Jobs · Engineering · Virginia

Staff DevSecOps Engineer

Areté · Falls Church, VA · Today
EngineeringFull-time

About the role

Areté is seeking a DevSecOps Engineer to support our software development teams on GitLab and our CI/CD tooling. This is a hands-on engineering role with a heavy support and enablement component.

Responsibilities

  • Serve as the primary point of contact for development teams on pipeline failures, GitLab access and permissions, runner issues, package and container registry usage, merge request workflows, and environment troubleshooting.
  • Create reusable pipeline templates, CI/CD components, and project scaffolding so teams start from a working, secure baseline instead of copying a pipeline from another repo.
  • Create onboarding guides, runbooks, and internal documentation; run training sessions on Git workflow, pipeline authoring, and secure development practices.
  • Advise developers on branching strategy, code review practice, versioning, and release management.
  • Build, maintain, optimize, and troubleshoot CI/CD pipelines in GitLab CI, automating builds, tests, deployments, and security scans.
  • Manage GitLab Runners across environments, including containerized and self-hosted runner fleets.
  • Administer self-hosted GitLab: upgrades, migrations, backups and restore testing, runners, integrations, monitoring, permissions, and security configuration.
  • Administer Areté's artifact repository (JFrog Artifactory) — repository structure, retention policy, remote/proxy repositories for external packages, and access control.
  • Administer supporting DevSecOps services such as SonarQube, a secrets manager, and container registries; perform Linux system administration (RHEL, Rocky, or Ubuntu) for the platform, including system services, logging, and SSL/TLS certificate management.
  • Implement and maintain SAST, DAST, software composition analysis, container image scanning, secret scanning, and SBOM generation within pipelines.
  • Configure quality and security gates, and work with development teams to triage and resolve findings rather than simply reporting them.
  • Manage build-time secrets, signing, and artifact provenance in line with Areté's security requirements.
  • Automate platform, build, and remediation tasks using Bash, Python, or PowerShell; manage infrastructure and configuration with IaC and deployment tooling.
  • Maintain DevSecOps procedures, system documentation, and standard operating procedures; support change management, audit readiness, and compliance-aligned workflows.
  • Track and report metrics on build times, pipeline reliability, and security posture, and drive measurable improvement.

Qualifications

  • Bachelor's Degree in Computer Science, Information Technology, Cybersecurity, or a related discipline, or an additional 2 years of relevant work experience in lieu of a degree.
  • Minimum of 3 years of hands-on DevOps or DevSecOps experience with modern CI/CD pipelines.
  • Demonstrated ability to build, debug, and optimize GitLab CI pipelines — .gitlab-ci.yml authoring, CI/CD components and templates, and diagnosing failures across build, test, packaging, and deployment stages.
  • Experience with self-hosted GitLab, as an administrator or advanced user, is strongly preferred.
  • Hands-on experience with Docker and container lifecycle management — image creation, registries, and image tagging/promotion.
  • Experience automating tasks with Bash, Python, or PowerShell.
  • Experience integrating at least one class of security tooling into pipelines — SAST, DAST, software composition analysis, secret scanning, or container image scanning.
  • Demonstrated ability to support developers directly — resolving CI/CD and Git workflow issues, teaching Git fundamentals (branching, rebasing, merge conflict resolution, repository hygiene), writing clear documentation and runbooks, and explaining technical issues to engineers and non-technical stakeholders alike.
  • Must hold an active Top Secret security clearance, or be eligible to obtain and maintain one.
  • Must have or be able to obtain a CompTIA Security+ CE certification within 120 days of employment, in accordance with DoDM 8140.03 and DFARS 252.239-7001.

Similar jobs

Staff DevSecOps Engineer

SailPointUnited States· 3 wk ago
RemoteEngineering$121k–$204k/yrapply on sailpoint.wd1.myworkdayjobs.com

DevSecOps Engineer, Staff

AMERICAN SYSTEMSMiddletown, RI· 2 mo ago
Engineering$82k/yrapply on careers-americansystems.icims.com