Security DevOps Engineer (DevSecOps) @ By Light Professional IT Services | Jobright.ai
JOBSarrow
RecommendedLiked
0
Applied
0
External
0
Security DevOps Engineer (DevSecOps) jobs in United States
182 applicants
company-logo

By Light Professional IT Services · 1 day ago

Security DevOps Engineer (DevSecOps)

ftfMaximize your interview chances
GovernmentInformation Services
badNo H1BnoteSecurity Clearance Requirednote

Insider Connection @By Light Professional IT Services

Discover valuable connections within the company who might provide insights and potential referrals.
Get 3x more responses when you reach out via email instead of LinkedIn.

Responsibilities

Perform GitHub code scanning using Dependabot and CodeQL.
Conduct vulnerability analysis and manage secrets to ensure compliance with security standards and documentation/reporting for Authority to Operate (ATO) security authorization for FISMA information systems.
Document findings, recommendations, and improvements. Generate regular reports on code quality metrics.
Conduct Threat Model analysis using Microsoft Threat Modeling Tool.
Research and address potential security issues for products, services, interfaces, protocols, etc., which may be introduced into the MHV environment.
Perform code quality assessments using static analysis tools to identify code smells, anti-patterns, and areas for improvement.
Conduct security scanning to identify vulnerabilities (e.g., OWASP Top Ten) in the codebase.
Optimize code performance, resolving bottlenecks, memory leaks, and resource-intensive areas.
Integrate code analysis tools into CI/CD pipelines, ensuring code quality checks are automated.
Develop scripts and automation tools using Python, Shell, or other scripting languages to streamline processes.
Prepare system, boundary, and authorization architectural diagrams using Visio.
Support the ATO process by documenting scans, creating diagrams, gathering artifacts, and addressing Security Control Assessments.
Work effectively with cross-functional teams, including developers, testers, and project managers, to ensure secure and efficient code releases.
Understand and work within AWS cloud infrastructure.
Utilize virtualization technologies such as VMware and containerization tools like Docker, Rancher, Kubernetes, and AWS EKS.

Qualification

Find out how your skills align with this job's requirements. If anything seems off, you can easily click on the tags to select or unselect skills to reflect your actual expertise.

GitHub code scanningVulnerability managementScripting skillsThreat modelingSecurity frameworksCloud infrastructureContainerization toolsAgile methodologiesPerformance optimization toolsTechnical documentation

Required

Proven experience with GitHub code scanning tools (Dependabot, CodeQL).
Proficiency in security scanning and vulnerability management (e.g., OWASP Top Ten).
Strong scripting and automation skills (Python, Shell).
Familiarity with Agile and DevOps methodologies.
Knowledge of security frameworks (NIST, VA 6500).
Hands-on experience with threat modeling tools (e.g., Microsoft Threat Modeling Tool).
Ability to create technical diagrams and documentation.

Preferred

Familiarity with FISMA compliance and ATO processes.
Experience with performance optimization tools.
Strong communication skills for cross-functional collaboration.

Company

By Light Professional IT Services

twittertwittertwitter
company-logo
BY LIGHT Professional IT Services is a provider of IT, cloud, cyber and infrastructure solutions to the US Federal Government.

Funding

Current Stage
Late Stage
Total Funding
unknown
2017-05-31Acquired

Leadership Team

leader-logo
Bob Donahue
President & CEO
linkedin
leader-logo
Mike Bowser
Chief Operating Officer
linkedin
Company data provided by crunchbase
logo

Orion

Your AI Copilot