Staff DevSecOps Engineer
Areté · Falls Church, VA · Today
EngineeringFull-time
About the role
Areté is seeking a DevSecOps Engineer to support our software development teams on GitLab and our CI/CD tooling. This is a hands-on engineering role with a heavy support and enablement component.
Responsibilities
- Serve as the primary point of contact for development teams on pipeline failures, GitLab access and permissions, runner issues, package and container registry usage, merge request workflows, and environment troubleshooting.
- Create reusable pipeline templates, CI/CD components, and project scaffolding so teams start from a working, secure baseline instead of copying a pipeline from another repo.
- Create onboarding guides, runbooks, and internal documentation; run training sessions on Git workflow, pipeline authoring, and secure development practices.
- Advise developers on branching strategy, code review practice, versioning, and release management.
- Build, maintain, optimize, and troubleshoot CI/CD pipelines in GitLab CI, automating builds, tests, deployments, and security scans.
- Manage GitLab Runners across environments, including containerized and self-hosted runner fleets.
- Administer self-hosted GitLab: upgrades, migrations, backups and restore testing, runners, integrations, monitoring, permissions, and security configuration.
- Administer Areté's artifact repository (JFrog Artifactory) — repository structure, retention policy, remote/proxy repositories for external packages, and access control.
- Administer supporting DevSecOps services such as SonarQube, a secrets manager, and container registries; perform Linux system administration (RHEL, Rocky, or Ubuntu) for the platform, including system services, logging, and SSL/TLS certificate management.
- Implement and maintain SAST, DAST, software composition analysis, container image scanning, secret scanning, and SBOM generation within pipelines.
- Configure quality and security gates, and work with development teams to triage and resolve findings rather than simply reporting them.
- Manage build-time secrets, signing, and artifact provenance in line with Areté's security requirements.
- Automate platform, build, and remediation tasks using Bash, Python, or PowerShell; manage infrastructure and configuration with IaC and deployment tooling.
- Maintain DevSecOps procedures, system documentation, and standard operating procedures; support change management, audit readiness, and compliance-aligned workflows.
- Track and report metrics on build times, pipeline reliability, and security posture, and drive measurable improvement.
Qualifications
- Bachelor's Degree in Computer Science, Information Technology, Cybersecurity, or a related discipline, or an additional 2 years of relevant work experience in lieu of a degree.
- Minimum of 3 years of hands-on DevOps or DevSecOps experience with modern CI/CD pipelines.
- Demonstrated ability to build, debug, and optimize GitLab CI pipelines — .gitlab-ci.yml authoring, CI/CD components and templates, and diagnosing failures across build, test, packaging, and deployment stages.
- Experience with self-hosted GitLab, as an administrator or advanced user, is strongly preferred.
- Hands-on experience with Docker and container lifecycle management — image creation, registries, and image tagging/promotion.
- Experience automating tasks with Bash, Python, or PowerShell.
- Experience integrating at least one class of security tooling into pipelines — SAST, DAST, software composition analysis, secret scanning, or container image scanning.
- Demonstrated ability to support developers directly — resolving CI/CD and Git workflow issues, teaching Git fundamentals (branching, rebasing, merge conflict resolution, repository hygiene), writing clear documentation and runbooks, and explaining technical issues to engineers and non-technical stakeholders alike.
- Must hold an active Top Secret security clearance, or be eligible to obtain and maintain one.
- Must have or be able to obtain a CompTIA Security+ CE certification within 120 days of employment, in accordance with DoDM 8140.03 and DFARS 252.239-7001.