Senior DevSecOps Engineer - Cloud jobs in United States
cer-icon
Apply on Employer Site
company-logo

UICGS / Bowhead Family of Companies ยท 1 day ago

Senior DevSecOps Engineer - Cloud

UICGS / Bowhead Family of Companies is seeking a Senior DevSecOps Engineer - Cloud to support their customer on the Nautical contract in the Arlington, VA area. This role involves leading the implementation of secure DevSecOps practices for migrating legacy DoD applications to cloud environments while collaborating with development teams to ensure security best practices throughout the software development lifecycle.

Information Technology & Services
badNo H1BnoteSecurity Clearance RequirednoteU.S. Citizen Onlynote

Responsibilities

Design and implement CI/CD pipelines incorporating security controls for cloud environments (AWS GovCloud, Azure Government, Google Cloud for Government)
Develop and maintain Infrastructure as Code (IaC) using tools such as Terraform, CloudFormation, and Ansible
Implement automated security scanning and vulnerability assessment tools within deployment pipelines
Establish container security practices for Docker and Kubernetes environments
Ensure compliance with DoD security frameworks including NIST 800-53, FISMA, and FedRAMP
Collaborate with development teams to implement security best practices throughout the software development lifecycle
Monitor and respond to security incidents in cloud environments
Maintain documentation for security procedures and compliance requirements
Provide technical guidance on secure cloud architecture patterns
Lead security assessments and Authority to Operate (ATO) processes
Interface with the customer and external stakeholders in working groups, technical exchange meetings, and other forums
Chair/co-chair meetings and working groups on behalf of government representatives as directed
Resolve problems, allocate resources, manage personnel, and monitor performance to meet contract requirements
Provide daily control and supervision of employees as assigned
Provide planned replacement information at least 15 calendar days prior to replacement
Provide information within 24 hours of an unplanned replacement
Other duties as assigned

Qualification

DevOps/DevSecOps engineeringCloud platforms AWSCloud platforms AzureCloud platforms GCPDoD security frameworksCI/CD tools JenkinsCI/CD tools GitLab CICI/CD tools Azure DevOpsScripting languages PythonScripting languages BashScripting languages PowerShellContainerization technologies DockerContainerization technologies KubernetesSecurity tools NessusSecurity tools QualysSecurity tools FortifySecurity tools SonarQubeNetwork security knowledgeTechnical personnel managementCloud certificationsMicroservices architecture knowledgeService mesh technologiesDAWIA PM Practitioner certificationDoD 8570 IAT Level IIIIIGIAC Security Essentials (GSEC)FITSP-DGIAC Cloud Security Automation (GCSA)GIAC Information Security Fundamentals (GISF)(ISC)2 SSCP

Required

Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Data Science, Information Systems, or related field from an ABET accredited or CAE designated institution, OR 10+ years of relevant experience in lieu of degree
Minimum of 10+ years of experience in DevOps/DevSecOps engineering
Minimum of 5+ years of experience with cloud platforms (AWS, Azure, GCP)
Experience with DoD security frameworks and compliance requirements
Proficiency in scripting languages (Python, Bash, PowerShell)
Experience with containerization technologies (Docker, Kubernetes)
Knowledge of security tools (Nessus, Qualys, Fortify, SonarQube)
Experience with CI/CD tools (Jenkins, GitLab CI, Azure DevOps)
Strong understanding of network security and encryption protocols
Experience managing technical personnel for IT and/or cybersecurity efforts
DoD 8570 IAT Level II or III certification
Must be able to maintain a security clearance at the Top Secret level with SCI eligibility and maintain SAP eligibility
US Citizenship is a requirement for this contract

Preferred

Master's degree in relevant field
Cloud certifications (AWS Solutions Architect, Azure Solutions Architect, GCP Professional Cloud Architect)
Experience with legacy DoD systems migration
Knowledge of microservices architecture patterns
Experience with service mesh technologies (Istio, Linkerd)
DAWIA PM Practitioner certification
GIAC Security Essentials (GSEC)
FITSP-D
GIAC Cloud Security Automation (GCSA)
GIAC Information Security Fundamentals (GISF)
(ISC)2 Systems Security Certified Practitioner (SSCP)
CompTIA Security+

Company

UICGS / Bowhead Family of Companies

twittertwitter
company-logo
UIC Government Services (UICGS).

Funding

Current Stage
Late Stage

Leadership Team

leader-logo
Mike Hundley
President
linkedin
Company data provided by crunchbase