DevSecOps Engineer
Listed on 2026-09-12
-
IT/Tech
If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.
Full Time Falls Church, VA, US
Salary Range: $ To $ Annually
Areté is seeking a Dev Sec Ops Engineer who is here for one purpose: to make our software development teams fast and successful on Git Lab and our CI/CD tooling.
You will own the day-to-day health of our self-hosted Git Lab environment, build and troubleshoot the pipelines our developers depend on, and integrate security scanning into those pipelines so compliance is something the pipeline handles rather than something developers fight. You are the person a developer goes to when a build, runner, or merge request workflow is broken. This is a hands-on engineering role with a heavy support and enablement component - a substantial part of the job is unblocking other engineers, writing the documentation that prevents the next ticket, and steadily raising the team's practices.
This position is onsite at our Falls Church, VA facility. The candidate will collaborate with Cyber Security and IT staff members, travel occasionally, and provide some after hours support. This is an exempt non-supervisory full-time position.
Primary Responsibilities- Serve as the primary point of contact for development teams on pipeline failures, Git Lab access and permissions, runner issues, package and container registry usage, merge request workflows, and environment troubleshooting.
- Build reusable pipeline templates, CI/CD components, and project scaffolding so teams start from a working, secure baseline instead of copying a pipeline from another repo.
- Create onboarding guides, runbooks, and internal documentation; run training sessions on Git workflow, pipeline authoring, and secure development practices.
- Advise developers on branching strategy, code review practice, versioning, and release management.
- Build, maintain, optimize, and troubleshoot CI/CD pipelines in Git Lab CI, automating builds, tests, deployments, and security scans.
- Improve build reliability and speed - caching, artifact management, parallelization, runner sizing and scaling.
- Manage Git Lab Runners across environments, including containerized and self-hosted runner fleets.
- Administer self-hosted Git Lab: upgrades, migrations, backups and restore testing, runners, integrations, monitoring, permissions, and security configuration.
- Administer Areté's artifact repository (JFrog Artifactory) — repository structure, retention policy, remote/proxy repositories for external packages, and access control.
- Administer supporting Dev Sec Ops services such as Sonar Qube, a secrets manager, and container registries; perform Linux system administration (RHEL, Rocky, or Ubuntu) for the platform, including system services, logging, and SSL/TLS certificate management.
- Implement and maintain SAST, DAST, software composition analysis, container image scanning, secret scanning, and SBOM generation within pipelines.
- Configure quality and security gates, and work with development teams to triage and resolve findings rather than simply reporting them.
- Manage build-time secrets, signing, and artifact provenance in line with Areté's security requirements.
- Automate platform, build, and remediation tasks using Bash, Python, or Power Shell; manage infrastructure and configuration with IaC and deployment tooling.
- Maintain Dev Sec Ops procedures, system documentation, and standard operating procedures; support change management, audit readiness, and compliance-aligned workflows.
- Track and report metrics on build times, pipeline reliability, and security posture, and drive measurable…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).