Senior DevOps CI/CD Engineer – AWS; DevSecOps Champion
Listed on 2026-08-28
-
IT/Tech
Cybersecurity, AWS, Cloud Computing: Infrastructure & Operations, Information Security & Data Protection
Type of
Requisition :
Regular Clearance Level Must Currently Possess:
Secret Clearance Level Must Be Able to Obtain:
Secret Public Trust/Other
Required:
None Job Family:
Software Engineering
Job Qualifications:
Skills:
Controls Compliance, Identity Access Management (IAM), Secure Software Development, Security Testing, Web Applications
Certifications:
None
Experience:
8 + years of related experience US Citizenship
Required:
Yes
DEVOPS ENGINEER PRINCIPAL GDIT is looking for a Engineer – AWS (Dev Sec Ops Champion) a senior technical role supporting DOJ Homeland Security Task Force (HSTF) / National Coordination Center (NCC). This role leads secure CI/CD and Dev Sec Ops practices for AWS-based solutions, designing and governing pipelines and automation that embed security, compliance, and risk management into the delivery lifecycle for mission‑critical systems.
Responsibilities- Define and enforce secure CI/CD and Dev Sec Ops standards, patterns, and guardrails for AWS-hosted applications, in alignment with GDIT Cyber Security Policy, Cyber Security Handbook, and Cloud/Security standards.
- Design, build, and maintain CI/CD pipelines (e.g., AWS Code Pipeline/Code Build, Jenkins, Git Lab CI, Git Hub Actions, Azure Dev Ops) with integrated security scanning, compliance checks, approvals, and testing.
- Lead infrastructure‑as‑code (IaC) implementations (Cloud Formation, Terraform) with embedded security and configuration baselines, supporting secure provisioning of AWS environments.
- Automate secure environment provisioning, configuration, and deployments across development, test, and production AWS accounts, in line with cyber and IT risk management requirements.
- Implement monitoring, logging, and alerting (Cloud Watch, Cloud Trail, centralized logging) to support secure, observable, and auditable delivery pipelines.
- Integrate identity and access management, encryption, secrets management, vulnerability scanning, and compliance controls into CI/CD workflows as part of Dev Sec Ops practices.
- Ensure CI/CD pipelines and AWS solutions comply with applicable contractual and regulatory requirements (e.g., NIST 800‑53/171, CMMC, FedRAMP, ISO 27001) and internal cyber standards.
- Collaborate with application development, cloud platform, cyber security, IT risk, and operations teams to ensure architectures are “Dev Sec Ops -ready” and align with secure development standards.
- Provide technical leadership, coaching, and documentation for project teams adopting Dev Sec Ops and secure CI/CD practices; develop reusable secure pipeline templates and patterns.
- Support proposals, technical reviews, and risk assessments where secure CI/CD, cloud security, and Dev Sec Ops capabilities are required, including input to labor category mapping and staffing.
- Bachelor’s degree in Computer Science, Information Systems, Engineering, Cyber Security, or related field; or equivalent experience.
- Typically 8+ years of relevant IT experience, with significant experience in Dev Ops/Dev Sec Ops and CI/CD for production systems.
- Hands‑on experience with AWS services (e.g., EC2, ECS/EKS, S3, IAM, VPC, Cloud Watch/Cloud Trail) in security‑sensitive or regulated environments.
- Proven experience designing and operating CI/CD pipelines using one or more modern platforms (AWS Code Pipeline/Code Build, Jenkins, Git Lab CI, Git Hub Actions, Azure Dev Ops).
- Strong experience with infrastructure‑as‑code (e.g. Cloud Formation, Terraform) and secure configuration management and automation.
- Demonstrated experience promoting signed builds into an air-gapped, classified, or otherwise network‑isolated target environment, including artifact transfer procedures and post‑deployment verification.
- Experience with containers and orchestration (e.g. Docker, ECS, EKS, Kubernetes) including security aspects (image scanning, runtime security, least privilege).
- Demonstrated experience integrating security testing, vulnerability scanning, and compliance checks into CI/CD workflows (Dev Sec Ops ).
- Experience working under formal security and risk frameworks (e.g., NIST 800‑53/171, CMMC, FedRAMP, ISO 27001, customer‑specific cyber requirements).
- Strong…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).