DevSecOps Engineer
Newport News, Virginia, 23601, USA
Listed on 2026-10-02
-
IT/Tech
Cybersecurity, Cloud Computing: Infrastructure & Operations, Information Security & Data Protection
ICF’s Digital Modernization division is a rapidly growing, entrepreneurial, technology department, seeking a Dev Sec Ops Engineer to support upcoming needs with our federal customers.
Our Digital Modernization division is an information technology and management consulting department that offers integrated, strategic solutions to its public and private-sector clients. ICF has the expertise, agility, and commitment to design, build, and operate high-performance IT engines to support all aspects of our client’s business.
We are seeking a Dev Sec Ops Engineer to support a federal client by helping integrate security practices into modern cloud and application delivery workflows. You will work alongside senior Dev Ops, security, and application teams to support CI/CD pipelines, cloud infrastructure, automated testing, and security controls in alignment with federal standards. Work is fully remote within the United States on government-furnished equipment, with core collaboration hours in Eastern Time.
Job Location:
Remote work is authorized. Must support US Eastern time zone working hours .
* If you accept this position, you should note that ICF does monitor employee work locations blocks access from foreign locations/foreign IP addresses and prohibits personal VPN connections.
What You Will Do:- - Assist in the development, maintenance, and monitoring of CI/CD pipelines using tools such as Git Lab CI or Jenkins, including artifact management (e.g., Nexus)
- - Support automated deployment and environment promotion for applications built on a COTS/low-code platform (e.g., Appian), from development through test and production
- - Help implement automated quality gates in pipelines — unit/integration test execution, automated regression suites, and code-quality/static analysis — in support of contract quality targets
- - Help integrate security scanning and compliance checks into build and deployment pipelines (SAST, DAST, dependency scanning, container scanning)
- - Support cloud infrastructure in AWS or Azure, including Gov Cloud regions, with an emphasis on security best practices; support infrastructure as code (IaC) using tools like Terraform, Cloud Formation, or platform-native tooling
- - Support monitoring and observability — log aggregation and streaming to enterprise monitoring (e.g., Splunk), alerting, performance testing (e.g., JMeter) — and assist with troubleshooting and incident response
- - Support backup/recovery operations and availability, recovery-time, and recovery-point objectives
- - Document configurations, processes, and security controls to support audits, Assessment & Authorization (ATO) activities, and continuous-monitoring evidence
- - Collaborate with development, operations, and security teams in an Agile/Scrum environment
- - Learn and apply federal security frameworks such as NIST 800-53, FISMA, and FedRAMP
- - U.S. citizenship, required due to federal contract requirements
- - Must reside in the United States (U.S.) and the work must be performed in the United States (U.S.), as this work is for a federal contract and laws do apply
- - Ability to obtain and maintain a favorable federal agency background investigation / suitability determination
- - 5+ years of experience in Dev Ops, cloud engineering, systems engineering, or cybersecurity
- - Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related technical field
- - An active federal security clearance or a prior favorable federal background investigation (supports reciprocity and faster onboarding)
- - Basic understanding of CI/CD concepts and Dev Ops practices; experience with Git Lab and/or Jenkins specifically
- - Familiarity with at least one cloud platform (AWS or Azure…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).