R&D DevSecOps Engineering Scientist
Listed on 2026-07-12
-
IT/Tech
Cybersecurity, Cloud Computing: Infrastructure & Operations, Information Security, Security Management & Operations
R&D Dev Sec Ops Engineering Scientist
Position will integrate security practices directly into the software development lifecycle (SDLC). This position builds and maintains secure development and deployment processes, implements security controls throughout the software lifecycle, ensures compliance with organizational security standards, and enables project teams to adopt Dev Sec Ops practices across their workflows.
Establish and Enhance Secure CI/CD:
Design, implement, and maintain secure continuous integration/deployment pipelines to meet project requirements. Develop and enhance automated build, test, and deployment processes. Integrate automated security scanning tools. Implement Security-as-Code and Policy-as-Code practices into CI/CD to ensure safe and secure code for production. Integrate security gates that block vulnerable code from progressing to production.
Infrastructure & Cloud Security:
Implement and maintain security for Infrastructure as Code. Configure and enforce network security policies. Manage secrets securely using enterprise secret management solutions. Harden cloud environments including IAM roles, security groups, and logging. Establish and improve basic IaC approaches across project codebases.
Vulnerability Management & Compliance :
Perform regular security scans and assess results across applications and dependencies. Identify, prioritize, track, and help remediate vulnerabilities. Establish vulnerability remediation workflows. Coordinate periodic security testing and assessments. Automate compliance checks for relevant standards. Implement automated compliance controls. Maintain audit trails and documentation for security controls. Support internal and external security audits.
Security Enablement & Collaboration :
Partner with development teams to promote secure coding practices and increase Dev Sec Ops adoption across projects. Provide security guidance and training to engineers. Help squads integrate Dev Sec Ops practices into their workflows. Contribute to security policies and standards.
Incident Response :
Participate in security incident response and investigation. Support systems administration duties as needed, including privileged user access to support systems at ARL and partner sites.
Other related functions as assigned.
Bachelor's degree in engineering, computer or information science, or other applied sciences.
Three years of experience in Dev Ops, SRE, or security engineering roles
Experience with CI/CD tools such as Git Hub Actions, Git Lab CI, Jenkins, or ArgoCD
Experience with continuous integration and deployment systems
Proficiency with at least one major cloud platform
Experience with Infrastructure as Code methodologies
Experience with Linux administration
Knowledge of container technologies and container security
Familiarity with security scanning and testing methodologies
Understanding of security best practices for software development
Familiarity with identity and access management principles
Strong problem-solving and analytical skills
Excellent communication skills with ability to explain security concepts to non-technical audiences
Strong documentation skills
Must currently hold, or be able to obtain within the first six months of employment, a DoD 8140 compliant security certification (e.g., Security+)
Experience with maintaining, securing, and monitoring applications/data stores in AWS
Experience with container orchestration platforms such as Kubernetes or ECS
Experience with secret management solutions such as Hashi Corp Vault or AWS Secrets Manager
Experience in incident response or security operations
Experience with classified systems or in classified environments
Eligibility for immediate access to classified information.
DoD 8140 compliant certifications (e.g., CISSP, Security+, GSEC)
AWS certifications such as Solutions Architect, Security Specialty, or Sys Ops Administrator
Knowledge of compliance frameworks such as SOC 2, PCI-DSS, HIPAA, or ISO 27001
Ten or more years experience in software engineering or Dev Ops.
Cumulative GPA of 3.0.
Salary Range: $104,000-$174,000+/negotiable depending on qualifications.
Working Conditions:
Standard office conditions
Repetitive use of a keyboard at a workstation
Use of manual dexterity
Some weekend, evening and holiday work
Possible interstate/intrastate travel
Required Materials:
Resume/CV
3 work references with their contact information; at least one reference should be from a supervisor
Letter of interest
Unofficial College transcripts
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).