the support of the I&T Team and the System Administration team.
  • Ensure software application and container-level cyber-security compliance with LM and USG standards.
  • Generate cyber-security artifacts required for Software Certification and Accreditation (C&A) and deployment to target environments.
  • Work with the Lead Architect to continuously improve software development processes and tools.

Requirements

  • Knowledge of modern DevSecOps tools and practices, including Docker/podman, Kubernetes, and OpenShift.
  • Knowledge of cloud computing design and security principles.
  • Experience with programming languages such as C, C++, Python, PowerShell, TypeScript, C#, or Java.
  • Experience working in an Agile development environment, including tools like Jira, Azure DevOps, and Confluence.
  • Knowledge of managing/developing cloud environments (e.g., AWS, Azure, GCP).
  • Experience supporting teams with requirements interpretation, interface definition, and testing.
  • Experience with CI/CD pipelines and infrastructure as code.
  • Security+ certification.
  • Must be a U.S. Citizen eligible for a government security clearance.

Desired Skills

  • Experience working with Vaults or removing passwords from source and at-rest configurations.
  • Hands-on experience with static/dynamic application security testing (SAST/DAST) tools (e.g., SonarQube, Checkmarx, OWASP ZAP).
  • Familiarity with container security (e.g., Trivy, Aqua, Twistlock, and runtime protection).
  • Knowledge of secret-management solutions (Vault, AWS Secrets Manager, Azure Key Vault).
  • Experience with software application and container-level cyber-security compliance to LM and USG standards.
  • Experience with software configuration management principles and implementation.
  • Ability to obtain a Top Secret/SCI clearance.
  • Experience with Government IL6 cloud environments (e.g., Cloud One, CloudWorks).

Schedule

  • 4x10-hour days, 3 days off per week.
  • Part-time remote telework: The selected candidate will work part of their schedule remotely and part on-site at a designated Lockheed Martin facility. The specific weekly schedule will be discussed during the hiring process.

Benefits

Lockheed Martin offers flexible schedules, competitive pay, and comprehensive benefits designed to support a healthy, fulfilling life at and outside of work.

Similar jobs