GovCIO is currently hiring a DevSecOps Engineer with an active Secret clearance to define, develop, and deploy cloud hosting and pipeline infrastructure to autome the software development lifecycle for a Government IT contract. This position will be loced in Fairfax, VA and will be a hybrid position.
Responsibilities:The DevSecOps Engineer defines, develops, and deploys cloud hosting and pipeline infrastructure to autome the software development lifecycle. This role designs and implements privacy and security best practices across all pipeline stages, ensuring th continuous integrion, testing, and deployment are executed securely and efficiently. The engineer leads development teams in applying security ges, automed builds, and testing within the pipeline and resolves architectural or operional issues affecting the pipeline or cloudhosting environment.
Qualificions:Bachelor's with 12+ years (or commensure experience)
Active Secret clearance with ability to obtain and hold DEA suitability
Required Skills and Experience
Strong proficiency with AWS services used in modern DevSecOps plforms, including IAM, ECS/EKS, Lambda, EC2, S3, CloudWch, CloudTrail, KMS, Secrets Manager, and VPClevel security controls.
Handson experience designing, building, and maintaining enterprisegrade CI/CD pipelines using GitHub Actions or other YAMLbased automion frameworks.
Expertise in infrastructureascode using Terraform, CloudFormion, or CDK, including modular design, environment provisioning, and enforcing configurion baselines.
Strong understanding of containerizion technologies such as Docker and Kubernetes, including image hardening, policy enforcement, admission controls, network policies, and automed image scanning.
Experience implementing DevSecOps security controls such as SAST, SCA, IaC scanning, dependency validion, secrets detection, and supplychain protection within the CI/CD pipeline.
Experience with cloudnive networking, load balancers, service mesh, and secure servicetoservice communicion pterns.
Proficiency in setting up automed test frameworks (unit, integrion, API, smoke, regression) and incorporing them into the pipeline.
Familiarity with logging, monitoring, and observability stacks such as ELK/OpenSearch, Prometheus/Grafana, AWS CloudWch, or Dadog.
Experience with automed deployment stregies, including blue/green, canary, and rolling deployments.
Strong knowledge of Linux fundamentals, shell scripting, and troubleshooting distributed cloud systems.
Experience implementing Zero Trustaligned security principles (least privilege, identitycentric access, secrets management, configurion hardening) within DevSecOps workflows.
Ability to diagnose and resolve performance, build, deployment, and pipeline reliability issues across multiple environments.
Experience supporting or collaboring with development, cloud engineering, cybersecurity, and operions teams in an Agile environment.
Excellent documention skills for pipeline designs, runbooks, IaC modules, architecture diagrams, and operional procedures.