×
Register Here to Apply for Jobs or Post Jobs. X

DevSecOps Engineer

Job in Arlington, Arlington County, Virginia, 22201, USA
Listing for: The Phoenix Group
Full Time position
Listed on 2026-09-09
Job specializations:
  • IT/Tech
    Cloud Computing: Infrastructure & Operations, Cybersecurity, Systems Engineer, SRE/Site Reliability
Salary/Wage Range or Industry Benchmark: 140000 - 190000 USD Yearly USD 140000.00 190000.00 YEAR
Job Description & How to Apply Below

We are seeking a highly skilled Sec Dev Ops  Engineer to lead the design, automation, and maintenance of secure cloud infrastructure and CI/CD pipelines within multi-cloud environments. This role focuses on implementing Zero Trust architectures, continuous security monitoring, and ensuring compliance across federal cloud platforms, integrating security controls into deployment workflows through Infrastructure as Code (IaC) and Policy-as-Code frameworks. The ideal candidate will possess deep cloud architecture expertise, robust automation skills, and a strong security-operations mindset to support secure, compliant, and scalable cloud operations.

Role Overview

The Sec Dev Ops  Engineer owns the development and management of secure, compliant cloud infrastructures across multiple cloud providers, enhancing automation, security, and observability to ensure robust federal cloud operations and continuous compliance with security standards such as FedRAMP and NIST 800-53.

Key Responsibilities

  • Support and operate Zero Trust Network Access (ZTNA) architectures, including app connectors, privileged remote access, and private application boundaries, utilizing tools like Zscaler ZPA / PRA.
  • Manage privileged credentials, API tokens, and secret lifecycle workflows using Hashi Corp Vault, establishing automated credential rotation and lifecycle management.
  • Integrate federated identity providers (Okta, Azure AD / Entra , AWS IAM Identity Center) and support multi-cloud identity migrations.
  • Enforce strict least-privilege access policies across cloud environments, automating role-based access controls and credential rotations.
  • Build, automate, and maintain multi-tenant cloud infrastructure across AWS, Azure, and Google Cloud Platform (GCP) using Infrastructure as Code (Terraform as primary, Ansible, Cloud Formation).
  • Automate cloud provisioning, configuration management, and application deployment through secure CI/CD pipelines and Git Ops processes (ArgoCD, Helm).
  • Configure and manage cloud networking, security groups, IAM roles, and network permissions aligning with FedRAMP IL4 controls.
  • Develop and uphold secure CI/CD pipelines using tools such as Git Hub Actions, Git Lab CI, Azure Dev Ops, or Jenkins, integrating Policy-as-Code frameworks (OPA, Hashi Corp Sentinel, Azure Policy).
  • Embed static application security testing (SAST), software composition analysis (SCA), and container vulnerability scanning into deployment workflows.
  • Build, deploy, and troubleshoot containerized workloads in Kubernetes environments (EKS, AKS, GKE) using Helm, ArgoCD, or Kustomize.
  • Support FedRAMP continuous monitoring (Con Mon), incident management, POA&M tracking, and remediation activities.
  • Automate audit evidence collection and compliance reporting for controls like CM-2, CM-6, AU-2, SC-12.
  • Participate in enterprise change management processes, including documentation and technical review cycles via tools such as Service Now.
  • Maintain centralized observability infrastructure using Grafana, Prometheus, Cloud Watch, and other cloud-native tooling.
  • Define, monitor, and report on SLIs/SLOs for critical cloud security services.
  • Lead incident response efforts, on-call troubleshooting, root cause analysis, and rapid resolution for security and operational issues.

Core Qualifications & Requirements

  • 3–5 years of professional experience in Sec Dev Ops , Cloud Security Engineering, Platform Engineering, or Dev Ops.
  • Hands-on experience with at least one major hyperscaler (preferably AWS); working knowledge of Azure and GCP.
  • Advanced skills in Infrastructure as Code (Terraform, Ansible, Cloud Formation) and scripting languages (Python, Bash, Power Shell).
  • Proven experience managing enterprise identity/access solutions (Okta, Entra ) and secrets management platforms (Hashi Corp Vault, AWS KMS, Azure Key Vault).
  • Familiarity with security tooling such as endpoint protection (EDR), CSPM (Cloud Security Posture Management), and vulnerability scanners (Crowd Strike, Wiz, Qualys).
  • Strong understanding of containerization and orchestration platforms (Docker, Kubernetes).
  • Practical knowledge of FedRAMP, NIST 800-53, SOC 2 frameworks, or comparable compliance standards.

Nice-to-Have Qualifications

  • Certifications such as Hashi Corp Certified:
    Terraform Associate, AWS Certified Sys Ops Administrator, Solutions Architect, or Security+.
  • Experience with additional cloud tools and automation frameworks.
  • Familiarity with enterprise change management and incident response processes in government or highly regulated environments.

Core Technical Skills

  • Infrastructure as Code:
    Terraform, Cloud Formation, Ansible
  • Scripting

    Languages:

    Python, Bash, Power Shell
  • Security & Compliance Tools:
    Wiz, Qualys, Crowd Strike, OPA, Hashi Corp Sentinel
  • Monitoring & Observability:
    Grafana, Prometheus, Cloud Watch, Pager Duty, Service Now
#J-18808-Ljbffr
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary