DevSecOps Engineer - RMF
Listed on 2026-09-18
-
IT/Tech
Cybersecurity, Cloud Computing: Infrastructure & Operations
Job Description
Net Impact Strategies is seeking a Dev Sec Ops Engineer to support secure cloud infrastructure and applications within a Department of Defense environment. This hands-on role combines Dev Sec Ops engineering with cybersecurity and Risk Management Framework support.
The ideal candidate will have experience with cloud platforms, Kubernetes, CI/CD pipelines, Linux administration, infrastructure automation, vulnerability remediation, and RMF/ATO documentation. This individual will partner with engineering and cybersecurity teams to implement secure solutions and produce the technical evidence required to obtain and maintain an Authorization to Operate.
Responsibilities- Design, deploy, maintain, and troubleshoot secure cloud infrastructure and applications across development, testing, and production environments.
- Administer Docker and Kubernetes environments, including deployments, networking, configuration, storage, scaling, and upgrades.
- Develop and maintain CI/CD pipelines that automate application builds, testing, security scanning, and deployment.
- Implement Infrastructure as Code using Terraform, Cloud Formation, Ansible, or comparable technologies.
- Administer Linux systems and troubleshoot issues across applications, containers, networks, operating systems, and cloud services.
- Implement monitoring, logging, alerting, backup, recovery, and operational automation capabilities.
- Apply security baselines, DISA STIGs, patching requirements, least-privilege access, and secure configuration practices.
- Identify, prioritize, remediate, and document vulnerabilities and security findings.
- Support DoD RMF and ATO activities by developing and maintaining SSPs, POA&Ms, architecture diagrams, inventories, data flows, PPSM documentation, and remediation evidence.
- Work with ISSOs, ISSMs, engineers, developers, and assessors to document NIST SP 800-53 control implementations and maintain accurate authorization packages.
Required Qualifications
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field.
- Four or more years of experience in Dev Ops, Dev Sec Ops , cloud engineering, systems engineering, or a related discipline.
- Hands-on experience with Linux, Docker, Kubernetes, Git, and AWS, Microsoft Azure, or another major cloud platform.
- Experience developing CI/CD pipelines and implementing Infrastructure as Code using Terraform, Cloud Formation, or comparable tools.
- Knowledge of cloud networking, identity and access management, secrets management, encryption, monitoring, vulnerability management, patching, and system hardening.
- Familiarity with DoD RMF, the ATO lifecycle, NIST SP 800-53, DISA STIGs, security-control documentation, and POA&Ms.
- Strong troubleshooting, technical-writing, communication, and collaboration skills.
- Experience supporting DoD or other federal information systems, including eMASS and RMF/ATO documentation.
- Experience with AWS Gov Cloud and Kubernetes platforms such as EKS, AKS, Rancher/RKE2, or Red Hat Open Shift.
- Experience with security and compliance tools such as Fortify, Sonar Qube, Snyk, Trivy, Nessus, ACAS, AWS Inspector, or SCAP.
- Security+, CISSP, SecurityX, AWS, Azure, CKA, CKS, or another relevant certification.
- Must be a U.S. citizen.
- Must be eligible to obtain and maintain the required U.S. Government security clearance and/or suitability determination.
- Must meet applicable DoD 8140 cybersecurity workforce qualification requirements.
At Net Impact Strategies, we post salary ranges in compliance with the specific labor laws and regulations of each county and state, ensuring transparency and fairness in our hiring practices. This approach reflects our…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).