AI Summary

Embed security practices into every stage of the software delivery lifecycle and CI/CD pipeline for a US Government client. Design scalable cloud architecture and manage containerized workloads while ensuring compliance with industry security standards.

Overview

  • Tier One Technologies is seeking a DevSecOps Engineer to strengthen software development lifecycle by embedding security practices into every stage of delivery for our US Government client.
  • This remote contract-to-hire position will be originated in Falls Church, VA.
  • SELECTED CANDIDATES WITHOUT REQUIRED CLEARANCE WILL BE SUBJECT TO A FEDERAL GOVERNMENT BACKGROUND INVESTIGATION TO RECEIVE IT.

Responsibilities

  • Working across development, operations, and security teams to ensure applications and infrastructure are secure, compliant, and resilient, while maintaining speed and efficiency in deployment.
  • Lead the evolution of the software delivery lifecycle by embedding security into every stage of the CI/CD pipeline.
  • Integrate existing automation frameworks with AI-based solutions to improve coverage, reliability, and efficiency.
  • Ensure that all AI scripts and programs are fully executable on postal-issued laptops within approved security and environment constraints.
  • Perform Static and Dynamic Application Security Testing (SAST/DAST), integrated into pipelines.
  • Collaborate with software developers and IT staff to oversee code releases and deployments.
  • Design and implement scalable cloud architecture using platforms such as AWS, Google Cloud Platform, or Azure.
  • Manage containerization technologies such as Docker and orchestration tools like Kubernetes.
  • Utilize Infrastructure as Code (IaC) tools like Ansible for automated provisioning of infrastructure.
  • Ensure system reliability through monitoring, logging, and alerting using tools like Jenkins and Git.
  • Develop RESTful APIs and microservices to facilitate communication between applications.
  • Maintain databases including MySQL, PostgreSQL, Oracle, and Microsoft SQL Server.
  • Participate in Agile development processes to improve software delivery cycles.
  • Troubleshoot issues across the application stack from front-end to back-end services.
  • Manage and secure cloud environments (AWS, Azure, GCP) and containerized workloads (Docker, Kubernetes).
  • Implement Infrastructure as Code (IaC) with secure configurations using Terraform, Ansible, or CloudFormation.
  • Monitor and respond to security incidents, leveraging SIEM tools and observability platforms.
  • Ensure compliance with industry standards and regulations (ISO 27001, NIST, GDPR, HIPAA, PCI DSS).
  • Provide training and guidance to teams on DevSecOps best practices.

Qualifications

  • Bachelor’s degree in Computer Science, Cybersecurity, or related field.
  • 13+ years of overall IT experience.
  • 10+ years of experience managing software releases across DEV, SIT, CAT/UAT, and PROD environments, supporting major and minor releases, patches, upgrades, and production deployments.
  • 10+ years of experience providing release support, code promotion, deployment monitoring, and production data fixes to ensure application stability and successful software delivery.
  • 5+ years of experience designing, implementing, and maintaining secure CI/CD pipelines with integrated automated security testing and compliance controls.
  • 3+ years of experience leveraging GitHub Copilot and other AI-enabled tools to automate manual processes, improve developer productivity, and streamline software delivery workflows.
  • 3+ years of experience implementing and enforcing Secure Coding Standards throughout the software development lifecycle.
  • Strong knowledge of integrating application security testing tools, including SAST, DAST, and Software Composition Analysis (SCA), into CI/CD pipelines and development workflows.
  • Proven ability to collaborate with development teams to promote secure coding practices and remediate security vulnerabilities early in the SDLC.
  • Hands-on experience with Jenkins, GitLab CI/CD, Azure DevOps, and/or CircleCI to automate builds, deployments, testing, and embedded security validation.
  • Deep knowledge of cloud security services and best practices across AWS, Microsoft Azure, and Google Cloud Platform (GCP).
  • Hands-on experience securing containerized applications and orchestration platforms, including Docker and Kubernetes.
  • Proficiency in Python and Java for developing automation scripts, security tooling, and CI/CD pipeline integrations.
  • Familiarity with Terraform, Ansible, or CloudFormation, with emphasis on secure configurations.
  • Excellent communication skills.
  • Be able to pass a drug screening, criminal history, and credit checks.
  • Must be a US Citizen or have permanent residence status (Green Card).
  • Must be able to obtain a Position of Public Trust Clearance.
  • Must have lived in the United States for the past 5 years.
  • Cannot have more than 6 months travel outside the United States within the last five years. Military Service excluded. (Exception does not include military family members.)

Similar Jobs

See all Remote Software Development jobs →

Personalize your Remote Job Search in 3 Easy Steps!

Discover remote opportunities in Software Development

Answer easy questions

Answer easy questions

200,000+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified